Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

Exhibit

{"error": "PERMISSION_DENIED", "message": "User does not have USE CATALOG privilege on catalog 'finance'", "operation": "SELECT * FROM finance.revenue.q1_data"}

Refer to the exhibit. A user encounters this error when running a query. What is the correct action to resolve this issue while maintaining the security model?

⚠ Common exam trap

A common mistake is granting SELECT directly on the table without providing the necessary hierarchical traversal permissions like USE CATALOG and USE SCHEMA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant 'USE CATALOG' on the 'finance' catalog to the user.

In Unity Catalog, the security model is hierarchical. To access a table, the user needs 'USE CATALOG' on the catalog, 'USE SCHEMA' on the schema, and 'SELECT' on the table. The error indicates the hierarchy is broken at the top level. Granting the necessary privileges allows the user to traverse the object tree, ensuring that security is enforced consistently from the catalog down to the individual data object.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant 'SELECT' on the 'q1_data' table to the user.

    Why it's wrong here

    Granting 'SELECT' is insufficient because the user lacks the 'USE CATALOG' privilege. The security model requires the user to have traversal rights on all parent objects, including the catalog and schema. Without these rights, the SQL engine will fail to resolve the path to the table regardless of table-level access.

  • ✓

    Grant 'USE CATALOG' on the 'finance' catalog to the user.

    Why this is correct

    The 'USE CATALOG' privilege is required to access any object within a catalog. By granting this to the user, you enable them to traverse the hierarchy to reach the schema and the table. This is the minimum required privilege to fix the broken path and resolve the access error.

  • ✗

    Change the user's role to 'Account Admin' to bypass restrictions.

    Why it's wrong here

    Assigning 'Account Admin' is a massive security violation. Admin roles provide broad access that goes far beyond what is needed to read a specific table. Permissions should always be assigned based on the principle of least privilege, providing exactly the access required for the user's specific business function.

  • ✗

    Move the 'q1_data' table to a catalog where the user has access.

    Why it's wrong here

    Moving data to bypass security restrictions is a poor practice that leads to fragmented data management and inconsistent governance. If the user needs access to the data, the correct approach is to grant them the appropriate permissions on the existing catalog, not to move the data itself.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.