Courseiva

Databricks-DE-Pro · topic practice

Data Security and Compliance practice questions

This domain covers securing data in Databricks: Unity Catalog fine-grained access control (row filters, column masks), customer-managed keys for encryption at rest, network restrictions via IP access lists, and secure data sharing across accounts. Questions present realistic engineering scenarios and ask you to select the correct Unity Catalog, cloud, or sharing feature to meet a stated compliance requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Data Security and Compliance

What the exam tests

What to know about Data Security and Compliance

Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.

Unity Catalog column masks and row filters for fine-grained access control on Delta tables

Customer-managed keys (CMK) for encrypting workspace-managed data at rest

IP access lists to restrict workspace connections to approved corporate network ranges

Delta Sharing to expose tables to external partners without copying data

Watch out for

Common Data Security and Compliance exam traps

  • ▸Confusing column masks with row filters, or applying them at table level instead of via Unity Catalog functions and GRANT statements
  • ▸Assuming CMK changes who can query data, when it only controls encryption keys protecting data at rest
  • ▸Believing Delta Sharing copies data to the recipient, rather than granting governed read access to the shared table

Practice set

Data Security and Compliance questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are valid ways to audit data access within Databricks Unity Catalog?

An organization is auditing its Unity Catalog environment. Which THREE of the following actions require the 'Metastore Admin' role?

An organization is using Databricks with Unity Catalog and needs to ensure that sensitive data remains encrypted even if the underlying cloud storage is compromised. What is the most effective solution?

A data engineer at a healthcare company needs to configure a Unity Catalog external location so that the storage credential can be used only from a specific set of IP addresses. The company uses AWS and has a Databricks workspace with Unity Catalog enabled. Which of the following should the engineer do to meet this requirement?

A data engineer is configuring Unity Catalog to control access to a table containing financial records. The security team requires that members of the 'finance_auditors' group can see individual transactions but cannot view the 'account_number' column, while all other columns remain accessible. The engineer creates a dynamic view that excludes the 'account_number' column and grants SELECT on the view to 'finance_auditors'. However, users in that group report they can still see the 'account_number' data when querying the underlying table directly. What is the most likely cause of this issue?

A data engineer must grant a newly created service principal read access to a single external Delta table named `sales_raw` in Unity Catalog, without granting any other privileges on the catalog or schema. The service principal currently has no permissions. Which command should the data engineer run?

A Data Engineer at a healthcare analytics company manages a Unity Catalog table `prod.claims.phi_records` that contains protected health information. An auditor requires that any user who queries this table must first have an approved, time-bound justification recorded, and that access automatically expires after 8 hours. The engineer also wants to avoid granting permanent table privileges to the analytics group. Which Unity Catalog feature should the engineer implement?

A financial institution uses Unity Catalog and needs to ensure that all data access is logged for compliance. They want to capture both successful and failed attempts to read a specific table named 'transactions' in the 'finance' schema. The audit logs must be retained for 7 years. Which of the following should the data engineer configure to meet these requirements?

A data engineer needs to ensure that a Delta table in Unity Catalog is accessible only from a specific set of IP addresses, while other tables in the same workspace remain accessible from anywhere. The workspace has Unity Catalog enabled and uses a network security perimeter. Which approach should the data engineer use?

A data engineer must implement column-level masking on a Unity Catalog table so that only members of the group 'pii_readers' can see actual values in the 'ssn' column, while all other users see a masked value. The engineer plans to use a user-defined function (UDF) as a column mask. Which two actions are required to make the column mask effective? (Choose two.)

A data engineer is setting up a new Unity Catalog metastore for a company that must comply with GDPR. The company wants to ensure that data stored in Delta tables can be permanently deleted when a user requests erasure. Which Unity Catalog feature should the engineer use to support this requirement?

A multinational retailer uses Unity Catalog with workspaces in three regions. A compliance rule states that customer data must remain in the region where it was collected, and that users in one region must not be able to query tables in another region's catalog. The Data Engineer needs to enforce this at the metastore level. Which Unity Catalog capability should the engineer use?

A startup uses Unity Catalog and wants to give a new data engineer the ability to create tables in the `analytics` schema, read all existing tables there, and nothing else. The security lead insists on least privilege. Which set of grants should the Data Engineer's administrator apply?

A data engineer is managing a Unity Catalog metastore and needs to grant a service principal permission to create tables in a specific schema named 'sales' within the catalog 'prod'. The service principal should not have any other privileges. Which SQL statement should the engineer execute?

A Data Engineer needs to ensure that PII data in a Delta table is accessible only to members of the 'hr_admin' group, while allowing all other users to view the non-PII columns. Which Unity Catalog feature is the most efficient way to implement this requirement?

An organization is migrating to Unity Catalog and needs to secure sensitive data. Which TWO of the following statements regarding Unity Catalog security best practices are correct?

A Data Engineer needs to encrypt data at rest within a Databricks workspace that uses a customer-managed key (CMK). What is the primary purpose of this configuration?

An organization wants to restrict data access to only allow connections from specific corporate IP ranges. Which Databricks feature should be configured to implement this network security requirement?

Question 19mediummultiple choice
Read the full NAT/PAT explanation →

What is the primary function of a 'Personal Access Token' (PAT) in Databricks, and why is it considered a security risk if not managed properly?

Which of the following describes the correct behavior of Unity Catalog's 'Data Lineage' when used for security compliance?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Data Security and Compliance sessions

Start a Data Security and Compliance only practice session

Every question in these sessions is drawn from the Data Security and Compliance domain — nothing else.

Related practice questions

Related Databricks-DE-Pro topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Databricks-DE-Pro exam test about Data Security and Compliance?
Be able to choose and apply the right Unity Catalog or workspace control for a stated requirement: masks and row filters for column/row-level access, CMK for encryption at rest, IP access lists for network restrictions, and Delta Sharing for cross-account reads. Get the access-control mechanism matched to the exact requirement.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Data Security and Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Data Security and Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Databricks-DE-Pro topics?
Use the topic links above to move to related areas, or go back to the Databricks-DE-Pro question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Databricks-DE-Pro exam covers. They are not copied from any real exam or dump site.