Databricks-DE-Pro Data Security and Compliance Practice Question
A data engineering team stores customer transaction data in a Unity Catalog managed table named prod.finance.transactions. The security team requires that any query referencing this table, whether through a view or directly, is recorded with the identity of the user who ran it, and that the audit logs are retained for 365 days. The workspace uses Unity Catalog and has audit logs delivered to a cloud storage location. Which configuration should the data engineer verify or set to meet the requirement that all access to the table is captured with the user identity?
⚠ Common exam trap
The trap here is assuming that cluster-level query logging or view-based access is equivalent to Unity Catalog audit logging, which already records user identity for all Unity Catalog access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that Unity Catalog audit logging is enabled for the account and that the audit log delivery is configured to the required cloud storage with appropriate retention.
Unity Catalog audit logs are generated at the account level and capture the identity of the user performing the action on Unity Catalog objects. To satisfy a retention requirement, the logs must be delivered to durable cloud storage with a retention policy. Cluster-level or view-level controls do not replace this native audit logging, and they do not provide the same structured, tamper-resistant record.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a cluster policy that enforces the use of a specific Spark log4j appender to send query logs to the audit storage.
Why it's wrong here
Cluster policies control cluster configuration, not audit log generation. A custom log4j appender could write logs, but it would not produce the standardized Unity Catalog audit events that include user identity and object details in the required format. It also would not integrate with the account-level audit log delivery and retention mechanism.
- ✗
Enable table access control on the cluster and set the cluster's Spark configuration to log all queries.
Why it's wrong here
Table access control on a cluster is a legacy Hive metastore feature and does not govern Unity Catalog tables. Setting a Spark configuration to log queries writes to driver logs, not to the account-level audit log, and does not reliably capture the authenticated user identity for Unity Catalog access. It also would not produce the structured audit records required for compliance retention.
- ✓
Ensure that Unity Catalog audit logging is enabled for the account and that the audit log delivery is configured to the required cloud storage with appropriate retention.
Why this is correct
Unity Catalog automatically records access events, including the user identity, for all queries against Unity Catalog objects. These events are written to the account-level audit log. To meet the 365-day retention requirement, the audit log must be delivered to a cloud storage location configured with the necessary lifecycle policy. No additional cluster-level setting is needed to capture the user identity.
- ✗
Create a view over the table and grant SELECT on the view only, so that all access goes through the view and is logged.
Why it's wrong here
Creating a view does not change audit logging behavior. Unity Catalog logs access to the underlying table regardless of whether it is queried directly or through a view. Restricting access to a view is an access control measure, not an auditing one, and would not by itself ensure that the user identity is captured for all access paths, including direct table access by privileged users.
About these practice questions
One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.