Databricks-GenAI-Assoc Governance Practice Question
A GenAI engineer registers a vector search index in Unity Catalog that points to a Delta table containing customer support transcripts. The security team requires that when an end-user queries the index through a Databricks notebook, the underlying table's row filter and column mask policies are enforced. Which Unity Catalog feature should the engineer configure?
⚠ Common exam trap
The trap here is assuming that security policies must be redefined on the vector search index itself, when Unity Catalog enforces them on the underlying Delta table at query time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable row-level security and column masks directly on the Delta table, and query the vector search index with the user's identity propagated.
Row filters and column masks in Unity Catalog are applied dynamically based on the identity executing the query. When a vector search index is queried with end-user identity propagation, the source table's policies are evaluated, so sensitive transcript fields are masked and rows are filtered according to group membership. This satisfies the security team's requirement without duplicating policies on the index.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply tags to the Delta table columns and rely on tag-based access control to mask values at query time.
Why it's wrong here
Tags in Unity Catalog are metadata used for classification, discovery, and attribute-based access control policies, but they do not themselves mask column values or filter rows when a vector search index is queried. Tag-based policies can complement column masks, but the actual masking logic must still be defined as a column mask function on the table.
- ✗
Create a separate vector search index for each user group and assign group-level permissions on those indexes.
Why it's wrong here
Creating separate indexes per group increases operational overhead and does not enforce the row filter or column mask policies defined on the source Delta table. It also does not scale when new groups are added, and permissions on the index alone do not mask sensitive columns at query time. The security team's requirement is policy enforcement, not index duplication.
- ✗
Use a service principal with read access to the Delta table and query the index through that principal.
Why it's wrong here
Using a service principal collapses all users into a single identity, so row filters and column masks that depend on the caller's group membership cannot be evaluated correctly. This approach also violates the principle of least privilege because every end-user effectively gains the service principal's access. It does not meet the requirement of enforcing policies per end-user.
- ✓
Enable row-level security and column masks directly on the Delta table, and query the vector search index with the user's identity propagated.
Why this is correct
Unity Catalog row filters and column masks are enforced at query time against the caller's identity. When a vector search index is queried through a SQL warehouse or notebook session that carries the end-user's identity, the underlying Delta table policies apply, ensuring the security team's masking and filtering requirements are met without duplicating rules on the index itself.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.