Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A data engineer wants to share a specific subset of sensitive PII data with an external department using Unity Catalog. The engineering team must ensure the data is anonymized dynamically based on the user's role without creating physical copies. Which feature is most appropriate?

⚠ Common exam trap

Candidates frequently choose to create physical duplicate tables with redacted columns, forgetting that Unity Catalog supports dynamic row filters and column masking natively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a masking function to the column and use row filters in Unity Catalog.

Unity Catalog row-level security and column-level masking allow for dynamic data governance. By applying a masking function using 'current_user_role()' or 'is_account_group_member()', administrators can ensure that users see redacted data without duplicating the underlying storage. This approach centralizes governance policies, simplifies auditing, and ensures that sensitive data exposure is strictly controlled at the query execution time across all compute resources within the Unity Catalog metastore environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a temporary view that filters rows using a WHERE clause and grants SELECT access.

    Why it's wrong here

    While views provide a layer of abstraction, they are not dynamically scoped to specific user roles or attributes in the same way native Unity Catalog masking functions are. Maintaining numerous views for different personas creates significant administrative overhead and increases the risk of data leakage through accidental view propagation.

  • ✓

    Apply a masking function to the column and use row filters in Unity Catalog.

    Why this is correct

    Unity Catalog supports dynamic data masking and row filters, which apply policies at query time based on user identity. This enables granular control over data access without duplicating data or creating complex view hierarchies. It is the industry-standard method for enforcing privacy compliance across the Databricks Data Intelligence Platform.

  • ✗

    Export the data to a new table with masked columns and grant access to the department.

    Why it's wrong here

    Creating physical copies for governance purposes violates the principle of minimizing data redundancy and increases storage costs. Furthermore, it creates a 'stale data' problem where the masked copy may fall out of sync with the primary source of truth, necessitating complex and fragile synchronization pipelines for updates.

  • ✗

    Configure access control lists (ACLs) on the underlying S3 bucket or ADLS container.

    Why it's wrong here

    Cloud provider ACLs operate at the object storage layer and lack awareness of relational schema or user roles within Databricks. Managing security at this level is coarse-grained and does not support the dynamic masking required to hide specific column values from unauthorized users while allowing access to rows.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.