Databricks-DE-Pro Data Security and Compliance Practice Question
An organization is migrating to Unity Catalog and needs to secure sensitive data. Which TWO of the following statements regarding Unity Catalog security best practices are correct?
⚠ Common exam trap
Test-takers frequently assume individual user accounts are acceptable for production CI/CD pipelines or object ownership, overlooking the maintenance nightmare when employees leave the organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use groups instead of individual users for access grants.
Effective security in Unity Catalog requires a deep understanding of object ownership and the principle of least privilege. By ensuring that objects are owned by a group rather than an individual, organizations prevent access gaps when staff turnover occurs. Additionally, using service principals for automated pipelines ensures that data access is tied to the workload rather than a user, maintaining consistent security postures across environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign table ownership to individual users for better tracking.
Why it's wrong here
Assigning ownership to individual users creates a significant security risk when those users leave the organization. If an account is deleted, ownership management becomes complex. Best practice dictates using service principals or dedicated groups to manage ownership to ensure continuity and prevent unauthorized access gaps.
- ✓
Use groups instead of individual users for access grants.
Why this is correct
Granting permissions to groups rather than individual users simplifies access management and reduces the risk of human error. When a new user joins a team, they automatically inherit the correct permissions by being added to the relevant group, ensuring consistent security posture across the entire data platform.
- ✗
Ensure that the metastore admin has access to all data.
Why it's wrong here
The metastore admin role should be treated with extreme caution and follow the principle of least privilege. While they manage metadata, they should not necessarily have unrestricted access to read sensitive business data. Separating administrative duties from data access duties is a critical component of security compliance.
- ✓
Use Service Principals for automated CI/CD job execution.
Why this is correct
Service principals are the ideal identity for automated processes and CI/CD pipelines. They provide a secure, non-interactive way to manage data access without relying on individual user credentials, which expire and pose security risks. This ensures that pipelines maintain consistent access even when team members change.
- ✗
Public access should be granted to the root catalog.
Why it's wrong here
Granting public access to the root catalog is a severe security vulnerability. It allows any user in the workspace to discover and potentially access data objects. Access control should be strictly restricted to specific users and groups using the principle of least privilege to ensure data security.
About these practice questions
One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.