A data engineer needs to grant a production transformation service principal the ability to read PII data stored in a Unity Catalog managed table, but wants to mask specific columns containing email addresses dynamically for this principal. Which combination of Unity Catalog features should the engineer implement?
Trap 1: Grant SELECT on the table, create a row filter using SQL…
Row filters restrict entire rows based on predicate logic rather than modifying specific column values for dynamic masking. Applying a row filter would drop entire records instead of obfuscating the email string data requested by the engineering requirements.
Trap 2: Create a cloned copy of the table using shallow clone, apply static…
Static data cloning creates an independent copy of the storage location, which duplicates storage costs and introduces data drift synchronization challenges. Unity Catalog dynamic masking avoids duplication by handling transformations directly at query execution time.
Trap 3: Configure access control lists at the storage container level using…
Cloud provider IAM policies operate at the file or container storage level and cannot isolate individual table columns stored within Delta parquet files. Unity Catalog manages fine-grained governance logically above cloud storage layers for column enforcement.
- A
Grant SELECT on the table, create a row filter using SQL user-defined functions, and assign it via the catalog explorer UI.
Why it fails: Row filters restrict entire rows based on predicate logic rather than modifying specific column values for dynamic masking. Applying a row filter would drop entire records instead of obfuscating the email string data requested by the engineering requirements.
- B
Create a cloned copy of the table using shallow clone, apply static data masking via Python notebooks, and grant read access exclusively to the clone.
Why it fails: Static data cloning creates an independent copy of the storage location, which duplicates storage costs and introduces data drift synchronization challenges. Unity Catalog dynamic masking avoids duplication by handling transformations directly at query execution time.
- C
Define a SQL user-defined function leveraging conditional logic on user identity and apply it as a column mask to the email column.
Unity Catalog natively supports column masking through user-defined functions applied directly to specific columns. When the service principal queries the table, the masking function intercepts the request and replaces email characters dynamically based on the identity context.
- D
Configure access control lists at the storage container level using cloud provider IAM policies to block the principal from viewing column paths.
Why it fails: Cloud provider IAM policies operate at the file or container storage level and cannot isolate individual table columns stored within Delta parquet files. Unity Catalog manages fine-grained governance logically above cloud storage layers for column enforcement.