Databricks-DE-Pro Data Security and Compliance Practice Question
Exhibit
{"action": "GRANT", "privilege": "SELECT", "object": "table", "securable": "main.sales.orders", "grantee": "analyst_group"}Refer to the exhibit. A data engineer executes this command in a Unity Catalog-enabled workspace. What is the immediate effect on the 'analyst_group'?
⚠ Common exam trap
Examinees often confuse SELECT privileges with ALL PRIVILEGES or MODIFY, assuming that read access also grants the ability to alter table definitions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The group gains permission to read data but not to modify table metadata.
The command grants 'SELECT' privileges on the 'orders' table to the 'analyst_group' within the 'sales' schema of the 'main' catalog. This is a standard Unity Catalog operation that enables users within the group to query the table. Understanding these permissions is vital for auditors and engineers managing data access lifecycle, ensuring only authorized groups can read sensitive business records.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The group gains permission to read data but not to modify table metadata.
Why this is correct
The 'SELECT' privilege specifically allows for data retrieval from the table. It does not grant 'MODIFY' or 'OWNER' privileges, meaning the group cannot change the schema, drop the table, or alter metadata. This maintains a clean separation of duties between data consumers and data owners within the environment.
- ✗
The group gains ownership of the table, allowing them to drop it.
Why it's wrong here
The 'GRANT' command provided only assigns the 'SELECT' privilege. It does not transfer ownership of the securable object. Ownership remains with the original creator or current owner unless explicitly transferred using the 'ALTER TABLE' command. Dropping the table requires higher-level privileges that are not included here.
- ✗
The command fails because 'main.sales.orders' is not a fully qualified name.
Why it's wrong here
In Unity Catalog, the 'catalog.schema.table' hierarchy is the standard fully qualified name format. 'main' is the catalog, 'sales' is the schema, and 'orders' is the table. The syntax provided is correct, and the command will succeed provided the caller has the necessary 'GRANT' privileges.
- ✗
The group gains access to both the data and the underlying S3 files directly.
Why it's wrong here
Unity Catalog decouples data access from storage access. Granting SELECT on a table provides access through the Databricks SQL engine, not direct access to the underlying S3 bucket. Users cannot bypass the engine to read files directly unless they have separate IAM permissions on the S3 bucket.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.