Courseiva
Governance →hardMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A healthcare company uses Databricks to build a RAG application over clinical notes stored in a Unity Catalog table. An auditor requires proof that only authorized personnel can view raw note text, while the RAG application must use embeddings generated from those notes. The team wants to avoid copying data outside Unity Catalog. Which approach best satisfies the auditor while preserving RAG functionality?

⚠ Common exam trap

The trap here is thinking that application-level redaction or IAM roles can substitute for Unity Catalog column masks when an auditor demands provable data-layer controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a column mask on the note text column that returns a redacted value for unauthorized users, and grant the RAG service principal access to a separate embeddings table derived from the notes.

A column mask on the sensitive note text column enforces redaction for unauthorized identities at query time, which is auditable. By having the RAG application consume a derived embeddings table instead of raw text, the application retains functionality while raw PHI remains protected. This keeps governance within Unity Catalog and satisfies the auditor's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move the clinical notes to an external location outside Unity Catalog and grant access via cloud IAM roles.

    Why it's wrong here

    Moving data outside Unity Catalog removes the centralized governance and audit trail the auditor expects. Cloud IAM roles do not provide fine-grained column-level masking or Unity Catalog lineage. This approach also complicates RAG integration because the data would no longer be managed as a Unity Catalog table.

  • ✓

    Create a column mask on the note text column that returns a redacted value for unauthorized users, and grant the RAG service principal access to a separate embeddings table derived from the notes.

    Why this is correct

    A column mask on the note text column ensures that only authorized users see raw PHI, satisfying the auditor. The RAG application can read embeddings from a derived table without needing raw text, so it continues to function. Unity Catalog enforces the mask at query time based on identity, providing auditable, centralized control.

  • ✗

    Grant the RAG application's service principal SELECT on the table and rely on the application to redact note text in its responses.

    Why it's wrong here

    Relying on the application to redact text is not enforceable by Unity Catalog and cannot be proven to an auditor. The service principal would still have direct read access to raw note text, so any compromise or logging gap could expose PHI. This approach fails the requirement of demonstrable access control at the data layer.

  • ✗

    Use a dynamic view that filters rows based on the user's group and grant the RAG service principal access to that view.

    Why it's wrong here

    A dynamic view can filter rows, but it does not mask the note text column itself. If the RAG service principal needs embeddings, it would still require access to the underlying text to generate them, or the view must expose the text. This does not satisfy the requirement to prevent unauthorized viewing of raw note text.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.