Which THREE of the following are valid ways to audit data access within Databricks Unity Catalog?
Trap 1: Using the 'SHOW PERMISSIONS' SQL command.
While 'SHOW GRANTS' is a valid command to inspect current permissions on an object, it is not an audit log. It shows the current state of access control, not the history of who accessed the data or when that access occurred, which is necessary for comprehensive security auditing.
Trap 2: Manually checking the user's home folder.
Manually checking files is not an audit process and does not provide a record of activity. Auditing must be centralized, automated, and immutable. Checking individual home folders is inefficient, prone to error, and fails to provide the high-level oversight required for a secure enterprise data platform.
- A
Querying system tables (e.g., system.access.audit).
System tables provide an easy, SQL-based way to analyze audit logs. They are built into the Unity Catalog environment, allowing engineers to query access patterns directly from their notebooks. This is the recommended method for creating dashboards or alerts regarding unauthorized access attempts or suspicious activity patterns.
- B
Reviewing workspace-level audit logs in the cloud provider.
Beyond Databricks internal logs, cloud provider logs (like AWS CloudTrail or Azure Monitor) capture infrastructure-level events. These are essential for a holistic audit trail that includes not just data access, but also changes to the underlying compute, networking, and identity configurations within the cloud environment.
- C
Using the 'SHOW PERMISSIONS' SQL command.
Why it fails: While 'SHOW GRANTS' is a valid command to inspect current permissions on an object, it is not an audit log. It shows the current state of access control, not the history of who accessed the data or when that access occurred, which is necessary for comprehensive security auditing.
- D
Accessing the account-level diagnostic logs via S3/ADLS.
Diagnostic logs delivered to an external cloud storage location provide a permanent, immutable record of all workspace activities. This is often a mandatory requirement for compliance frameworks like SOC2 or HIPAA, as it ensures that logs can be retained long-term, independent of the workspace lifecycle.
- E
Manually checking the user's home folder.
Why it fails: Manually checking files is not an audit process and does not provide a record of activity. Auditing must be centralized, automated, and immutable. Checking individual home folders is inefficient, prone to error, and fails to provide the high-level oversight required for a secure enterprise data platform.