Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A GenAI engineer has built a RAG application that queries a Delta table named `prod_ai.knowledge_base.documents` through a Databricks SQL warehouse. The application uses a service principal `sp-rag-prod` to authenticate. The table contains confidential internal documents. The security team wants to ensure that the service principal can only read the table and cannot modify or delete it. Which Unity Catalog privilege should be granted to `sp-rag-prod` on the table?

⚠ Common exam trap

The trap here is assuming that USE SCHEMA or ownership is needed for read access, when in fact SELECT alone on the table is sufficient for a service principal to query data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SELECT

The service principal needs only to read the table for the RAG application. Granting SELECT provides exactly that capability without allowing data modification. Other privileges either grant excessive rights (MODIFY, ALL PRIVILEGES) or do not permit reading table data (USE SCHEMA). SELECT is the correct least-privilege grant for a read-only consumer in Unity Catalog.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ALL PRIVILEGES

    Why it's wrong here

    ALL PRIVILEGES includes SELECT, MODIFY, and other administrative rights. Granting this would let the service principal modify or drop the table, contradicting the security team's explicit restriction. It is overly broad and violates least privilege, making it an incorrect choice for a read-only workload.

  • ✗

    USE SCHEMA

    Why it's wrong here

    USE SCHEMA allows a principal to access objects within a schema but does not grant permission to read data from a table. Without SELECT on the table, the service principal cannot query the documents. Therefore, USE SCHEMA alone is insufficient and does not meet the requirement to read the table.

  • ✗

    MODIFY

    Why it's wrong here

    MODIFY grants the ability to insert, update, and delete data in a table. This would allow the service principal to alter or remove documents, which violates the requirement that it should only read. MODIFY is too permissive for a read-only RAG application and increases the risk of accidental or malicious data changes.

  • ✓

    SELECT

    Why this is correct

    SELECT is the minimum privilege required to read data from a table. Granting SELECT to the service principal allows the RAG application to query the table without giving it the ability to insert, update, or delete data. This follows the principle of least privilege and satisfies the security team's requirement that the service principal can only read the table.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.