Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A data scientist is using Databricks to fine-tune a large language model. The training data is stored in a Unity Catalog table that contains sensitive customer information. The data scientist needs to read the table but should not be able to see the raw values of certain columns. Which Unity Catalog feature should be used to dynamically mask the sensitive columns based on the user's group membership?

⚠ Common exam trap

Many candidates confuse row-level security with column-level masking, or assuming that encryption provides dynamic masking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic column masking

Dynamic column masking in Unity Catalog enables the data scientist to see masked values for sensitive columns based on their group membership. By applying a column mask that checks group membership, the raw values are hidden from unauthorized users while still allowing the data scientist to read the table for fine-tuning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Dynamic column masking

    Why this is correct

    Dynamic column masking allows you to define a masking function that returns different values depending on the user's group membership. This enables sensitive columns to be masked for unauthorized users while remaining visible to authorized ones, exactly matching the scenario.

  • ✗

    Column-level encryption

    Why it's wrong here

    Column-level encryption encrypts data at rest, but it does not dynamically mask values based on user identity. Authorized users would still see decrypted values if they have the decryption key. It does not provide the dynamic, group-based masking required here.

  • ✗

    Attribute-based access control

    Why it's wrong here

    Attribute-based access control (ABAC) is a broader access control paradigm, but in Unity Catalog, dynamic masking is implemented via column masks, not ABAC. ABAC may govern access but does not itself provide the masking behavior described.

  • ✗

    Row-level security

    Why it's wrong here

    Row-level security filters rows based on conditions, but it does not mask column values. The requirement is to hide specific column values, not to restrict which rows are visible. Therefore, row-level security is not the appropriate feature.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.