Databricks-DE-Pro · domain
Data Security and Compliance
This domain covers securing data in Databricks: Unity Catalog fine-grained access control (row filters, column masks), customer-managed keys for encryption at rest, network restrictions via IP access lists, and secure data sharing across accounts. Questions present realistic engineering scenarios and ask you to select the correct Unity Catalog, cloud, or sharing feature to meet a stated compliance requirement.
Focused practice
Practice Data Security and Compliance questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Data Security and Compliance
Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.
Unity Catalog column masks and row filters for fine-grained access control on Delta tables
Customer-managed keys (CMK) for encrypting workspace-managed data at rest
IP access lists to restrict workspace connections to approved corporate network ranges
Delta Sharing to expose tables to external partners without copying data
Watch out for
Common Data Security and Compliance exam traps
- ▸Confusing column masks with row filters, or applying them at table level instead of via Unity Catalog functions and GRANT statements
- ▸Assuming CMK changes who can query data, when it only controls encryption keys protecting data at rest
- ▸Believing Delta Sharing copies data to the recipient, rather than granting governed read access to the shared table
Question index
All Data Security and Compliance questions (28)
Click any question to see the full explanation, or start a practice session above.
Which of the following describes the correct behavior of Unity Catalog's 'Data Lineage' when used for security compliance?
Hard2A data engineer is configuring audit logging for a Unity Catalog-enabled workspace. The security team wants to capture all access to tables and the granting of privileges. Which Databricks feature should the engineer enable to collect these audit events?
Easy3A data engineer needs to ensure that PII data in a Delta table is accessible only to users in the 'HR_Manager' group. Which approach provides the most granular and scalable security implementation?
Medium4When migrating an existing Hive metastore to Unity Catalog, what is the most important security consideration regarding object naming?
Medium5Refer to the exhibit. A user encounters this error when running a query. What is the correct action to resolve this issue while maintaining the security model?
Hard6Which TWO of the following are primary benefits of using Unity Catalog for data governance in Databricks?
Medium7A data engineer needs to grant a service principal permission to read data from a Unity Catalog table named sales.orders. The service principal is used by an automated job and should have only the minimum necessary privileges. Which Unity Catalog privilege should be granted on the table to allow the service principal to read data?
Easy8A data engineer is configuring a Databricks workspace with Unity Catalog. The security team wants to ensure that all data access is logged for compliance auditing. The engineer enables audit logs and configures delivery to a cloud storage location. Which Unity Catalog object should the engineer use to query audit logs for data access events?
Easy9An organization wants to restrict data access to only allow connections from specific corporate IP ranges. Which Databricks feature should be configured to implement this network security requirement?
Medium10A financial services firm stores market data in an external location registered in Unity Catalog as `s3://firm-market-data/`. The security team requires that only a specific IAM role, assumed by a Unity Catalog storage credential, can read the bucket, and that no Databricks user can bypass Unity Catalog to read the data directly with their own cloud credentials. The Data Engineer must configure the storage credential. Which configuration achieves this?
Hard11Which TWO of the following are benefits of using Unity Catalog for managing data governance in a multi-workspace environment?
Medium12A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The organization's security policy requires that Databricks assumes an IAM role, and that no long-lived AWS access keys are stored in Databricks. The engineer has created an IAM role with a trust policy and an external ID. Which action must the engineer take to complete the storage credential configuration in Unity Catalog?
Hard13Refer to the exhibit. A data engineer executes this command in a Unity Catalog-enabled workspace. What is the immediate effect on the 'analyst_group'?
Hard14What is the primary function of a 'Personal Access Token' (PAT) in Databricks, and why is it considered a security risk if not managed properly?
Medium15A data engineer is configuring a Unity Catalog external location to allow access to an S3 bucket. The security team requires that all access to the bucket be authenticated using a specific IAM role, and that the credentials not be stored in Databricks. Which Unity Catalog object should the engineer create to meet this requirement?
Medium16A Data Engineer is implementing column-level security on a Unity Catalog table `sales.customers` that contains `email`, `ssn`, and `region` columns. The requirement is that analysts in the `analyst` group see only the last four digits of `ssn` and a hashed `email`, while members of the `compliance` group see full values. The engineer plans to use column masks. Which TWO actions are required to meet the requirement? (Choose two.)
Medium17An organization requires that all data stored in their S3 bucket used by Databricks be encrypted using a Customer Managed Key (CMK). Which configuration must be performed to meet this requirement?
Medium18A data engineer is implementing fine-grained access control on a Delta table in Unity Catalog that contains sensitive customer data. The requirement is to mask the `credit_card` column for all users except members of the `finance` group, and to filter out rows where the `region` column is not in the user's allowed regions. Which two Unity Catalog features should the engineer use? (Choose two.)
Hard19A Data Engineer needs to encrypt data at rest within a Databricks workspace that uses a customer-managed key (CMK). What is the primary purpose of this configuration?
Hard20A data engineer is configuring a Unity Catalog external location to securely access data in an AWS S3 bucket. The engineer has already created an IAM role with the necessary permissions and configured the storage credential. Which additional step is required to allow Databricks to access the S3 bucket?
Medium21A data engineer is designing a solution to share a Delta table with an external partner organization. The partner uses a different Databricks account and must be able to read the table, but the data must not be copied outside the provider's cloud storage. The provider uses Unity Catalog and wants to minimize operational overhead while ensuring the partner sees only the shared table. Which Unity Catalog feature should the engineer use?
Hard22Which of the following is the most secure method for a Data Engineer to provide access to a specific Delta table for a temporary project?
Medium23An organization is migrating to Unity Catalog and needs to secure sensitive data. Which TWO of the following statements regarding Unity Catalog security best practices are correct?
Hard24A data engineer is tasked with ensuring that sensitive information in a 'customer' table is masked for all users except the 'Data_Science' group. What is the correct Unity Catalog feature to implement?
Hard25When configuring a Service Principal to access a Unity Catalog-enabled workspace, which THREE steps are required to ensure secure and functional access?
Hard26A data engineering team stores customer transaction data in a Unity Catalog managed table named prod.finance.transactions. The security team requires that any query referencing this table, whether through a view or directly, is recorded with the identity of the user who ran it, and that the audit logs are retained for 365 days. The workspace uses Unity Catalog and has audit logs delivered to a cloud storage location. Which configuration should the data engineer verify or set to meet the requirement that all access to the table is captured with the user identity?
Medium27A data engineer is setting up a new Unity Catalog metastore. What is the primary purpose of the 'Metastore Admin' role?
Medium28A Data Engineer needs to ensure that PII data in a Delta table is accessible only to members of the 'hr_admin' group, while allowing all other users to view the non-PII columns. Which Unity Catalog feature is the most efficient way to implement this requirement?
MediumOther domains
All Databricks-DE-Pro exam domains
Frequently asked questions
- What does the Data Security and Compliance domain cover on the Databricks-DE-Pro exam?
- Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.
- How many questions are in this domain?
- This page lists all 28 Data Security and Compliance questions in the Databricks-DE-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Security and Compliance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.