Databricks-GenAI-Assoc Application Development Practice Question
A team needs to provide fine-grained access control to an LLM application that uses a vector index stored in a Delta table. Which Unity Catalog feature should they use to restrict access to specific rows based on user identity?
⚠ Common exam trap
Candidates often confuse Row-Level Security with Column-Level Security or Attribute-Based Access Control. RLS is specifically designed to filter rows based on the current user's identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Row-level security (RLS)
Row-level security (RLS) in Unity Catalog allows administrators to define policies that filter data returned from tables based on the user's identity. By applying these policies to the Delta table used as a knowledge base, the team ensures that the LLM only retrieves information the user is authorized to see. This is essential for compliance and security in multi-tenant or sensitive information application environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Column-level masking
Why it's wrong here
Column-level masking hides or transforms the values of specific columns, such as emails or names. While useful for data privacy, it does not prevent a user from retrieving sensitive information contained in rows they are not authorized to view, making it insufficient for row-level access control.
- ✓
Row-level security (RLS)
Why this is correct
Row-level security policies filter rows at query time based on user attributes. When an application queries the vector index, the Databricks engine automatically applies the filter, ensuring the RAG model only has access to authorized context, which is the standard mechanism for implementing secure data-aware applications.
- ✗
Workspace-level permissions
Why it's wrong here
Workspace permissions control access to notebooks, clusters, and dashboards, not the data within tables. These permissions are too broad for controlling access to individual rows within a dataset, making them an ineffective tool for enforcing granular data governance on the information used by an LLM application.
- ✗
Access Control Lists (ACLs)
Why it's wrong here
ACLs are legacy mechanisms for controlling table-level access in older Databricks environments. They lack the fine-grained, identity-aware row filtering capabilities provided by modern Unity Catalog security policies, which are necessary for the complex requirements of modern data-centric AI applications and secure information retrieval.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.