Courseiva

Databricks-DE-Pro Data Security and Compliance Practice Question

Which of the following is the most secure method for a Data Engineer to provide access to a specific Delta table for a temporary project?

⚠ Common exam trap

Candidates often suggest granting individual access or using long-lived service principals, which creates significant security debt. They overlook that Unity Catalog groups are the standard for scalable, auditable, and temporary access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adding the user to a temporary Unity Catalog group.

Granting temporary access should be done using time-bound permissions or dedicated temporary groups. In Unity Catalog, the best approach is to manage access through a group and remove the user from that group when the project concludes. This ensures a clean, auditable, and repeatable process for managing temporary access requests, which is essential for maintaining a secure environment and avoiding the 'permission creep' that happens when users retain access indefinitely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Granting ownership of the table to the user.

    Why it's wrong here

    Granting ownership is a dangerous practice for temporary tasks. It gives the user full control, including the ability to drop the table or change permissions for other users. Ownership should remain with a stable, group-based identity to ensure that the table's security posture is maintained long-term.

  • ✓

    Adding the user to a temporary Unity Catalog group.

    Why this is correct

    Using a temporary group is a best-practice method for managing project-based access. When the project ends, the user is removed from the group, effectively revoking their access immediately. This approach is clean, transparent, and easy to audit, satisfying security requirements for managing temporary data access for external or internal collaborators.

  • ✗

    Sharing the credentials of a Service Principal.

    Why it's wrong here

    Sharing credentials is a major security violation. Credentials for service principals should be kept secret and managed via secure vaults or CI/CD pipelines. Sharing them with users defeats the purpose of non-interactive identity and creates a significant risk of credential leakage and unauthorized access that cannot be traced.

  • ✗

    Creating a copy of the table for the user.

    Why it's wrong here

    Copying data for every project is inefficient and creates a security nightmare. It leads to data sprawl, making it impossible to enforce uniform security policies or ensure that the copy is deleted when the project ends. This duplicates effort and significantly increases the surface area for unauthorized data exposure.

About these practice questions

Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.