Courseiva

Databricks-DE-Pro · topic practice

Data Governance practice questions

This domain covers Unity Catalog's governance layer on Databricks: metastores, catalogs, schemas, grants, external locations and storage credentials, column- and row-level security, audit logging, and Delta Sharing. Questions are scenario-based, asking you to pick the correct Unity Catalog object or feature to enforce access, protect PII, or share data across accounts and non-Databricks consumers.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Data Governance

What the exam tests

What to know about Data Governance

You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.

Configuring external locations and storage credentials to govern cloud storage paths in Unity Catalog

Applying GRANT/REVOKE privileges on catalogs, schemas, tables, and views

Using column masks, row filters, and dynamic views to protect PII

Sharing data with external or non-Databricks recipients via Delta Sharing

Watch out for

Common Data Governance exam traps

  • ▸Assuming table ACLs alone protect PII; column masks or row filters are needed for fine-grained enforcement.
  • ▸Confusing external locations with storage credentials; the credential authenticates, the location defines the governed path.
  • ▸Believing Delta Sharing requires the recipient to run Databricks; recipients can consume shares with open Delta Sharing clients.

Practice set

Data Governance questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Data Governance explanation →

A data engineer needs to grant a production transformation service principal the ability to read PII data stored in a Unity Catalog managed table, but wants to mask specific columns containing email addresses dynamically for this principal. Which combination of Unity Catalog features should the engineer implement?

Refer to the exhibit. An analyst in 'finance_group' reports they cannot see the table 'main.finance.transactions_sensitive'. Based on the provided GRANT statements, why is the access denied?

Exhibit

GRANT USAGE ON CATALOG main TO `finance_group`;
GRANT SELECT ON SCHEMA main.finance TO `finance_group`;
GRANT SELECT ON TABLE main.finance.transactions TO `finance_group`;
REVOKE SELECT ON TABLE main.finance.transactions_sensitive TO `finance_group`;
Question 3mediummultiple choice
Read the full Data Governance explanation →

An organization is migrating from Hive Metastore to Unity Catalog. Which requirement is mandatory for existing tables to be managed by Unity Catalog?

Refer to the exhibit. A data engineer is setting up a Storage Credential in Unity Catalog to access an S3 bucket. Why is this policy insufficient for full external table management?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject",
        "s3:ListBucket"
      ],
      "Resource": [
        "arn:aws:s3:::my-company-data/*",
        "arn:aws:s3:::my-company-data"
      ]
    }
  ]
}
Question 5mediummultiple choice
Read the full Data Governance explanation →

Which entity in Unity Catalog acts as the primary container for managing permissions and grouping related data assets?

Refer to the exhibit. A user in 'data_science_group' attempts to query 'main.raw.sensitive_data'. What is the outcome?

Exhibit

GRANT SELECT ON CATALOG main TO `data_science_group`;
GRANT USE SCHEMA ON SCHEMA main.raw TO `data_science_group`;
REVOKE SELECT ON TABLE main.raw.sensitive_data FROM `data_science_group`;
Question 7mediummultiple choice
Read the full Data Governance explanation →

Which role is specifically required to create a new Catalog in a Unity Catalog-enabled Databricks workspace?

A data engineer is implementing column-level masking in Unity Catalog. The requirement is to show the full value of the 'email' column to members of the 'hr_group' and a partially masked value to all other users. The engineer creates a mask function and applies it using ALTER TABLE ... SET MASK. Which additional step is required to ensure that only 'hr_group' sees unmasked data?

A data engineer is configuring a Unity Catalog metastore to use customer-managed keys (CMK) for encryption at rest. They need to ensure that all data in the metastore is encrypted with the CMK, including managed tables and the metastore's internal data. Which two actions must the engineer take? (Choose two.)

Question 10mediummultiple choice
Read the full Data Governance explanation →

A data engineer is configuring attribute-based access control in Unity Catalog. The company's security policy states that analysts may only query rows from the `sales` table where the `region` column matches their assigned region, stored in the user attribute `region`. The engineer has already created a user-defined function `main.governance.region_filter(region STRING)` that returns TRUE if the region matches the user's attribute. Which SQL statement should the engineer use to enforce this policy?

A data engineer is setting up a Unity Catalog external location for an AWS S3 bucket. The storage credential uses an IAM role. The engineer must ensure that the external location can be used to create external tables and that access is restricted to the specified S3 path. Which two actions are required? (Choose two.)

Question 12mediummultiple choice
Read the full Data Governance explanation →

A data engineer at a healthcare company manages a Unity Catalog managed table `main.clinical.patient_records` that contains protected health information. The security team requires that analysts in the `analytics_group` be able to see only aggregated statistics from this table, never individual rows. The data engineer must implement a solution that dynamically filters out sensitive rows for that group while allowing other groups to see all rows. Which Unity Catalog feature should be used to meet these requirements?

Question 13hardmultiple choice
Read the full Data Governance explanation →

A data engineer needs to ensure that a Unity Catalog external table `main.finance.transactions` stored in an ADLS Gen2 container is accessible to a service principal named `etl-sp` for both reading and writing. The storage credential `adls-cred` has been created and granted to `etl-sp`. The external location `abfss://finance@datalake.dfs.core.windows.net/transactions` has been created. The engineer runs: `GRANT READ FILES, WRITE FILES ON EXTERNAL LOCATION abfss://finance@datalake.dfs.core.windows.net/transactions TO etl-sp;` but the service principal still cannot write to the table. What is the most likely reason?

A data engineer is configuring Unity Catalog to govern access to an external S3 bucket. The bucket contains multiple prefixes for different departments. The engineer wants to grant a group `dept_finance` the ability to read all files under the `s3://company-bucket/finance/` prefix and write to a sub-prefix `s3://company-bucket/finance/processed/`. Which TWO actions must the engineer take to achieve this? (Choose two.)

Question 15hardmultiple choice
Read the full Data Governance explanation →

A data engineer is using Delta Sharing to share a table `main.sales.orders` with an external partner. The partner needs to access the shared data using their own Databricks workspace. The engineer creates a share, adds the table, and creates a recipient for the partner. The partner reports that they can see the share but cannot query the table. The engineer verifies that the recipient has been granted SELECT on the share. What is the most likely cause of the issue?

A data engineer is configuring a Unity Catalog storage credential to access an AWS S3 bucket. The engineer has created an IAM role with the necessary permissions and an instance profile, and now needs to set up the storage credential. Which two statements accurately describe the requirements for the storage credential to function correctly? (Choose two.)

Question 17mediummultiple choice
Read the full Data Governance explanation →

A data engineer needs to restrict access to personally identifiable information (PII) columns in a Unity Catalog table for a group of analysts. Which Unity Catalog feature should be used to enforce this policy while ensuring data remains queryable?

Which TWO of the following are primary benefits of using Unity Catalog for managing data lineage in Databricks?

Which THREE actions are required to properly implement a secure data sharing strategy using Delta Sharing?

Question 20mediummultiple choice
Read the full Data Governance explanation →

A data engineer wants to ensure that all data in a specific catalog is encrypted at rest. Which feature should they verify is enabled within the Unity Catalog metastore configuration?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Data Governance sessions

Start a Data Governance only practice session

Every question in these sessions is drawn from the Data Governance domain — nothing else.

Related practice questions

Related Databricks-DE-Pro topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Databricks-DE-Pro exam test about Data Governance?
You must be able to choose the right Unity Catalog object or feature to enforce access, protect sensitive columns, and share data securely. The most important thing: map each governance requirement to the correct mechanism, such as grants, masks, row filters, external locations, or Delta Sharing.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Data Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Data Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Databricks-DE-Pro topics?
Use the topic links above to move to related areas, or go back to the Databricks-DE-Pro question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Databricks-DE-Pro exam covers. They are not copied from any real exam or dump site.