Databricks-DE-Pro · domain
Data Governance
This domain covers Unity Catalog's governance layer on Databricks: metastores, catalogs, schemas, grants, external locations and storage credentials, column- and row-level security, audit logging, and Delta Sharing. Questions are scenario-based, asking you to pick the correct Unity Catalog object or feature to enforce access, protect PII, or share data across accounts and non-Databricks consumers.
Focused practice
Practice Data Governance questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Data Governance
You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
Configuring external locations and storage credentials to govern cloud storage paths in Unity Catalog
Applying GRANT/REVOKE privileges on catalogs, schemas, tables, and views
Using column masks, row filters, and dynamic views to protect PII
Sharing data with external or non-Databricks recipients via Delta Sharing
Watch out for
Common Data Governance exam traps
- ▸Assuming table ACLs alone protect PII; column masks or row filters are needed for fine-grained enforcement.
- ▸Confusing external locations with storage credentials; the credential authenticates, the location defines the governed path.
- ▸Believing Delta Sharing requires the recipient to run Databricks; recipients can consume shares with open Delta Sharing clients.
Question index
All Data Governance questions (16)
Click any question to see the full explanation, or start a practice session above.
A data engineer needs to audit which users have accessed a Unity Catalog table containing sensitive data. They want to see a record of all queries that read from the table over the past 30 days. Which Unity Catalog feature should they use?
Easy2A data engineer needs to restrict access to personally identifiable information (PII) columns in a Unity Catalog table for a group of analysts. Which Unity Catalog feature should be used to enforce this policy while ensuring data remains queryable?
Medium3A data engineer is configuring a Unity Catalog external location to allow a service principal to write to an ADLS Gen2 container. The storage credential uses a managed identity. The engineer grants the service principal `WRITE FILES` on the external location. However, when the service principal attempts to write, it fails with a permissions error. The engineer verifies that the managed identity has the Storage Blob Data Contributor role on the container. What is the most likely cause of the failure?
Hard4A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?
Medium5A data engineer has a Unity Catalog managed table `sales.raw.transactions` that contains a column `customer_email` with PII. Analysts in the `marketing_analysts` group need to query the table for aggregate reporting but must never see individual email addresses. The engineer wants to enforce this dynamically without creating a separate view or copy of the data. Which Unity Catalog feature should the engineer use?
Medium6Which THREE actions are required to properly implement a secure data sharing strategy using Delta Sharing?
Hard7A data engineer needs to grant a new data analyst the ability to query tables in the `sales` catalog, which is in Unity Catalog. The analyst should only be able to read data and not modify any tables or metadata. Which sequence of privileges should the engineer grant to the analyst?
Medium8Which TWO of the following are primary benefits of using Unity Catalog for managing data lineage in Databricks?
Medium9When migrating to Unity Catalog, what is the best practice for managing existing data access permissions?
Medium10A data engineer is implementing column-level masking in Unity Catalog. They need to mask the 'email' column in the table 'prod.customers' such that only members of the 'hr_group' see the full email, while all other users see a masked version. The engineer creates a masking function and applies it using ALTER TABLE. Which statement correctly applies the mask?
Hard11A data engineer is asked to implement column-level masking for a Unity Catalog table `main.hr.employees` that contains a column `ssn` with Social Security numbers. The requirement is that only members of the `hr_group` should see the full SSN, while all other users should see only the last four digits (e.g., XXX-XX-1234). The engineer decides to use a column mask function. Which statement accurately describes how to apply the mask?
Easy12An organization needs to share a dataset with a client who does not use Databricks. What is the most efficient and secure way to share this data using Unity Catalog?
Medium13Which TWO of the following are true regarding Unity Catalog's ability to govern external locations?
Hard14A data engineer is designing a Unity Catalog governance model for a new data lakehouse. They need to ensure that data access is auditable and that sensitive data is protected. Which two actions should the engineer take to meet these requirements? (Choose two.)
Medium15A data engineer is using Delta Sharing to share a table with an external partner. The partner needs to access the shared data using their own Databricks workspace. Which protocol does Delta Sharing use to enable this cross-platform sharing?
Easy16A data engineer is configuring a Unity Catalog metastore to use a customer-managed key (CMK) for encryption at rest. The engineer has created the necessary Key Vault and key in Azure. Which additional configuration is required to enable CMK for the metastore?
MediumOther domains
All Databricks-DE-Pro exam domains
Frequently asked questions
- What does the Data Governance domain cover on the Databricks-DE-Pro exam?
- You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
- How many questions are in this domain?
- This page lists all 16 Data Governance questions in the Databricks-DE-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.