Courseiva
Data Governance →mediumMultiple Choice

Databricks-DE-Pro Data Governance Practice Question

When migrating to Unity Catalog, what is the best practice for managing existing data access permissions?

⚠ Common exam trap

Candidates often suggest migrating permissions 'as-is' from the Hive Metastore. This carries over legacy security debt and fails to take advantage of Unity Catalog's superior, centralized RBAC capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a role-based access control (RBAC) model in Unity Catalog.

Adopting the principle of least privilege during migration is essential. By reviewing and re-granting permissions in the new Unity Catalog environment, you can eliminate legacy security debt and ensure that only necessary access is provided. This is the perfect opportunity to implement a robust, role-based access control (RBAC) model, ensuring the new environment is more secure than the legacy Hive Metastore it replaces, and facilitating long-term compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automatically import all Hive Metastore permissions during migration.

    Why it's wrong here

    Automatically migrating old permissions is dangerous as it carries over outdated and potentially insecure access policies. Migration is an opportunity to clean up permissions, implement consistent naming conventions, and apply the principle of least privilege, which is far more beneficial than replicating legacy flaws into the new governance system.

  • ✓

    Implement a role-based access control (RBAC) model in Unity Catalog.

    Why this is correct

    RBAC is the gold standard for enterprise governance. By creating functional roles and assigning them to groups in Unity Catalog, you ensure that permissions are consistent, easy to manage, and auditable. This approach scales much better than assigning permissions to individual users and avoids the complexity of manual, ad-hoc access management.

  • ✗

    Grant every user 'ADMIN' access to simplify the migration process.

    Why it's wrong here

    Granting administrative access to all users is a massive security risk that violates every principle of data governance. It exposes sensitive data, increases the risk of accidental deletion or corruption, and makes compliance auditing impossible. Security should always be a primary consideration, and simplicity should never be prioritized over safety.

  • ✗

    Use the metastore owner's credentials for all data access.

    Why it's wrong here

    Relying on a single set of credentials for all data access violates the principle of accountability and makes it impossible to identify which individual or process performed specific actions. Each user or service principal should have their own identity, allowing for detailed audit logs and granular, secure access management in Unity Catalog.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.