Databricks-GenAI-Assoc Governance Practice Question
A healthcare company uses Databricks to build a GenAI chatbot that answers questions from patient records stored in a Delta table. The records contain PHI, and the company must ensure that the chatbot never returns PHI to unauthorized users. The security team wants to enforce policies at the data layer so that even if the LLM is manipulated, it cannot access PHI. Which Unity Catalog feature should be used to dynamically redact PHI columns based on the user's group membership?
⚠ Common exam trap
Many candidates confuse row-level security with column-level security; row filters remove entire rows, while column masks selectively redact values within columns, which is necessary when only specific fields contain PHI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Column masks using a user-defined function that returns redacted values for unauthorized groups.
Unity Catalog column masks are designed to dynamically redact column values based on the user's identity or group membership. By applying a mask function to PHI columns, the healthcare company can ensure that unauthorized users see redacted values while authorized users see the actual data. This enforcement occurs at the data layer, preventing PHI leakage even if the LLM is manipulated, and it applies to all queries against the table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row-level security with a filter function that excludes rows containing PHI.
Why it's wrong here
Row-level security filters entire rows, not specific columns. If PHI is spread across columns within a row, filtering rows would remove non-PHI data as well, degrading the chatbot's usefulness. The requirement is to redact specific PHI columns while keeping other columns visible, so a column-level mechanism is needed. Row filters alone cannot selectively hide column values based on group membership.
- ✗
Attribute-based access control (ABAC) policies defined on the catalog to deny access to PHI columns.
Why it's wrong here
ABAC policies in Unity Catalog can grant or deny access to securable objects, but they do not dynamically redact column values based on group membership at query time. Denying access to a column would cause queries to fail rather than returning redacted data, which would break the chatbot for unauthorized users. The requirement is to redact PHI while still allowing queries, so column masks are the correct feature.
- ✓
Column masks using a user-defined function that returns redacted values for unauthorized groups.
Why this is correct
Unity Catalog column masks allow dynamic redaction of column values based on the invoking user's group membership. A mask function can check 'is_account_group_member()' and return a redacted value (e.g., 'REDACTED') for users not in an authorized group, while returning the original value for authorized users. This enforces PHI protection at the data layer, ensuring the chatbot cannot retrieve PHI for unauthorized users even if the LLM is manipulated.
- ✗
Dynamic view that joins the patient records with a permissions table and filters out PHI columns.
Why it's wrong here
A dynamic view can restrict rows but cannot dynamically redact column values based on the user's group without complex logic. More importantly, views are separate objects that must be maintained and granted access to, and they do not automatically apply to all queries against the base table. The security team wants enforcement at the data layer for any query, so column masks on the base table are more appropriate.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.