Databricks-DE-Pro Data Governance Practice Question
Which TWO of the following are true regarding Unity Catalog's ability to govern external locations?
⚠ Common exam trap
Candidates often assume that Unity Catalog grants access directly to the storage bucket using IAM roles. They overlook the mandatory intermediate 'storage credential' object required for this process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
External locations require a storage credential to function.
Unity Catalog can manage access to external cloud storage locations by creating 'External Locations'. This allows administrators to grant specific permissions to users to read from or write to these storage buckets without providing them with direct cloud provider credentials. This abstraction is vital for security, as it centralizes control and auditing of data access within the platform while keeping the underlying storage infrastructure shielded from the users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
External locations require a storage credential to function.
Why this is correct
A storage credential acts as a bridge between Unity Catalog and the cloud storage provider. Without it, Unity Catalog would have no way to authenticate and access the files in the storage account on behalf of the user, making it impossible to manage external tables securely within the metastore.
- ✗
Users can directly mount external locations as DBFS paths.
Why it's wrong here
Unity Catalog's external location model is intended to replace or augment traditional DBFS mounts. While it provides similar functionality, it does not rely on global DBFS mounts. Instead, it provides granular, policy-driven access to data files, which is a much more secure and manageable approach for enterprise data governance.
- ✓
Access to external locations can be granted to users using GRANT statements.
Why this is correct
Unity Catalog allows administrators to use the GRANT command to authorize specific users or groups to read or write to an external location. This declarative security model is key to modern governance, as it makes access management programmatic and auditable, aligning with the overall goal of centralized control and security.
- ✗
External locations are automatically created for every S3 bucket in the account.
Why it's wrong here
Unity Catalog does not automatically import or create external locations for all S3 buckets. This would be a security nightmare, as it would expose all storage resources by default. Administrators must explicitly register each location, ensuring that only necessary data assets are governed and made accessible within the platform.
- ✗
External locations are only supported for Delta-formatted data.
Why it's wrong here
Unity Catalog supports various data formats in external locations, not just Delta. While Delta is the recommended format for performance and governance, Unity Catalog is designed to be flexible, allowing users to register and govern external tables in formats like Parquet, CSV, or JSON for compatibility with legacy systems.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.