Courseiva

Databricks-DE-Pro · domain

Data Governance

This domain covers Unity Catalog's governance layer on Databricks: metastores, catalogs, schemas, grants, external locations and storage credentials, column- and row-level security, audit logging, and Delta Sharing. Questions are scenario-based, asking you to pick the correct Unity Catalog object or feature to enforce access, protect PII, or share data across accounts and non-Databricks consumers.

16 questions3 easy9 medium4 hard

Focused practice

Practice Data Governance questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Data Governance

You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.

Configuring external locations and storage credentials to govern cloud storage paths in Unity Catalog

Applying GRANT/REVOKE privileges on catalogs, schemas, tables, and views

Using column masks, row filters, and dynamic views to protect PII

Sharing data with external or non-Databricks recipients via Delta Sharing

Watch out for

Common Data Governance exam traps

  • ▸Assuming table ACLs alone protect PII; column masks or row filters are needed for fine-grained enforcement.
  • ▸Confusing external locations with storage credentials; the credential authenticates, the location defines the governed path.
  • ▸Believing Delta Sharing requires the recipient to run Databricks; recipients can consume shares with open Delta Sharing clients.

Question index

All Data Governance questions (16)

Click any question to see the full explanation, or start a practice session above.

1

A data engineer needs to audit which users have accessed a Unity Catalog table containing sensitive data. They want to see a record of all queries that read from the table over the past 30 days. Which Unity Catalog feature should they use?

Easy
2

A data engineer needs to restrict access to personally identifiable information (PII) columns in a Unity Catalog table for a group of analysts. Which Unity Catalog feature should be used to enforce this policy while ensuring data remains queryable?

Medium
3

A data engineer is configuring a Unity Catalog external location to allow a service principal to write to an ADLS Gen2 container. The storage credential uses a managed identity. The engineer grants the service principal `WRITE FILES` on the external location. However, when the service principal attempts to write, it fails with a permissions error. The engineer verifies that the managed identity has the Storage Blob Data Contributor role on the container. What is the most likely cause of the failure?

Hard
4

A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?

Medium
5

A data engineer has a Unity Catalog managed table `sales.raw.transactions` that contains a column `customer_email` with PII. Analysts in the `marketing_analysts` group need to query the table for aggregate reporting but must never see individual email addresses. The engineer wants to enforce this dynamically without creating a separate view or copy of the data. Which Unity Catalog feature should the engineer use?

Medium
6

Which THREE actions are required to properly implement a secure data sharing strategy using Delta Sharing?

Hard
7

A data engineer needs to grant a new data analyst the ability to query tables in the `sales` catalog, which is in Unity Catalog. The analyst should only be able to read data and not modify any tables or metadata. Which sequence of privileges should the engineer grant to the analyst?

Medium
8

Which TWO of the following are primary benefits of using Unity Catalog for managing data lineage in Databricks?

Medium
9

When migrating to Unity Catalog, what is the best practice for managing existing data access permissions?

Medium
10

A data engineer is implementing column-level masking in Unity Catalog. They need to mask the 'email' column in the table 'prod.customers' such that only members of the 'hr_group' see the full email, while all other users see a masked version. The engineer creates a masking function and applies it using ALTER TABLE. Which statement correctly applies the mask?

Hard
11

A data engineer is asked to implement column-level masking for a Unity Catalog table `main.hr.employees` that contains a column `ssn` with Social Security numbers. The requirement is that only members of the `hr_group` should see the full SSN, while all other users should see only the last four digits (e.g., XXX-XX-1234). The engineer decides to use a column mask function. Which statement accurately describes how to apply the mask?

Easy
12

An organization needs to share a dataset with a client who does not use Databricks. What is the most efficient and secure way to share this data using Unity Catalog?

Medium
13

Which TWO of the following are true regarding Unity Catalog's ability to govern external locations?

Hard
14

A data engineer is designing a Unity Catalog governance model for a new data lakehouse. They need to ensure that data access is auditable and that sensitive data is protected. Which two actions should the engineer take to meet these requirements? (Choose two.)

Medium
15

A data engineer is using Delta Sharing to share a table with an external partner. The partner needs to access the shared data using their own Databricks workspace. Which protocol does Delta Sharing use to enable this cross-platform sharing?

Easy
16

A data engineer is configuring a Unity Catalog metastore to use a customer-managed key (CMK) for encryption at rest. The engineer has created the necessary Key Vault and key in Azure. Which additional configuration is required to enable CMK for the metastore?

Medium

Frequently asked questions

What does the Data Governance domain cover on the Databricks-DE-Pro exam?
You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
How many questions are in this domain?
This page lists all 16 Data Governance questions in the Databricks-DE-Pro question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Data Governance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
databricks-data-engineer-professional DATABRICKS-DATA-ENGINEER-PROFESSIONAL de pro data governance Practice Questions