Courseiva

CCNA Data Governance Questions

16 questions · Data Governance · All types, answers revealed

1
MCQeasy

A data engineer needs to audit which users have accessed a Unity Catalog table containing sensitive data. They want to see a record of all queries that read from the table over the past 30 days. Which Unity Catalog feature should they use?

A.Delta transaction log
B.Data lineage
C.Information schema
D.Audit logs
AnswerD

Audit logs capture detailed information about user activities, including queries executed against Unity Catalog tables. They record who accessed what data and when, making them the correct choice for auditing access to sensitive tables. Audit logs are stored in the metastore's storage location and can be queried for analysis.

Why this answer

Audit logs in Unity Catalog record all access and query activities, including the user, timestamp, and the tables accessed. They are essential for security auditing and compliance. Data lineage, information schema, and Delta transaction logs serve different purposes and do not provide a record of user access.

Exam trap

The trap here is assuming data lineage tracks user access, but it only tracks data flow, not individual queries.

2
MCQmedium

A data engineer needs to restrict access to personally identifiable information (PII) columns in a Unity Catalog table for a group of analysts. Which Unity Catalog feature should be used to enforce this policy while ensuring data remains queryable?

A.Apply a static mask using a custom UDF during data ingestion.
B.Grant the analyst group SELECT access on the table and instruct them to cast PII columns to null.
C.Define a column mask using SQL functions to redact data for the analyst group.
D.Create separate physical tables for analysts containing only non-sensitive columns.
AnswerC

Unity Catalog column masking allows engineers to apply granular security policies directly to table columns. By defining a mask, the platform automatically redacts data based on the user's role at query time, ensuring compliance without modifying the underlying storage. This provides a clean separation between data storage and security enforcement.

Why this answer

Dynamic views or Row-level security (RLS) and Column-level security (CLS) are essential for compliance. By utilizing SQL functions like current_user() within a defined mask, you ensure that PII is obscured based on user identity. This approach centralizes security within the data platform, preventing the need to duplicate datasets for different access levels, which significantly reduces the administrative burden and minimizes the risk of unauthorized data exposure in production environments.

Exam trap

Candidates often suggest creating separate views for each user role. This leads to 'view explosion,' which is difficult to maintain and audit compared to centralized column masking.

3
MCQhard

A data engineer is configuring a Unity Catalog external location to allow a service principal to write to an ADLS Gen2 container. The storage credential uses a managed identity. The engineer grants the service principal `WRITE FILES` on the external location. However, when the service principal attempts to write, it fails with a permissions error. The engineer verifies that the managed identity has the Storage Blob Data Contributor role on the container. What is the most likely cause of the failure?

A.The service principal does not have the `USE EXTERNAL LOCATION` privilege on the external location.
B.The service principal lacks the `CREATE EXTERNAL TABLE` privilege on the external location.
C.The external location is missing the `READ FILES` privilege for the service principal.
D.The managed identity lacks the Storage Blob Data Reader role on the container.
AnswerA

In Unity Catalog, to use an external location, a principal must have the `USE EXTERNAL LOCATION` privilege in addition to any file-level privileges like `WRITE FILES`. Without `USE EXTERNAL LOCATION`, the principal cannot access the external location at all, even if it has `WRITE FILES`. The managed identity's cloud permissions are separate and do not grant Unity Catalog access.

Why this answer

Unity Catalog requires both `USE EXTERNAL LOCATION` and the appropriate file-level privileges (`READ FILES`, `WRITE FILES`) to access data in an external location. The `USE EXTERNAL LOCATION` privilege grants the ability to reference the external location in queries and commands, while `WRITE FILES` allows writing data. Without `USE EXTERNAL LOCATION`, the service principal cannot utilize the external location, resulting in a permissions error despite having `WRITE FILES` and cloud storage permissions.

Exam trap

The trap here is focusing on cloud IAM roles and file-level privileges while overlooking the mandatory `USE EXTERNAL LOCATION` privilege that gates access to the external location itself.

4
MCQmedium

A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?

A.Workspace-level access control lists.
B.Customer-managed keys (CMK) for managed storage.
C.Unity Catalog lineage tracking.
D.Table access control (TAC).
AnswerB

Customer-managed keys provide a mechanism to encrypt data at rest using keys managed by the customer. This is the industry-standard approach for ensuring data confidentiality in a multi-tenant cloud environment, providing an additional layer of security and auditability that is essential for enterprise compliance and robust data governance.

Why this answer

Customer-managed keys (CMK) for managed storage are the standard governance tool for ensuring that data at rest is encrypted according to organizational security policies. By configuring CMK, the organization maintains control over the encryption lifecycle, satisfying compliance requirements. This feature is critical for highly regulated industries where the entity, rather than the cloud provider, must maintain the ultimate authority over data access and encryption standards in the cloud.

Exam trap

Candidates often confuse 'encryption at rest' with 'access control' or 'data masking.' They may select options like Unity Catalog permissions, which govern access but not storage-level encryption.

5
MCQmedium

A data engineer has a Unity Catalog managed table `sales.raw.transactions` that contains a column `customer_email` with PII. Analysts in the `marketing_analysts` group need to query the table for aggregate reporting but must never see individual email addresses. The engineer wants to enforce this dynamically without creating a separate view or copy of the data. Which Unity Catalog feature should the engineer use?

A.Create a row filter on `sales.raw.transactions` that excludes rows where `customer_email` is not null.
B.Enable attribute-based access control (ABAC) at the catalog level to automatically mask all PII columns for all non-admin users.
C.Apply a column mask to `customer_email` using a user-defined function that returns NULL for members of `marketing_analysts`.
D.Revoke SELECT on the table from `marketing_analysts` and grant SELECT only on a view that omits `customer_email`.
AnswerC

Column masks in Unity Catalog allow dynamic redaction of column values based on the querying user or group. By attaching a mask function that returns NULL for marketing_analysts, the engineer enforces the restriction at query time without altering the underlying data or creating separate views. This meets the requirement of dynamic enforcement and is applied directly to the table column.

Why this answer

A column mask in Unity Catalog applies a user-defined function at query time to transform or redact column values based on the invoking user's identity or group memberships. This allows the same table to return different values for different users without duplicating data or creating separate views. It is the native mechanism for dynamic column-level security and satisfies the requirement to hide email addresses from marketing analysts while still permitting aggregate queries.

Exam trap

The trap here is assuming that row filters can restrict columns or that revoking table access and using a view is the only way to hide sensitive columns, overlooking the dynamic column mask feature.

6
Multi-Selecthard

Which THREE actions are required to properly implement a secure data sharing strategy using Delta Sharing?

Select 3 answers
A.Create a SHARE object containing the tables to be shared.
B.Configure a RECIPIENT object representing the external partner.
C.Grant the recipient access to the underlying S3 bucket directly.
D.Execute a GRANT SHARE command to link the SHARE and RECIPIENT objects.
E.Copy the data to a public-facing S3 bucket for easier access.
AnswersA, B, D

The SHARE object is the container in Unity Catalog that bundles the datasets intended for distribution. Without creating this object, there is no mechanism to group the tables or views for the recipient, making it impossible to manage the scope of data being exposed to the external parties.

Why this answer

Delta Sharing provides a secure way to share data without replication. Implementing it requires creating a sharing object, defining the recipients, and granting access to specific tables. This ensures that only authorized entities can access the data, maintaining strict governance.

By abstracting the data access from the storage location, organizations can share data securely with external partners while retaining full control over who has access and when that access is revoked.

Exam trap

Candidates often forget the specific order or the need for a RECIPIENT object, incorrectly assuming that sharing is done by simply granting table access to a user's email address.

7
MCQmedium

A data engineer needs to grant a new data analyst the ability to query tables in the `sales` catalog, which is in Unity Catalog. The analyst should only be able to read data and not modify any tables or metadata. Which sequence of privileges should the engineer grant to the analyst?

A.Grant `ALL PRIVILEGES` on the catalog and rely on table-level `SELECT` to restrict modifications.
B.Grant `USE CATALOG` on `sales` and `SELECT` on all tables, without schema-level privileges.
C.Grant `USE CATALOG` on `sales`, `USE SCHEMA` on all schemas, and `SELECT` on all tables.
D.Grant `BROWSE` on the catalog, `READ VOLUME` on all volumes, and `SELECT` on all tables.
AnswerC

To query tables in Unity Catalog, a user needs `USE CATALOG` on the catalog, `USE SCHEMA` on the schema, and `SELECT` on the tables. This sequence grants the minimum privileges required for read-only access. It does not include any write or modify privileges, ensuring the analyst cannot alter data or metadata.

Why this answer

In Unity Catalog, querying a table requires a chain of privileges: `USE CATALOG` on the catalog, `USE SCHEMA` on the schema, and `SELECT` on the table. Granting these three privileges provides read-only access without allowing any modifications. This follows the principle of least privilege and ensures the analyst can only read data as required.

Exam trap

The trap here is forgetting that `USE SCHEMA` is required in addition to `USE CATALOG` and `SELECT`, or assuming that `BROWSE` or `ALL PRIVILEGES` can substitute for the necessary read-only privileges.

8
Multi-Selectmedium

Which TWO of the following are primary benefits of using Unity Catalog for managing data lineage in Databricks?

Select 2 answers
A.It provides automated, column-level lineage tracking for SQL and Python workloads.
B.It forces all data to be stored in a single, centrally managed S3 bucket.
C.It enables visibility into dependencies between datasets across different workspaces.
D.It automatically encrypts all data at rest using customer-managed keys.
E.It allows users to manually edit the lineage graph to include external data sources.
AnswersA, C

Unity Catalog integrates directly with the Databricks engine to track data movement, including column-level transformations. This automated capture ensures that lineage information is always up-to-date, removing the need for manual documentation or external tools that often fall out of sync with the actual data processing logic implemented in the notebooks.

Why this answer

Unity Catalog automatically captures lineage at the table and column level for queries executed on the platform. This metadata is crucial for impact analysis and compliance auditing. By providing a unified view of how data moves from source to destination, organizations can maintain transparency, satisfy regulatory requirements for data tracking, and easily debug complex ETL pipelines that span across multiple workspaces and various cloud storage locations.

Exam trap

Students sometimes believe lineage tracking is restricted to manual documentation or table-level only, missing its automated column-level capabilities.

9
MCQmedium

When migrating to Unity Catalog, what is the best practice for managing existing data access permissions?

A.Automatically import all Hive Metastore permissions during migration.
B.Implement a role-based access control (RBAC) model in Unity Catalog.
C.Grant every user 'ADMIN' access to simplify the migration process.
D.Use the metastore owner's credentials for all data access.
AnswerB

RBAC is the gold standard for enterprise governance. By creating functional roles and assigning them to groups in Unity Catalog, you ensure that permissions are consistent, easy to manage, and auditable. This approach scales much better than assigning permissions to individual users and avoids the complexity of manual, ad-hoc access management.

Why this answer

Adopting the principle of least privilege during migration is essential. By reviewing and re-granting permissions in the new Unity Catalog environment, you can eliminate legacy security debt and ensure that only necessary access is provided. This is the perfect opportunity to implement a robust, role-based access control (RBAC) model, ensuring the new environment is more secure than the legacy Hive Metastore it replaces, and facilitating long-term compliance.

Exam trap

Candidates often suggest migrating permissions 'as-is' from the Hive Metastore. This carries over legacy security debt and fails to take advantage of Unity Catalog's superior, centralized RBAC capabilities.

10
MCQhard

A data engineer is implementing column-level masking in Unity Catalog. They need to mask the 'email' column in the table 'prod.customers' such that only members of the 'hr_group' see the full email, while all other users see a masked version. The engineer creates a masking function and applies it using ALTER TABLE. Which statement correctly applies the mask?

A.ALTER TABLE prod.customers ALTER COLUMN email SET MASK prod.security.mask_email;
B.ALTER TABLE prod.customers ALTER COLUMN email SET MASK FUNCTION prod.security.mask_email;
C.ALTER TABLE prod.customers ALTER COLUMN email SET MASK mask_email;
D.ALTER TABLE prod.customers MODIFY COLUMN email SET MASK prod.security.mask_email;
AnswerA

This statement correctly applies a column mask using the fully qualified function name. The syntax ALTER COLUMN ... SET MASK is valid in Unity Catalog, and referencing the function with catalog.schema.name ensures it is resolved correctly. The mask will be applied to all queries unless the user is a member of the group specified in the function's logic.

Why this answer

The correct syntax to apply a column mask in Unity Catalog is ALTER TABLE table_name ALTER COLUMN column_name SET MASK function_name, where function_name is a fully qualified function that returns the masked value. This ensures that the mask is applied consistently and only authorized users see the original data.

Exam trap

The trap here is using MODIFY COLUMN or adding the FUNCTION keyword, which are not part of the SET MASK syntax.

11
MCQeasy

A data engineer is asked to implement column-level masking for a Unity Catalog table `main.hr.employees` that contains a column `ssn` with Social Security numbers. The requirement is that only members of the `hr_group` should see the full SSN, while all other users should see only the last four digits (e.g., XXX-XX-1234). The engineer decides to use a column mask function. Which statement accurately describes how to apply the mask?

A.Use row-level filters to exclude rows where the user is not in hr_group, effectively hiding sensitive data.
B.Create a view that selects all columns except ssn, and a separate view that includes ssn for hr_group, then grant appropriate privileges on each view.
C.Create a function that returns the masked value based on IS_MEMBER('hr_group'), then use ALTER TABLE ... ALTER COLUMN ssn SET MASK function_name.
D.Grant SELECT on the ssn column only to hr_group, and revoke it from all other users.
AnswerC

Unity Catalog supports column masks via a user-defined function that dynamically returns a value based on the invoking user's group membership. The function can use IS_MEMBER to check if the user belongs to hr_group and return the full SSN or a masked version accordingly. The mask is applied using ALTER TABLE ... ALTER COLUMN ... SET MASK, which attaches the function to the column. This approach enforces the masking at query time for all users except those in the specified group.

Why this answer

Column masks in Unity Catalog are implemented via user-defined functions that can dynamically return different values based on the user's group membership. The function can use IS_MEMBER to check if the user is in hr_group and return either the full SSN or a masked version. The mask is attached to the column using ALTER TABLE ...

ALTER COLUMN ... SET MASK. This enforces masking for all users except those in the specified group, meeting the requirement.

Exam trap

The trap here is thinking that column-level grants or views can provide dynamic masking, when only a column mask function can return different values based on the user.

12
MCQmedium

An organization needs to share a dataset with a client who does not use Databricks. What is the most efficient and secure way to share this data using Unity Catalog?

A.Export the data to CSV and upload it to a public FTP server.
B.Use Delta Sharing with an open sharing provider.
C.Grant the client read-only access to a dedicated Databricks workspace.
D.Create a public API endpoint that queries the table for the client.
AnswerB

Delta Sharing is the industry-standard, secure protocol for data sharing. It supports both Databricks and non-Databricks recipients, allowing for seamless integration. Because it works at the protocol level, it avoids the security risks of copying data and ensures that the provider retains full control over the shared assets.

Why this answer

Delta Sharing is an open-standard protocol that allows sharing data with any recipient, regardless of their platform or environment. By using Unity Catalog to share data, the organization maintains centralized governance and audit trails while enabling the recipient to consume the data using familiar tools. This approach is highly efficient because it avoids the need for data duplication and ensures the recipient always accesses the most current version.

Exam trap

Candidates often suggest exporting data to CSV or Parquet files for the client. This is insecure, creates data silos, and loses the benefit of centralized governance and audit logs.

13
Multi-Selecthard

Which TWO of the following are true regarding Unity Catalog's ability to govern external locations?

Select 2 answers
A.External locations require a storage credential to function.
B.Users can directly mount external locations as DBFS paths.
C.Access to external locations can be granted to users using GRANT statements.
D.External locations are automatically created for every S3 bucket in the account.
E.External locations are only supported for Delta-formatted data.
AnswersA, C

A storage credential acts as a bridge between Unity Catalog and the cloud storage provider. Without it, Unity Catalog would have no way to authenticate and access the files in the storage account on behalf of the user, making it impossible to manage external tables securely within the metastore.

Why this answer

Unity Catalog can manage access to external cloud storage locations by creating 'External Locations'. This allows administrators to grant specific permissions to users to read from or write to these storage buckets without providing them with direct cloud provider credentials. This abstraction is vital for security, as it centralizes control and auditing of data access within the platform while keeping the underlying storage infrastructure shielded from the users.

Exam trap

Candidates often assume that Unity Catalog grants access directly to the storage bucket using IAM roles. They overlook the mandatory intermediate 'storage credential' object required for this process.

14
Multi-Selectmedium

A data engineer is designing a Unity Catalog governance model for a new data lakehouse. They need to ensure that data access is auditable and that sensitive data is protected. Which two actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable audit logging for the metastore to capture all access and permission changes.
B.Use dynamic views to mask PII columns for all users except administrators.
C.Apply tags to sensitive columns and use attribute-based access control (ABAC) policies to restrict access.
D.Create a separate metastore for each department to isolate data.
E.Store all data in a single catalog and grant `ALL PRIVILEGES` to the data engineering team.
AnswersA, C

Audit logging in Unity Catalog records detailed events such as data access, permission changes, and metadata operations. Enabling it provides the necessary audit trail to track who accessed what data and when, which is essential for compliance and security monitoring. This directly addresses the requirement for auditable data access.

Why this answer

Enabling audit logging captures all access and permission changes, providing the necessary audit trail. Applying tags to sensitive columns and using ABAC policies enforces fine-grained access control based on those tags, protecting sensitive data consistently. Together, these actions create a governance model that is both auditable and secure, leveraging Unity Catalog's native capabilities for centralized policy management.

Exam trap

The trap here is assuming that broad privileges or separate metastores provide security and auditability, when in fact they increase risk and complexity, while overlooking the native audit logging and tag-based ABAC features.

15
MCQeasy

A data engineer is using Delta Sharing to share a table with an external partner. The partner needs to access the shared data using their own Databricks workspace. Which protocol does Delta Sharing use to enable this cross-platform sharing?

A.SFTP transfer of Parquet files
B.JDBC/ODBC connection to the provider's SQL warehouse
C.REST API with pre-signed URLs
D.Direct access to the provider's cloud storage with IAM roles
AnswerC

Delta Sharing uses a REST API to provide access to shared data. The recipient's client authenticates and requests data, and the server returns pre-signed URLs pointing directly to cloud storage. This allows the recipient to download the data without needing direct access to the provider's cloud storage or Databricks workspace, enabling secure cross-platform sharing.

Why this answer

Delta Sharing is an open protocol that uses a REST API to facilitate data sharing. The provider's Delta Sharing server authenticates requests and returns pre-signed URLs that allow the recipient to download data directly from cloud storage. This design enables secure, cross-platform sharing without exposing the provider's storage credentials or requiring the recipient to use Databricks.

Exam trap

The trap here is assuming that Delta Sharing uses traditional database connectivity like JDBC/ODBC or direct storage access, when it actually leverages a REST API with pre-signed URLs for secure, temporary access.

16
MCQmedium

A data engineer is configuring a Unity Catalog metastore to use a customer-managed key (CMK) for encryption at rest. The engineer has created the necessary Key Vault and key in Azure. Which additional configuration is required to enable CMK for the metastore?

A.Create a private endpoint for the Key Vault.
B.Assign the Key Vault Crypto Service Encryption User role to the Databricks managed identity used for the metastore.
C.Grant the Databricks access connector the Key Vault Crypto Service Encryption User role.
D.Enable soft delete on the Key Vault.
AnswerB

To use CMK for Unity Catalog metastore encryption, you must grant the Databricks managed identity (the one associated with the metastore) the Key Vault Crypto Service Encryption User role on the Key Vault. This allows Databricks to use the key for encrypting the metastore's data.

Why this answer

Unity Catalog CMK for Azure requires that the Databricks managed identity for the metastore has the Key Vault Crypto Service Encryption User role on the Key Vault. This role allows Databricks to perform wrap and unwrap operations with the key. Without this role assignment, the metastore cannot use the CMK for encryption.

Exam trap

The trap here is confusing the access connector identity with the metastore managed identity, or assuming network configurations like private endpoints are required for CMK.

Ready to test yourself?

Try a timed practice session using only Data Governance questions.