Courseiva

CCNA Data Security Compliance Questions

28 questions · Data Security Compliance topic · All types, answers revealed

1
MCQhard

Which of the following describes the correct behavior of Unity Catalog's 'Data Lineage' when used for security compliance?

A.It shows which users accessed the data.
B.It captures table-to-table data dependencies.
C.It manually triggers an alert when PII is detected.
D.It permanently stores the raw data content.
AnswerB

Unity Catalog lineage maps dependencies between tables, including views and downstream transformations. This is essential for compliance, as it allows engineers to see the flow of sensitive data through the ETL pipeline, making it easier to ensure that masking policies are applied to all downstream, derived datasets.

Why this answer

Data Lineage in Unity Catalog automatically captures the flow of data from source to target. This is invaluable for security compliance, as it allows administrators to trace sensitive data across the environment, identify which tables are derived from PII sources, and understand the impact of modifying or deleting specific tables. By visualizing these dependencies, teams can ensure that security policies are consistently applied throughout the data lifecycle.

Exam trap

Test-takers often assume data lineage only tracks user access events or notebook execution history, missing that its core mechanism maps table-to-table data dependencies.

2
MCQeasy

A data engineer is configuring audit logging for a Unity Catalog-enabled workspace. The security team wants to capture all access to tables and the granting of privileges. Which Databricks feature should the engineer enable to collect these audit events?

A.Workspace access control lists (ACLs).
B.Diagnostic log delivery to a cloud storage location.
C.Delta Live Tables event log.
D.Unity Catalog data lineage.
AnswerB

Databricks diagnostic logs include audit logs that record Unity Catalog data access and privilege changes. Delivering these logs to cloud storage such as S3, ADLS, or GCS allows the security team to retain and analyze them. This is the standard mechanism for capturing audit events for compliance, and it covers table access and GRANT/REVOKE operations.

Why this answer

Databricks audit logs, delivered through diagnostic log delivery, capture Unity Catalog data access and privilege changes. They are the authoritative source for security auditing and compliance. Other features like Delta Live Tables event logs, data lineage, and workspace ACLs serve different purposes and do not provide the required audit event stream.

Exam trap

The trap here is equating data lineage with audit logging, when lineage tracks data flow between objects rather than recording user access events or privilege grants.

3
MCQmedium

A data engineer needs to ensure that PII data in a Delta table is accessible only to users in the 'HR_Manager' group. Which approach provides the most granular and scalable security implementation?

A.Create separate views for each group and grant access to those views.
B.Implement column-level masking on the PII column.
C.Apply a row filter function to the table using Unity Catalog.
D.Use data partitioning to store HR data in separate folders.
AnswerC

Row filters in Unity Catalog allow for defining an expression that acts as a WHERE clause. By using the 'is_account_group_member' function, you can ensure that only members of the specified HR group see rows containing PII. This is the most efficient and manageable way to enforce granular row-level data access.

Why this answer

Using Unity Catalog's Row-Level Security (RLS) via SQL functions is the standard best practice. It dynamically filters rows at query time based on the execution context, such as the current user's group membership. This approach avoids duplicating data into siloed tables, minimizes maintenance overhead, and ensures consistent enforcement across different BI tools and compute resources connecting to the same catalog.

Exam trap

Candidates often pick view-based security or access control lists (ACLs) on storage paths, missing that Unity Catalog row filters offer granular, scalable security enforcement.

4
MCQmedium

When migrating an existing Hive metastore to Unity Catalog, what is the most important security consideration regarding object naming?

A.Table names must be all uppercase.
B.The object names must fit the catalog.schema.table structure.
C.Legacy object owners must be deleted.
D.All tables must be converted to Parquet.
AnswerB

Unity Catalog requires a strict three-level namespace. During migration, existing objects must be mapped to this structure. Failure to do so will prevent the object from being accessible within the new governed environment, potentially leading to downtime or security gaps during the transition from the legacy Hive metastore.

Why this answer

In Unity Catalog, the three-level namespace (catalog.schema.table) is mandatory. Existing Hive metastore objects often lack this structure and may contain characters or naming patterns that are incompatible with Unity Catalog's standards. Ensuring a clean naming convention during migration is not just a structural requirement; it is a security necessity to ensure that existing access policies can be correctly migrated and enforced in the new, more rigorous governance environment.

Exam trap

Candidates often focus solely on permission remapping while ignoring that Unity Catalog enforces a strict three-level namespace structure.

5
MCQhard

Refer to the exhibit. A user encounters this error when running a query. What is the correct action to resolve this issue while maintaining the security model?

A.Grant 'SELECT' on the 'q1_data' table to the user.
B.Grant 'USE CATALOG' on the 'finance' catalog to the user.
C.Change the user's role to 'Account Admin' to bypass restrictions.
D.Move the 'q1_data' table to a catalog where the user has access.
AnswerB

The 'USE CATALOG' privilege is required to access any object within a catalog. By granting this to the user, you enable them to traverse the hierarchy to reach the schema and the table. This is the minimum required privilege to fix the broken path and resolve the access error.

Why this answer

In Unity Catalog, the security model is hierarchical. To access a table, the user needs 'USE CATALOG' on the catalog, 'USE SCHEMA' on the schema, and 'SELECT' on the table. The error indicates the hierarchy is broken at the top level.

Granting the necessary privileges allows the user to traverse the object tree, ensuring that security is enforced consistently from the catalog down to the individual data object.

Exam trap

A common mistake is granting SELECT directly on the table without providing the necessary hierarchical traversal permissions like USE CATALOG and USE SCHEMA.

6
Multi-Selectmedium

Which TWO of the following are primary benefits of using Unity Catalog for data governance in Databricks?

Select 2 answers
A.It provides a centralized interface for managing permissions across multiple workspaces.
B.It automatically encrypts all data files at rest using AES-256.
C.It captures fine-grained data lineage for data assets.
D.It allows users to bypass Spark SQL for direct file-system operations.
E.It replaces the need for IAM roles when accessing external data.
AnswersA, C

Centralized access control is a core feature of Unity Catalog. It allows administrators to define permissions once in a single catalog and apply them consistently across all workspaces attached to that metastore. This drastically reduces the administrative burden and minimizes the risk of inconsistent security policies across environments.

Why this answer

Unity Catalog provides a unified governance layer that simplifies security across different workspaces. Its primary value lies in centralized access control and a unified auditing capability. By providing a single source of truth for permissions and data lineage, it significantly reduces the complexity of managing large-scale data environments while ensuring compliance with internal security policies and regulatory frameworks.

Exam trap

Candidates often select compute-performance or cluster-management advantages, incorrectly associating them with Unity Catalog instead of data governance.

7
MCQeasy

A data engineer needs to grant a service principal permission to read data from a Unity Catalog table named sales.orders. The service principal is used by an automated job and should have only the minimum necessary privileges. Which Unity Catalog privilege should be granted on the table to allow the service principal to read data?

A.ALL PRIVILEGES
B.SELECT
C.USAGE
D.MODIFY
AnswerB

SELECT is the privilege that allows reading data from a table in Unity Catalog. Granting SELECT on sales.orders to the service principal gives it the ability to query the table, which is the minimum required for read access. This follows the principle of least privilege and does not grant unnecessary capabilities such as modifying data or changing metadata.

Why this answer

In Unity Catalog, SELECT is the privilege that grants read access to a table. For a service principal that only needs to read data, granting SELECT on the specific table is the least-privilege approach. Other privileges like MODIFY or ALL PRIVILEGES would provide additional capabilities that are not required and could increase risk.

Exam trap

The trap here is confusing USAGE with read access; USAGE on a table does not allow reading data, and MODIFY is for writes, not reads.

8
MCQeasy

A data engineer is configuring a Databricks workspace with Unity Catalog. The security team wants to ensure that all data access is logged for compliance auditing. The engineer enables audit logs and configures delivery to a cloud storage location. Which Unity Catalog object should the engineer use to query audit logs for data access events?

A.The system table 'system.access.audit' in Unity Catalog.
B.The 'event_log' table in the workspace's Hive metastore.
C.The 'audit_logs' Delta table in the 'default' database.
D.The 'information_schema.audit_logs' view in Unity Catalog.
AnswerA

Unity Catalog provides system tables that contain audit logs. The 'system.access.audit' table records all access events, including data access, and can be queried directly in Databricks SQL or a notebook. This table is part of the system schema and is automatically populated when audit logging is enabled. It is the correct object for querying audit logs within Unity Catalog.

Why this answer

Unity Catalog system tables include 'system.access.audit', which records audit events such as data access. This table is automatically populated and can be queried for compliance. Other options refer to non-existent or unrelated objects.

The system table is the correct and standard way to access audit logs within Unity Catalog.

Exam trap

The trap here is confusing cluster event logs or metadata views with Unity Catalog audit logs, which are specifically stored in system tables.

9
MCQmedium

An organization wants to restrict data access to only allow connections from specific corporate IP ranges. Which Databricks feature should be configured to implement this network security requirement?

A.Unity Catalog access controls.
B.IP Access Lists.
C.Cluster-level Spark configurations.
D.Workspace-level SSO integration.
AnswerB

IP Access Lists are the specific Databricks feature designed to restrict access based on source IP. By defining a set of allowed CIDR ranges, administrators can ensure that users can only interact with the Databricks environment from authorized network locations, satisfying critical security and compliance requirements for enterprise clients.

Why this answer

Network-level security is a cornerstone of enterprise data governance. By using IP access lists, Databricks allows administrators to define a whitelist of allowed CIDR blocks. This ensures that even if a user has valid credentials, they cannot access the Databricks workspace unless they are connecting from a trusted corporate network, effectively mitigating the risk of unauthorized access from public or malicious locations.

Exam trap

Candidates often confuse 'IP Access Lists' with 'Unity Catalog permissions' or 'Workspace Entitlements.' They fail to realize that network-level traffic filtering happens before authentication.

10
MCQhard

A financial services firm stores market data in an external location registered in Unity Catalog as `s3://firm-market-data/`. The security team requires that only a specific IAM role, assumed by a Unity Catalog storage credential, can read the bucket, and that no Databricks user can bypass Unity Catalog to read the data directly with their own cloud credentials. The Data Engineer must configure the storage credential. Which configuration achieves this?

A.Create a storage credential using an access key and secret key with full S3 permissions, and attach it to the external location.
B.Create a storage credential that assumes an IAM role whose trust policy allows only the Unity Catalog metastore's IAM role, and grant the credential to the external location.
C.Create a storage credential backed by an instance profile attached to the cluster's EC2 instances, and grant it to the external location.
D.Create a storage credential that assumes an IAM role trusted by every Databricks workspace in the account, and grant it to the external location.
AnswerB

This is the supported pattern: the storage credential assumes a customer IAM role, and the role's trust policy permits only the Unity Catalog metastore's IAM role to assume it. Because the bucket policy or role permissions allow access only through that path, users cannot read the bucket with their own credentials, and Unity Catalog mediates all access. Granting the credential to the external location completes the wiring.

Why this answer

The secure pattern is a storage credential that assumes a customer IAM role whose trust policy names only the Unity Catalog metastore's IAM role. That makes the metastore the sole path to the bucket, so users cannot use their own credentials to read it, and Unity Catalog enforces privileges at query time. Static keys, broad workspace trust, and instance profiles all create alternate access paths or long-lived secrets.

Exam trap

The trap here is assuming that any storage credential that can read the bucket is sufficient, when the trust policy must specifically restrict assumption to the Unity Catalog metastore's IAM role to prevent bypass.

11
Multi-Selectmedium

Which TWO of the following are benefits of using Unity Catalog for managing data governance in a multi-workspace environment?

Select 2 answers
A.Workspaces can have independent, non-overlapping governance.
B.Centralized access control across all workspaces.
C.Unified audit trail for all data activities.
D.Increased performance for all SQL queries.
E.Automatic data encryption at the application level.
AnswersB, C

Unity Catalog provides a centralized point to manage access control. Instead of configuring permissions in every workspace, an admin can grant access in Unity Catalog, and those permissions are honored across every workspace connected to the metastore. This significantly reduces administrative overhead and ensures a uniform security policy everywhere.

Why this answer

Unity Catalog provides a unified, centralized governance layer that spans all workspaces in a Databricks account. This eliminates the need for siloed management, ensuring that users have consistent access rights, audit trails, and data discovery across the entire organization. By streamlining these processes, Unity Catalog simplifies compliance and improves collaboration while maintaining strict control over who can access which data objects across the enterprise.

Exam trap

Candidates often think Unity Catalog is only for 'data discovery' or 'metadata storage,' overlooking its primary enterprise value: unified security and auditing across multiple independent workspaces.

12
MCQhard

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The organization's security policy requires that Databricks assumes an IAM role, and that no long-lived AWS access keys are stored in Databricks. The engineer has created an IAM role with a trust policy and an external ID. Which action must the engineer take to complete the storage credential configuration in Unity Catalog?

A.Specify the IAM role ARN and the external ID in the storage credential, and ensure the role's trust policy allows the Databricks AWS account to assume it.
B.Provide the AWS access key ID and secret access key of an IAM user that has permissions to the S3 bucket.
C.Attach an instance profile to the cluster and grant the cluster's IAM role access to the S3 bucket, then create the storage credential without an IAM role.
D.Configure a service principal in Databricks, assign it the S3 bucket policy, and use its client ID and secret as the storage credential.
AnswerA

Unity Catalog storage credentials for S3 use an IAM role that Databricks assumes. The credential stores the role ARN, and the trust policy must allow the Databricks AWS account principal to assume the role, optionally with an external ID for confused deputy protection. This meets the no-long-lived-keys requirement and is the standard secure configuration.

Why this answer

For Unity Catalog to access S3 without long-lived AWS keys, a storage credential must reference an IAM role that Databricks assumes. The role's trust policy must permit the Databricks AWS account to assume it, and an external ID can be used to prevent the confused deputy problem. This design centralizes credential management and avoids storing static keys.

Exam trap

The trap here is thinking that an instance profile or a Databricks service principal can serve as a Unity Catalog storage credential for S3, when the supported method is an IAM role with a trust policy.

13
MCQhard

Refer to the exhibit. A data engineer executes this command in a Unity Catalog-enabled workspace. What is the immediate effect on the 'analyst_group'?

A.The group gains permission to read data but not to modify table metadata.
B.The group gains ownership of the table, allowing them to drop it.
C.The command fails because 'main.sales.orders' is not a fully qualified name.
D.The group gains access to both the data and the underlying S3 files directly.
AnswerA

The 'SELECT' privilege specifically allows for data retrieval from the table. It does not grant 'MODIFY' or 'OWNER' privileges, meaning the group cannot change the schema, drop the table, or alter metadata. This maintains a clean separation of duties between data consumers and data owners within the environment.

Why this answer

The command grants 'SELECT' privileges on the 'orders' table to the 'analyst_group' within the 'sales' schema of the 'main' catalog. This is a standard Unity Catalog operation that enables users within the group to query the table. Understanding these permissions is vital for auditors and engineers managing data access lifecycle, ensuring only authorized groups can read sensitive business records.

Exam trap

Examinees often confuse SELECT privileges with ALL PRIVILEGES or MODIFY, assuming that read access also grants the ability to alter table definitions.

14
MCQmedium

What is the primary function of a 'Personal Access Token' (PAT) in Databricks, and why is it considered a security risk if not managed properly?

A.It allows users to bypass multi-factor authentication.
B.It is intended for end-user dashboard access.
C.It provides long-lived programmatic access to the API.
D.It encrypts data stored in the workspace.
AnswerC

PATs provide a mechanism for scripts to authenticate with Databricks without interactive logins. Because they are long-lived, if they are hardcoded in scripts or exposed in logs, they provide an attacker with persistent access to the user's workspace, creating a significant security vulnerability if not rotated regularly.

Why this answer

Personal Access Tokens (PATs) are used for programmatic access to Databricks REST APIs. They authenticate the user and inherit their permissions. The risk lies in their longevity; if an unexpired token is leaked, an attacker can impersonate the user without needing to re-authenticate via SSO.

Therefore, limiting token duration and using service principals for automated tasks are crucial security measures to protect the platform.

Exam trap

Students mistakenly believe PATs bypass user permissions or act as cluster-level configs, ignoring that they inherit the creating user's full privileges.

15
MCQmedium

A data engineer is configuring a Unity Catalog external location to allow access to an S3 bucket. The security team requires that all access to the bucket be authenticated using a specific IAM role, and that the credentials not be stored in Databricks. Which Unity Catalog object should the engineer create to meet this requirement?

A.A storage credential that assumes the IAM role using AWS STS.
B.A storage credential that references the IAM role via an instance profile.
C.A service principal with an attached IAM role in AWS.
D.An external location that directly embeds the IAM role's access key and secret key.
AnswerA

A Unity Catalog storage credential encapsulates an IAM role that Databricks assumes using AWS STS to obtain temporary credentials. This avoids storing long-lived credentials in Databricks and allows the security team to control access via the IAM role's trust policy. It is the correct way to authenticate access to an S3 bucket from Unity Catalog.

Why this answer

Unity Catalog storage credentials are the correct object for authenticating to cloud storage. They reference an IAM role that Databricks assumes via AWS STS, providing temporary credentials without storing secrets. External locations then reference the storage credential and define the bucket path.

This design meets the requirement of using a specific IAM role and avoiding stored credentials.

Exam trap

The trap here is confusing instance profiles, which are used for cluster-level S3 access outside Unity Catalog, with storage credentials, which are the Unity Catalog mechanism for external locations.

16
Multi-Selectmedium

A Data Engineer is implementing column-level security on a Unity Catalog table `sales.customers` that contains `email`, `ssn`, and `region` columns. The requirement is that analysts in the `analyst` group see only the last four digits of `ssn` and a hashed `email`, while members of the `compliance` group see full values. The engineer plans to use column masks. Which TWO actions are required to meet the requirement? (Choose two.)

Select 2 answers
A.Grant the `analyst` group the `USE SCHEMA` privilege on the schema containing `sales.customers`.
B.Create a masking function that inspects the invoking user's group membership and returns either the full value or a masked value.
C.Apply the masking function to the `ssn` and `email` columns using ALTER TABLE ... ALTER COLUMN ... SET MASK.
D.Revoke SELECT on the `ssn` and `email` columns from the `analyst` group before applying the mask.
E.Create a row filter function that returns TRUE only for rows where the user belongs to the `compliance` group.
AnswersB, C

A column mask function can branch on the current user's groups using functions such as `is_account_group_member`, returning the raw value for `compliance` and a masked value for everyone else. This centralizes the logic and ensures analysts receive only the truncated SSN or hashed email while compliance sees full data. Without this conditional function, the mask cannot differentiate the two groups.

Why this answer

Column masks require two things: a function that decides the returned value based on the invoking user's groups, and the ALTER TABLE statement that binds that function to each sensitive column. Together they let analysts see truncated SSN and hashed email while compliance sees full values. Revoking column SELECT breaks queries, row filters hide rows instead of transforming values, and USE SCHEMA is only a prerequisite.

Exam trap

The trap here is treating column masks as an access denial mechanism and revoking column SELECT, when masks are meant to transform values while SELECT remains granted.

17
MCQmedium

An organization requires that all data stored in their S3 bucket used by Databricks be encrypted using a Customer Managed Key (CMK). Which configuration must be performed to meet this requirement?

A.Enable server-side encryption with S3-managed keys (SSE-S3).
B.Configure the workspace to use a Customer Managed Key for DBFS root.
C.Set the encryption policy in the Spark configuration of every cluster.
D.Apply an IAM role to the storage bucket that restricts access to the root user.
AnswerB

Configuring the Databricks workspace to use a Customer Managed Key for the DBFS root ensures that all data stored in the default storage location is encrypted with your specific KMS key. This fulfills the compliance requirement by centralizing the cryptographic control of data at the root storage level.

Why this answer

When using Customer Managed Keys (CMK) for storage encryption, the Databricks environment must be configured with the appropriate IAM policies and KMS key grants. This ensures that the Databricks compute resources have the necessary permissions to perform cryptographic operations. Configuring this correctly at the storage and workspace level is essential for compliance with data protection standards like HIPAA or GDPR.

Exam trap

Candidates mistakenly select standard table-level encryption or application-level settings instead of the workspace-level configuration required for DBFS root encryption.

18
Multi-Selecthard

A data engineer is implementing fine-grained access control on a Delta table in Unity Catalog that contains sensitive customer data. The requirement is to mask the `credit_card` column for all users except members of the `finance` group, and to filter out rows where the `region` column is not in the user's allowed regions. Which two Unity Catalog features should the engineer use? (Choose two.)

Select 2 answers
A.Table ACLs that grant SELECT only on specific columns.
B.Workspace-level IP access list to restrict access to the table.
C.Row filter using a SQL UDF that checks the user's allowed regions against the `region` column.
D.Dynamic view that joins the table with a mapping table of user regions.
E.Column mask using a SQL UDF that returns the masked value unless the user is in the `finance` group.
AnswersC, E

Row filters in Unity Catalog apply a SQL UDF that evaluates per row and returns a boolean, allowing you to restrict which rows are visible. This is the correct feature to filter out rows where the `region` is not in the user's allowed regions, based on the invoking user's identity or group membership.

Why this answer

Unity Catalog provides native row filters and column masks for fine-grained access control. A column mask with a SQL UDF can conditionally reveal or obscure the credit card column based on group membership, while a row filter with a SQL UDF can restrict rows by region. Together they implement the required masking and filtering directly on the table without requiring a separate view.

Exam trap

The trap here is assuming that table ACLs support column-level grants, when Unity Catalog achieves column-level security through column masks or views, not through GRANT on individual columns.

19
MCQhard

A Data Engineer needs to encrypt data at rest within a Databricks workspace that uses a customer-managed key (CMK). What is the primary purpose of this configuration?

A.To increase the read throughput of Delta tables.
B.To enable transient data encryption for cluster nodes.
C.To control the lifecycle of the encryption keys used for storage.
D.To bypass the need for Unity Catalog permissions.
AnswerC

The primary purpose of CMK is to allow the organization to manage the lifecycle of encryption keys. This includes rotation policies and the ability to immediately revoke access to the storage account, ensuring that the cloud provider cannot access the data without the customer's active cooperation.

Why this answer

Using a customer-managed key (CMK) provides an additional layer of security and control over data at rest in cloud storage, such as S3 or ADLS. By managing the key in the cloud provider's Key Management Service (KMS), the organization can revoke access to the data at any time by disabling the key. This is a common requirement for high-compliance industries that need verifiable control over their encrypted data.

Exam trap

Candidates often confuse CMK with data-in-transit encryption (TLS) or think it is primarily for performance acceleration. They miss that CMK is strictly about administrative control over encryption key lifecycles.

20
MCQmedium

A data engineer is configuring a Unity Catalog external location to securely access data in an AWS S3 bucket. The engineer has already created an IAM role with the necessary permissions and configured the storage credential. Which additional step is required to allow Databricks to access the S3 bucket?

A.Generate a personal access token (PAT) for the IAM role and store it in Databricks secrets.
B.Configure the S3 bucket policy to allow access from the Databricks control plane's IP addresses.
C.Attach the IAM role directly to the Databricks workspace's EC2 instances so they can assume the role.
D.Create an external location that references the storage credential and the S3 bucket path, then grant appropriate privileges on the external location.
AnswerD

An external location combines a storage credential with a cloud storage path. After creating the storage credential, you must create an external location that points to the S3 bucket path and uses that credential. Then, you grant privileges like CREATE EXTERNAL TABLE or READ FILES on the external location to users or groups. This is the required step to enable access.

Why this answer

After creating a storage credential, you must create an external location that maps the credential to a specific S3 path. Then, you grant privileges on that external location to allow access. This is the standard Unity Catalog workflow for external data.

The other options describe incorrect or legacy methods.

Exam trap

The trap here is thinking that attaching IAM roles to instances or using secrets is sufficient, when Unity Catalog requires an external location object to bridge the credential and path.

21
MCQhard

A data engineer is designing a solution to share a Delta table with an external partner organization. The partner uses a different Databricks account and must be able to read the table, but the data must not be copied outside the provider's cloud storage. The provider uses Unity Catalog and wants to minimize operational overhead while ensuring the partner sees only the shared table. Which Unity Catalog feature should the engineer use?

A.A foreign table that points to the partner's storage location.
B.Grant SELECT on the table to the partner's service principal and configure cross-account IAM access.
C.Delta Sharing
D.A deep clone of the table into a storage location accessible by the partner.
AnswerC

Delta Sharing is a secure data sharing protocol that allows sharing data across organizations without copying it. The provider creates a share containing the table and grants the recipient access. The recipient reads the data using their own compute, and the data remains in the provider's storage. This minimizes operational overhead and meets the requirement of not copying data outside the provider's storage.

Why this answer

Delta Sharing is designed for cross-organization data sharing without copying data. The provider defines a share, adds the table, and grants the recipient access. The recipient can then read the shared data using their own Databricks workspace or other compatible clients.

The data stays in the provider's storage, and the provider retains control over access. This meets the requirements with minimal overhead.

Exam trap

The trap here is confusing Delta Sharing with cloning or foreign tables; only Delta Sharing allows reading data in place across accounts without copying.

22
MCQmedium

Which of the following is the most secure method for a Data Engineer to provide access to a specific Delta table for a temporary project?

A.Granting ownership of the table to the user.
B.Adding the user to a temporary Unity Catalog group.
C.Sharing the credentials of a Service Principal.
D.Creating a copy of the table for the user.
AnswerB

Using a temporary group is a best-practice method for managing project-based access. When the project ends, the user is removed from the group, effectively revoking their access immediately. This approach is clean, transparent, and easy to audit, satisfying security requirements for managing temporary data access for external or internal collaborators.

Why this answer

Granting temporary access should be done using time-bound permissions or dedicated temporary groups. In Unity Catalog, the best approach is to manage access through a group and remove the user from that group when the project concludes. This ensures a clean, auditable, and repeatable process for managing temporary access requests, which is essential for maintaining a secure environment and avoiding the 'permission creep' that happens when users retain access indefinitely.

Exam trap

Candidates often suggest granting individual access or using long-lived service principals, which creates significant security debt. They overlook that Unity Catalog groups are the standard for scalable, auditable, and temporary access control.

23
Multi-Selecthard

An organization is migrating to Unity Catalog and needs to secure sensitive data. Which TWO of the following statements regarding Unity Catalog security best practices are correct?

Select 2 answers
A.Assign table ownership to individual users for better tracking.
B.Use groups instead of individual users for access grants.
C.Ensure that the metastore admin has access to all data.
D.Use Service Principals for automated CI/CD job execution.
E.Public access should be granted to the root catalog.
AnswersB, D

Granting permissions to groups rather than individual users simplifies access management and reduces the risk of human error. When a new user joins a team, they automatically inherit the correct permissions by being added to the relevant group, ensuring consistent security posture across the entire data platform.

Why this answer

Effective security in Unity Catalog requires a deep understanding of object ownership and the principle of least privilege. By ensuring that objects are owned by a group rather than an individual, organizations prevent access gaps when staff turnover occurs. Additionally, using service principals for automated pipelines ensures that data access is tied to the workload rather than a user, maintaining consistent security postures across environments.

Exam trap

Test-takers frequently assume individual user accounts are acceptable for production CI/CD pipelines or object ownership, overlooking the maintenance nightmare when employees leave the organization.

24
MCQhard

A data engineer is tasked with ensuring that sensitive information in a 'customer' table is masked for all users except the 'Data_Science' group. What is the correct Unity Catalog feature to implement?

A.Create a view that performs a CASE statement to mask the column.
B.Apply a masking policy using a SQL function to the table column.
C.Use the 'DROP COLUMN' command to remove sensitive columns.
D.Encrypt the column using an external library before writing to Delta.
AnswerB

Unity Catalog supports masking policies using SQL functions. By defining a function that checks for group membership and returns either the original or masked value, you apply a central policy. This is the official and most efficient method to handle dynamic masking requirements across the entire organization.

Why this answer

Dynamic data masking in Unity Catalog allows for the creation of masking functions that return obfuscated values based on the current user's role. By assigning these functions to columns, administrators ensure that sensitive data is protected while remaining available for authorized users. This approach is highly effective for maintaining data usability without compromising the security of PII.

Exam trap

Candidates mistakenly choose physical data duplication or static table views with restricted access rather than dynamic column masking.

25
Multi-Selecthard

When configuring a Service Principal to access a Unity Catalog-enabled workspace, which THREE steps are required to ensure secure and functional access?

Select 3 answers
A.Create the Service Principal in the cloud provider's IAM.
B.Assign the Service Principal the 'Owner' role on the entire workspace.
C.Grant the Service Principal access to the required Unity Catalog objects.
D.Add the Service Principal to the workspace using the SCIM API or UI.
E.Enable multi-factor authentication (MFA) for the Service Principal.
AnswersA, C, D

The Service Principal must originate in the cloud provider's IAM system, such as AWS IAM or Azure AD. This provides the identity that Databricks will use to authenticate requests, ensuring that the identity is managed and secured according to the organization's enterprise-wide security standards and policies.

Why this answer

Service Principals are the recommended way to automate CI/CD and production jobs. Configuring them correctly involves provisioning the identity in the cloud provider, syncing it with the Databricks account, and granting specific permissions on the data objects. This lifecycle management is critical for operational security and ensuring that automated processes have the least privilege required to function correctly in a production environment.

Exam trap

Test-takers frequently forget that service principals must be explicitly added to the workspace via SCIM alongside cloud IAM configuration.

26
MCQmedium

A data engineering team stores customer transaction data in a Unity Catalog managed table named prod.finance.transactions. The security team requires that any query referencing this table, whether through a view or directly, is recorded with the identity of the user who ran it, and that the audit logs are retained for 365 days. The workspace uses Unity Catalog and has audit logs delivered to a cloud storage location. Which configuration should the data engineer verify or set to meet the requirement that all access to the table is captured with the user identity?

A.Configure a cluster policy that enforces the use of a specific Spark log4j appender to send query logs to the audit storage.
B.Enable table access control on the cluster and set the cluster's Spark configuration to log all queries.
C.Ensure that Unity Catalog audit logging is enabled for the account and that the audit log delivery is configured to the required cloud storage with appropriate retention.
D.Create a view over the table and grant SELECT on the view only, so that all access goes through the view and is logged.
AnswerC

Unity Catalog automatically records access events, including the user identity, for all queries against Unity Catalog objects. These events are written to the account-level audit log. To meet the 365-day retention requirement, the audit log must be delivered to a cloud storage location configured with the necessary lifecycle policy. No additional cluster-level setting is needed to capture the user identity.

Why this answer

Unity Catalog audit logs are generated at the account level and capture the identity of the user performing the action on Unity Catalog objects. To satisfy a retention requirement, the logs must be delivered to durable cloud storage with a retention policy. Cluster-level or view-level controls do not replace this native audit logging, and they do not provide the same structured, tamper-resistant record.

Exam trap

The trap here is assuming that cluster-level query logging or view-based access is equivalent to Unity Catalog audit logging, which already records user identity for all Unity Catalog access.

27
MCQmedium

A data engineer is setting up a new Unity Catalog metastore. What is the primary purpose of the 'Metastore Admin' role?

A.To create and manage compute clusters for all users.
B.To define the root storage location and manage top-level catalogs.
C.To monitor and respond to daily system health alerts.
D.To approve all requests for new user sign-ups.
AnswerB

The Metastore Admin has the authority to configure the root storage location and create catalogs, which are the containers for all other data objects. This role is responsible for the overall hierarchy and security structure of the data estate, making it the most critical role for initial setup.

Why this answer

The Metastore Admin is the highest-privilege role in Unity Catalog, responsible for the initial configuration and top-level governance settings. This role is essential for establishing the security foundation of the platform, including catalog creation and cross-workspace access control. Proper management of this role is critical to prevent privilege escalation and ensure that only authorized personnel can define the organization's overall data governance strategy.

Exam trap

Candidates often confuse the Metastore Admin with a Workspace Admin. They assume the role manages individual workspace settings rather than the overarching metastore-level governance and root storage configurations for the entire account.

28
MCQmedium

A Data Engineer needs to ensure that PII data in a Delta table is accessible only to members of the 'hr_admin' group, while allowing all other users to view the non-PII columns. Which Unity Catalog feature is the most efficient way to implement this requirement?

A.Create separate physical tables for HR and general users.
B.Use standard SQL views for every user to filter columns.
C.Apply a column mask using a SQL function in Unity Catalog.
D.Assign the 'SELECT' permission on individual columns in the UI.
AnswerC

Column masking in Unity Catalog allows administrators to define functions that dynamically redact or obscure data based on the user's role. This provides a unified, policy-driven approach to data security that is applied at query time, ensuring compliance without the complexity of managing numerous views or physical tables.

Why this answer

Unity Catalog's row-level security and column-level masking allow for fine-grained access control directly at the table level. By defining a masking function or a column filter, the Data Engineer ensures that the security policy is enforced consistently across all SQL warehouses and Databricks Runtime versions. This approach centralizes governance, reduces administrative overhead compared to view-based security, and ensures that data privacy compliance is maintained without duplicating data or creating multiple table versions.

Exam trap

Candidates frequently suggest creating duplicate filtered views or tables for different user groups, ignoring Unity Catalog's modern column masking capabilities which provide centralized efficiency.

Ready to test yourself?

Try a timed practice session using only Data Security Compliance questions.