Databricks-DE-Pro Data Security and Compliance Practice Question
An organization requires that all data stored in their S3 bucket used by Databricks be encrypted using a Customer Managed Key (CMK). Which configuration must be performed to meet this requirement?
⚠ Common exam trap
Candidates mistakenly select standard table-level encryption or application-level settings instead of the workspace-level configuration required for DBFS root encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the workspace to use a Customer Managed Key for DBFS root.
When using Customer Managed Keys (CMK) for storage encryption, the Databricks environment must be configured with the appropriate IAM policies and KMS key grants. This ensures that the Databricks compute resources have the necessary permissions to perform cryptographic operations. Configuring this correctly at the storage and workspace level is essential for compliance with data protection standards like HIPAA or GDPR.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable server-side encryption with S3-managed keys (SSE-S3).
Why it's wrong here
SSE-S3 uses AWS-managed keys, not customer-managed keys. While this provides encryption at rest, it does not allow the customer to rotate, control, or revoke access to the keys in the way that AWS KMS with CMK does. It fails to meet the requirement for Customer Managed Key usage.
- ✓
Configure the workspace to use a Customer Managed Key for DBFS root.
Why this is correct
Configuring the Databricks workspace to use a Customer Managed Key for the DBFS root ensures that all data stored in the default storage location is encrypted with your specific KMS key. This fulfills the compliance requirement by centralizing the cryptographic control of data at the root storage level.
- ✗
Set the encryption policy in the Spark configuration of every cluster.
Why it's wrong here
While Spark configurations can manage temporary data encryption, they do not enforce encryption for the persistent S3 bucket itself. Encryption must be enabled at the storage layer via AWS policies or bucket settings to ensure that data is encrypted at rest regardless of the cluster configuration.
- ✗
Apply an IAM role to the storage bucket that restricts access to the root user.
Why it's wrong here
IAM roles restrict access but do not enable encryption. While restricting access is a security best practice, it does not satisfy the specific requirement for encrypting data with a CMK. Encryption is a distinct process from identity and access management in the AWS ecosystem for storage security.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
One of 267 original Databricks-DE-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.