Courseiva
Governance →mediumMultiple Select

Databricks-GenAI-Assoc Governance Practice Question

A GenAI platform team is preparing a Unity Catalog schema to host a retrieval-augmented generation pipeline. They will store prompt templates and evaluation datasets as Delta tables, and they need to expose the pipeline to a group of application developers. The security team asks the platform team to describe how Unity Catalog privileges must be granted for the developers to query the tables. Which TWO statements correctly describe the required privilege model? (Choose two.)

⚠ Common exam trap

The trap here is granting broad catalog-level privileges such as ALL PRIVILEGES instead of the narrow USE CATALOG, USE SCHEMA, and SELECT combination required for read access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Developers need USE CATALOG on the catalog and USE SCHEMA on the schema before any table privileges take effect

Reading a table in Unity Catalog requires traversing the namespace and holding a data privilege. USE CATALOG on the catalog and USE SCHEMA on the schema make the table addressable, and SELECT on the table, or on the schema for broad coverage, authorizes the read. Together these two statements describe the minimum privilege set that lets the developers query the RAG pipeline's tables without over-granting administrative rights.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Developers need CREATE TABLE on the catalog to read prompt templates stored as Delta tables

    Why it's wrong here

    CREATE TABLE authorizes creating new tables in a schema; it has no bearing on reading existing ones. Granting it to developers who only need to query data expands the attack surface by letting them add objects. The requirement is read access to prompt templates and evaluation datasets, which SELECT provides, not the ability to create tables.

  • ✓

    Developers need USE CATALOG on the catalog and USE SCHEMA on the schema before any table privileges take effect

    Why this is correct

    Unity Catalog privilege evaluation is hierarchical. A principal must have USE CATALOG on the containing catalog and USE SCHEMA on the containing schema for table-level grants to be usable. Without those, even an explicit SELECT grant on a table is ineffective because the traversal of the namespace is blocked, so this is a genuine prerequisite for the developers.

  • ✗

    Developers must be granted ALL PRIVILEGES on the catalog so that future objects are automatically accessible

    Why it's wrong here

    ALL PRIVILEGES on a catalog is far broader than needed and grants ownership-like capabilities across every schema and object, violating least privilege. It also does not automatically propagate every future privilege in the way teams assume, and it is not a requirement for querying tables. The security team would reject this as excessive.

  • ✗

    Developers must own the schema so that they can create their own tables without further grants

    Why it's wrong here

    Ownership confers full control including the ability to drop the schema and change grants on every object, which is inappropriate for a group of application developers. The scenario only requires querying existing tables, not administering the schema. Ownership is not a prerequisite for SELECT, so this grant is both unnecessary and risky.

  • ✓

    Developers must be granted SELECT on each table, or SELECT on the schema to cover all current and future tables

    Why this is correct

    SELECT is the privilege that authorizes reading data from a table. The platform team can grant it per table for tight control, or grant SELECT at the schema level, which applies to every table in the schema including tables created later. Either satisfies the requirement that developers can query the prompt templates and evaluation datasets.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.