Courseiva

CCNA Governance Questions

39 questions · Governance · All types, answers revealed

1
MCQmedium

A data scientist is building a GenAI application that uses the OpenAI API through Databricks external model endpoints. The application must use credentials stored securely in Databricks and must not expose the API key in code or logs. Which Databricks feature should the data scientist use to store and reference the OpenAI API key?

A.Unity Catalog volumes with restricted permissions
B.Hardcoding the API key in a notebook and then deleting the cell
C.Databricks secrets with a secret scope
D.Environment variables set in the cluster's Spark configuration
AnswerC

Databricks secrets allow storing sensitive strings like API keys in a secret scope, which is backed by an encrypted store. Secrets are referenced using dbutils.secrets.get or in endpoint configurations without exposing the value in notebooks or logs. This is the standard, secure way to manage credentials for external services in Databricks.

Why this answer

Databricks secrets provide a secure, encrypted store for sensitive credentials such as API keys. They can be referenced in code and in external model endpoint configurations without revealing the secret value. This meets the requirement to keep the OpenAI API key secure and out of code and logs.

Exam trap

The trap here is assuming that environment variables or volumes provide sufficient security for secrets, when in fact they lack encryption and fine-grained access control.

2
MCQeasy

A GenAI engineer is using MLflow to track experiments for a fine-tuned language model. The engineer wants to ensure that model artifacts and parameters are governed by Unity Catalog, so that access can be controlled and audited. Which Unity Catalog object should the engineer use to register the model?

A.A Unity Catalog schema
B.A Unity Catalog registered model
C.A Unity Catalog volume
D.A Unity Catalog table
AnswerB

A Unity Catalog registered model is the object designed for governing machine learning models. It provides a three-level namespace, versioning, and the ability to grant privileges such as `EXECUTE` and `MANAGE`. By registering the model in Unity Catalog, the engineer ensures that access is controlled and audited, meeting the governance requirement.

Why this answer

Unity Catalog registered models are the correct object for governing machine learning models. They provide a three-level namespace and support fine-grained access control, versioning, and auditing. By registering the fine-tuned model as a Unity Catalog model, the engineer can manage access and track usage, satisfying the governance requirement.

Exam trap

The trap here is confusing volumes or tables with the model registration object, but only registered models provide model-specific governance.

3
MCQmedium

A generative AI team stores prompt/response logs in a Unity Catalog Delta table named `main.genai.interaction_logs`. Compliance requires that the raw `prompt_text` column be readable only by members of the `ai_compliance` group, while all other users querying the table must see the literal string `REDACTED`. Which Unity Catalog feature should be implemented directly on the table to satisfy this requirement without creating a separate view?

A.Row filter
B.Dynamic view with a CASE expression
C.Column mask
D.Attribute-based access control tag
AnswerC

A column mask is a Unity Catalog function bound to a column that evaluates the invoking user's identity and returns either the real value or a substituted value. Applying it to prompt_text with a CASE on is_account_group_member('ai_compliance') makes compliance users see raw text and everyone else see REDACTED, exactly as required, while keeping a single table.

Why this answer

Column masks are the Unity Catalog mechanism designed to transform individual column values based on the caller's group membership while leaving the table itself queryable by everyone. Binding a mask function to prompt_text that checks is_account_group_member('ai_compliance') gives compliance staff the raw text and returns REDACTED to all other users, meeting the requirement on the existing table.

Exam trap

The trap here is confusing row-level filtering, which removes rows, with column-level masking, which rewrites values for the same rows.

4
MCQmedium

A GenAI engineer registers a vector search index in Unity Catalog that points to a Delta table containing customer support transcripts. The security team requires that when an end-user queries the index through a Databricks notebook, the underlying table's row filter and column mask policies are enforced. Which Unity Catalog feature should the engineer configure?

A.Apply tags to the Delta table columns and rely on tag-based access control to mask values at query time.
B.Create a separate vector search index for each user group and assign group-level permissions on those indexes.
C.Use a service principal with read access to the Delta table and query the index through that principal.
D.Enable row-level security and column masks directly on the Delta table, and query the vector search index with the user's identity propagated.
AnswerD

Unity Catalog row filters and column masks are enforced at query time against the caller's identity. When a vector search index is queried through a SQL warehouse or notebook session that carries the end-user's identity, the underlying Delta table policies apply, ensuring the security team's masking and filtering requirements are met without duplicating rules on the index itself.

Why this answer

Row filters and column masks in Unity Catalog are applied dynamically based on the identity executing the query. When a vector search index is queried with end-user identity propagation, the source table's policies are evaluated, so sensitive transcript fields are masked and rows are filtered according to group membership. This satisfies the security team's requirement without duplicating policies on the index.

Exam trap

The trap here is assuming that security policies must be redefined on the vector search index itself, when Unity Catalog enforces them on the underlying Delta table at query time.

5
MCQhard

A company is deploying a GenAI chatbot that uses a Databricks Model Serving endpoint hosting a fine-tuned Llama 2 model. The endpoint is registered in Unity Catalog. The security team wants to restrict which groups can invoke the endpoint and also log all inference requests for auditing. Which combination of Unity Catalog and Databricks features should the engineer use to meet these requirements?

A.Grant EXECUTE on the model version to the allowed groups and enable inference tables on the serving endpoint
B.Grant USE CATALOG and USE SCHEMA on the model's parent schema and enable verbose logging on the endpoint
C.Grant SELECT on the model version to the allowed groups and enable audit logs in the workspace admin console
D.Use a personal access token (PAT) with scoped permissions and configure a Delta table as a sink for endpoint logs
AnswerA

Unity Catalog privileges on model versions include EXECUTE, which controls who can use the model for inference. Granting EXECUTE to specific groups restricts invocation. Inference tables automatically capture request and response payloads for the serving endpoint, providing an audit trail. Together, they satisfy both access control and logging requirements without custom code.

Why this answer

To control who can invoke a model served by Databricks, you grant the EXECUTE privilege on the model version in Unity Catalog. Inference tables are a built-in feature of Model Serving that automatically log request and response data to a Delta table for auditing and monitoring. This combination directly addresses the security team's requirements for access restriction and request logging.

Exam trap

The trap here is confusing SELECT privilege on a model with EXECUTE, or assuming that workspace audit logs capture inference payloads.

6
MCQhard

A platform team is serving a retrieval-augmented generation application. The vector index is built from a Delta table in Unity Catalog, and the team wants every similarity search executed by an end user to be automatically restricted to documents that user is allowed to see, without maintaining a separate index per department. Which approach best enforces this at query time?

A.Apply a column mask to the embedding column so unauthorized users receive null vectors
B.Build one vector index per department and route queries based on the caller's group
C.Grant SELECT only to a service principal and have the application connect as that principal for all users
D.Create a row filter function on the source Delta table that filters rows by the invoking user's group membership
AnswerD

Row filters on the underlying Delta table are evaluated against the invoking principal, so a retrieval query that reads through the table returns only rows that caller may see. Because the vector index is refreshed from that table, embedding the filter there enforces per-user visibility automatically without duplicating indexes per department, which matches the requirement precisely.

Why this answer

Row filters evaluate the invoking user's identity as part of the query, so placing the filter on the source Delta table means every read, including retrieval reads that feed similarity search, is automatically scoped to allowed rows. This keeps a single governed index and avoids per-department duplication while still enforcing per-user document visibility at query time.

Exam trap

The trap here is assuming vector search bypasses Unity Catalog authorization, when reads through governed tables still honor row filters.

7
MCQmedium

A data engineer wants to track who accessed a specific table in Unity Catalog. Which tool should they use?

A.Databricks cluster logs
B.Unity Catalog system tables
C.Cloud provider logs
D.Workspace activity console
AnswerB

Unity Catalog system tables (like 'system.access.audit') store comprehensive logs of all data access events. These tables are the standardized way to query historical audit information across the entire metastore, enabling engineers to perform detailed analysis of who accessed specific tables and when.

Why this answer

The System Tables (specifically the access_logs table) in Unity Catalog provide detailed audit logs of all interactions with data objects. By querying these tables using SQL, administrators can monitor data access patterns, identify unauthorized attempts to view sensitive data, and fulfill audit requirements. This centralized logging is a cornerstone of the governance transparency provided by Unity Catalog.

Exam trap

Candidates commonly suggest standard Spark logs or cluster event logs instead of utilizing the specialized audit capabilities found in Unity Catalog system tables.

8
MCQmedium

A GenAI engineer has built a Retrieval Augmented Generation (RAG) application using Databricks Vector Search. The index is created on a Delta table that contains sensitive customer support transcripts. Company policy requires that end users can only retrieve chunks from documents they are authorized to view. The engineer wants to enforce this at query time without duplicating the index. Which approach should the engineer use?

A.Create a separate Vector Search index for each user group and route queries based on the user's group membership.
B.Use Databricks Vector Search with the 'filter' parameter in the query, based on user attributes passed from the application.
C.Apply Unity Catalog column masks on the embedding column of the source Delta table to redact sensitive text before vectorization.
D.Enable Attribute-Based Access Control (ABAC) on the source Delta table using row filter and column mask functions.
AnswerB

Databricks Vector Search supports query-time filtering on metadata columns. The engineer can include user authorization attributes as metadata during index creation and then pass a filter expression at query time (e.g., 'allowed_groups' containing the user's group). This enforces document-level security without duplicating the index, directly satisfying the policy requirement while keeping a single index for all users.

Why this answer

Databricks Vector Search enables document-level security by allowing metadata filtering at query time. The engineer can include authorization attributes (such as group memberships) as metadata fields when creating the index, then pass a filter expression in the query that matches the user's attributes. This enforces access control without duplicating the index, aligning with the requirement to keep a single index while restricting retrieval to authorized documents.

Exam trap

The trap here is assuming that Unity Catalog row filters and column masks on the source table automatically apply to Vector Search index queries, when in fact the index is a separate serving layer that requires its own query-time filtering.

9
MCQhard

A generative AI engineer trains a model on a Delta table that contains customer support transcripts. Before registering the model, security requires that the training data be classified so that policies can be applied consistently across the lakehouse. The engineer wants to attach a governed label to the transcript column indicating it contains sensitive personal data. Which Unity Catalog feature should be used?

A.A governed tag applied to the column
B.A storage credential scoped to the transcript path
C.A comment added to the column definition
D.A row filter that excludes rows containing personal data
AnswerA

Governed tags in Unity Catalog attach classification metadata to securable objects, including individual columns, and can be used to drive policy decisions and discovery. Tagging the transcript column as sensitive personal data gives security a consistent label that downstream policies and audits can reference, which is exactly the classification requirement described.

Why this answer

Governed tags provide a structured, searchable classification layer in Unity Catalog that can be attached to columns and referenced by policy and discovery tooling. Applying a sensitivity tag to the transcript column gives security a consistent label for the training data, enabling uniform policy enforcement and auditability rather than relying on informal comments or access mechanisms.

Exam trap

The trap here is treating descriptive comments or access grants as classification, when only governed tags provide enforceable labels.

10
MCQhard

A company wants to share a GenAI application's prompt templates and evaluation datasets with a partner organization. The partner uses its own Databricks account and must not access any other company data. The company also wants to revoke access easily. Which Unity Catalog feature should they use?

A.Export the prompt templates and evaluation datasets to cloud storage and share a bucket URL.
B.Create a new metastore for the partner and attach the company's workspace to it.
C.Grant the partner's users direct SELECT privileges on the company's Unity Catalog tables.
D.Delta Sharing with a share containing only the prompt templates and evaluation datasets.
AnswerD

Delta Sharing allows sharing specific tables or views with external organizations without copying data. By creating a share that includes only the prompt templates and evaluation datasets, the company limits access to those assets. Access can be revoked by removing the recipient from the share, meeting the easy revocation requirement.

Why this answer

Delta Sharing is designed for secure cross-organization data sharing without copying. By creating a share with only the prompt templates and evaluation datasets, the company limits exposure to those assets. The partner accesses the share from their own Databricks account, and the company can revoke access by removing the recipient, satisfying both isolation and revocation needs.

Exam trap

The trap here is assuming that direct permission grants or cloud storage exports can achieve cross-account sharing with easy revocation, when Delta Sharing is the purpose-built feature.

11
MCQmedium

A data engineer wants to share a specific subset of sensitive PII data with an external department using Unity Catalog. The engineering team must ensure the data is anonymized dynamically based on the user's role without creating physical copies. Which feature is most appropriate?

A.Create a temporary view that filters rows using a WHERE clause and grants SELECT access.
B.Apply a masking function to the column and use row filters in Unity Catalog.
C.Export the data to a new table with masked columns and grant access to the department.
D.Configure access control lists (ACLs) on the underlying S3 bucket or ADLS container.
AnswerB

Unity Catalog supports dynamic data masking and row filters, which apply policies at query time based on user identity. This enables granular control over data access without duplicating data or creating complex view hierarchies. It is the industry-standard method for enforcing privacy compliance across the Databricks Data Intelligence Platform.

Why this answer

Unity Catalog row-level security and column-level masking allow for dynamic data governance. By applying a masking function using 'current_user_role()' or 'is_account_group_member()', administrators can ensure that users see redacted data without duplicating the underlying storage. This approach centralizes governance policies, simplifies auditing, and ensures that sensitive data exposure is strictly controlled at the query execution time across all compute resources within the Unity Catalog metastore environment.

Exam trap

Candidates frequently choose to create physical duplicate tables with redacted columns, forgetting that Unity Catalog supports dynamic row filters and column masking natively.

12
MCQhard

A GenAI engineer is building a chatbot using Databricks Model Serving and needs to ensure that the endpoint can only be invoked by users who have been granted the 'genai_users' group. The endpoint is registered in Unity Catalog. Which configuration is required to enforce this access control?

A.Grant USE CATALOG and USE SCHEMA on the catalog and schema containing the endpoint to the 'genai_users' group.
B.Grant EXECUTE on the model serving endpoint to the 'genai_users' group.
C.Attach the endpoint to a cluster that has been granted CAN ATTACH TO for the 'genai_users' group.
D.Set the endpoint's owner to the 'genai_users' group and rely on ownership for access.
AnswerB

In Unity Catalog, model serving endpoints are securable objects that support the EXECUTE privilege. Granting EXECUTE to the 'genai_users' group allows only those users to invoke the endpoint. Without this grant, other users cannot call the endpoint, thus enforcing the required access control.

Why this answer

Model serving endpoints registered in Unity Catalog are secured with the EXECUTE privilege. To allow only the 'genai_users' group to invoke the endpoint, an administrator must grant EXECUTE on the endpoint to that group. This ensures that only authorized users can call the endpoint, meeting the access-control requirement.

Exam trap

The trap here is assuming that USE CATALOG/USE SCHEMA or cluster permissions control endpoint invocation, but the EXECUTE privilege is the specific grant needed.

13
MCQmedium

Which action must an administrator perform to allow a user to use Databricks SQL to query a table that is stored in an external storage location?

A.Grant the user the OWNER role for the storage credential.
B.Grant the user the READ FILES privilege on the external location.
C.Grant the user the ALL PRIVILEGES privilege on the metastore.
D.Add the user to the workspace-level admin group.
AnswerB

Querying an external table requires the user to have the READ FILES privilege on the external location object that manages the underlying storage path. This is in addition to the standard catalog, schema, and table privileges, ensuring that storage access is explicitly governed.

Why this answer

To query an external table, the user needs access to the storage location, the catalog, the schema, and the table. The administrator must grant the USAGE privilege on the catalog and schema, the SELECT privilege on the table, and the READ FILES privilege on the external location. This multi-layered approach ensures that data access is both logically and physically controlled.

Exam trap

Examinees frequently confuse table-level SELECT permissions with storage-level privileges, forgetting that querying external tables requires explicit READ FILES permissions on the external location.

14
MCQeasy

A GenAI team is using MLflow to track experiments for a large language model. They want to ensure that only team members can view the experiment results and that the experiment artifacts are stored in a governed location. Which Unity Catalog integration should they use to manage MLflow experiments?

A.Use the MLflow tracking server with a personal access token for each team member
B.Store experiment artifacts in a Unity Catalog volume and use workspace ACLs on the notebook
C.Enable inference tables on the MLflow experiment to log access
D.Register the MLflow experiment in Unity Catalog and grant appropriate privileges on the experiment object
AnswerD

Unity Catalog supports registering MLflow experiments as securable objects. Once registered, you can grant privileges like USE SCHEMA and SELECT on the experiment to control access. Artifacts are stored in a Unity Catalog volume or external location, providing governance and auditability. This directly meets the requirements for access control and governed storage.

Why this answer

Registering an MLflow experiment in Unity Catalog makes it a securable object, allowing you to grant privileges to specific groups. Artifacts are stored in a governed location such as a Unity Catalog volume or external location. This provides both access control and governance, meeting the team's requirements.

Exam trap

The trap here is assuming that workspace ACLs or personal access tokens provide sufficient governance for MLflow experiments, when in fact Unity Catalog registration is required for fine-grained access control.

15
Multi-Selecthard

Which TWO of the following are primary components of the Unity Catalog identity model?

Select 2 answers
A.Workspace-local users
B.Account-level users
C.Groups
D.Cloud-provider-specific identities
E.Data asset aliases
AnswersB, C

Account-level users are the fundamental identity entity in Unity Catalog. By managing users at the account level, organizations ensure that a single identity is used across all workspaces, allowing for consistent permission assignment and easier lifecycle management of employees and service principals.

Why this answer

The Unity Catalog identity model is unified at the account level, meaning that identities are managed consistently across all workspaces. The core components are Users and Groups. By centralizing these identities in the account console, Databricks ensures that permissions are applied uniformly, regardless of which workspace a user is accessing, which is critical for large-scale enterprise governance and audit compliance.

Exam trap

Candidates frequently include 'Workspaces' or 'Metastores' as identity components, confusing the physical deployment infrastructure with the actual user/group identity objects managed in the account.

16
Multi-Selectmedium

A GenAI platform team is preparing a Unity Catalog schema to host a retrieval-augmented generation pipeline. They will store prompt templates and evaluation datasets as Delta tables, and they need to expose the pipeline to a group of application developers. The security team asks the platform team to describe how Unity Catalog privileges must be granted for the developers to query the tables. Which TWO statements correctly describe the required privilege model? (Choose two.)

Select 2 answers
A.Developers need CREATE TABLE on the catalog to read prompt templates stored as Delta tables
B.Developers need USE CATALOG on the catalog and USE SCHEMA on the schema before any table privileges take effect
C.Developers must be granted ALL PRIVILEGES on the catalog so that future objects are automatically accessible
D.Developers must own the schema so that they can create their own tables without further grants
E.Developers must be granted SELECT on each table, or SELECT on the schema to cover all current and future tables
AnswersB, E

Unity Catalog privilege evaluation is hierarchical. A principal must have USE CATALOG on the containing catalog and USE SCHEMA on the containing schema for table-level grants to be usable. Without those, even an explicit SELECT grant on a table is ineffective because the traversal of the namespace is blocked, so this is a genuine prerequisite for the developers.

Why this answer

Reading a table in Unity Catalog requires traversing the namespace and holding a data privilege. USE CATALOG on the catalog and USE SCHEMA on the schema make the table addressable, and SELECT on the table, or on the schema for broad coverage, authorizes the read. Together these two statements describe the minimum privilege set that lets the developers query the RAG pipeline's tables without over-granting administrative rights.

Exam trap

The trap here is granting broad catalog-level privileges such as ALL PRIVILEGES instead of the narrow USE CATALOG, USE SCHEMA, and SELECT combination required for read access.

17
Multi-Selecthard

Which THREE conditions must be met for a user to successfully create a new table in a Unity Catalog schema?

Select 3 answers
A.The user must have the USAGE privilege on the catalog.
B.The user must have the USAGE privilege on the schema.
C.The user must have the CREATE TABLE privilege on the schema.
D.The user must have the MODIFY privilege on the catalog.
E.The user must have the OWNER role for the entire metastore.
AnswersA, B, C

Access to any object within a catalog starts with the USAGE privilege at the catalog level. Without this fundamental permission, a user cannot navigate into the catalog to access schemas or perform any operations like creating new tables, even if they have other schema-level permissions.

Why this answer

Creating a table in Unity Catalog involves a specific permission chain. The user must have USAGE on the catalog, USAGE on the schema, and the CREATE TABLE privilege on the schema. These requirements ensure that governance is maintained at every level of the hierarchy, preventing unauthorized data creation in sensitive or restricted namespaces within the organization's data architecture.

Exam trap

Many candidates forget the 'USAGE' privilege on the parent catalog and schema, incorrectly assuming that 'CREATE TABLE' permission on the schema is sufficient to perform the action.

18
MCQmedium

Which Unity Catalog object should be used to manage access to a folder of JSON files that are not part of a formal Delta table?

A.Managed Table
B.External Location
C.Unity Catalog Volume
D.Global View
AnswerC

Volumes are the designated Unity Catalog objects for managing non-tabular data. They allow users to read, write, and manage file-based assets using a familiar path-based interface, with full support for Unity Catalog's granular access controls at the volume level.

Why this answer

Volumes in Unity Catalog are designed specifically for managing non-tabular data, such as JSON files, CSVs, or machine learning models. By creating a volume, you can govern access to these files using the same security model as tables. This allows for consistent data governance across all types of assets in your environment, not just those formatted as Delta tables.

Exam trap

Candidates often incorrectly select 'External Location' or 'Managed Table', failing to realize that Volumes are the specific Unity Catalog object built for governance of non-tabular file assets like JSON or CSV.

19
MCQmedium

A GenAI engineer is developing a RAG application that uses a Vector Search index. The index is created from a Delta table that contains sensitive information. The security team requires that the engineer can audit which users have queried the index and what data they retrieved. Which Unity Catalog feature should the engineer enable to capture this information?

A.Unity Catalog lineage
B.Vector Search index metadata
C.Inference tables on the Vector Search endpoint
D.Audit logs in system tables
AnswerD

Audit logs in system tables capture access and query events across Databricks, including Vector Search index queries. They record the user identity, the action performed, and the timestamp. By querying the audit logs, the engineer can audit who queried the index and when, satisfying the security requirement. This is the standard mechanism for auditing access to Unity Catalog objects.

Why this answer

Audit logs in system tables capture all access and query events, including those against Vector Search indexes. They record the user, action, and timestamp, enabling the engineer to audit who queried the index and when. This is the appropriate Unity Catalog feature for meeting the security team's auditing requirement.

Exam trap

The trap here is assuming that inference tables or lineage provide user-level query auditing, but only audit logs capture that information.

20
MCQeasy

A generative AI engineer registers a model in Unity Catalog and wants a downstream application to call it for inference without granting the application broad workspace access. The engineer is told to grant a specific Unity Catalog privilege on the registered model so the application can invoke it. Which privilege should be granted?

A.SELECT
B.MODIFY
C.EXECUTE
D.USE CATALOG
AnswerC

EXECUTE is the Unity Catalog privilege that authorizes a principal to invoke a registered model or function. Granting EXECUTE on the model to the application's principal allows inference calls while keeping catalog and schema browsing rights separate, which is the least-privilege path for serving a model registered in Unity Catalog.

Why this answer

Registered models in Unity Catalog are invoked under the EXECUTE privilege, which authorizes a principal to call the model without granting ownership or modification rights. Granting EXECUTE to the application's identity, alongside any needed USE CATALOG and USE SCHEMA to resolve the path, provides least-privilege inference access for the downstream application.

Exam trap

The trap here is assuming table-style privileges like SELECT also govern model invocation, when models require EXECUTE.

21
MCQmedium

A GenAI engineer has built a RAG application that queries a Delta table named `prod_ai.knowledge_base.documents` through a Databricks SQL warehouse. The application uses a service principal `sp-rag-prod` to authenticate. The table contains confidential internal documents. The security team wants to ensure that the service principal can only read the table and cannot modify or delete it. Which Unity Catalog privilege should be granted to `sp-rag-prod` on the table?

A.ALL PRIVILEGES
B.USE SCHEMA
C.MODIFY
D.SELECT
AnswerD

SELECT is the minimum privilege required to read data from a table. Granting SELECT to the service principal allows the RAG application to query the table without giving it the ability to insert, update, or delete data. This follows the principle of least privilege and satisfies the security team's requirement that the service principal can only read the table.

Why this answer

The service principal needs only to read the table for the RAG application. Granting SELECT provides exactly that capability without allowing data modification. Other privileges either grant excessive rights (MODIFY, ALL PRIVILEGES) or do not permit reading table data (USE SCHEMA).

SELECT is the correct least-privilege grant for a read-only consumer in Unity Catalog.

Exam trap

The trap here is assuming that USE SCHEMA or ownership is needed for read access, when in fact SELECT alone on the table is sufficient for a service principal to query data.

22
MCQeasy

A data scientist wants to use a Unity Catalog registered model in a GenAI pipeline. The model was trained on sensitive data, and the governance team requires that the model's lineage back to the training dataset be traceable. Which Unity Catalog capability provides this traceability?

A.Unity Catalog lineage graph that automatically tracks data and model dependencies.
B.Model version tags that describe the training data.
C.Workspace notebook comments that document the training data path.
D.Model signature that records input and output schema.
AnswerA

Unity Catalog automatically captures lineage for tables, models, and notebooks, showing how a model version was derived from training datasets. This provides the required traceability without manual effort and is auditable. The lineage graph is a core governance feature that links data assets across the workspace.

Why this answer

Unity Catalog lineage automatically tracks the flow of data through notebooks, jobs, and models, including the training dataset used to produce a model version. This gives the governance team an auditable, automated trace from model to data. Manual methods such as tags or comments are not reliable for compliance.

Exam trap

The trap here is assuming that metadata such as tags or signatures can substitute for automated lineage when proving traceability to an auditor.

23
MCQhard

What is the purpose of the 'metastores.list' command in the Unity Catalog CLI?

A.To list all users registered in the metastore.
B.To list all metastores available to the user in the account.
C.To list all tables within a specific metastore.
D.To list all storage credentials linked to the metastore.
AnswerB

This command specifically retrieves a list of metastore objects. It is the standard way to inspect the metastore topology for an account, helping administrators verify which metastores are provisioned, their IDs, and their region, which is vital for effective cross-region governance management.

Why this answer

The 'metastores.list' command allows administrators to view all Unity Catalog metastores that the current user has permission to see within their Databricks account. This is essential for managing multiple metastores in a complex, multi-region architecture. Understanding which metastores exist and their properties is the first step in ensuring that data governance policies are consistently applied across all regional footprints.

Exam trap

Candidates often confuse Unity Catalog CLI commands with workspace-level CLI commands or assume 'metastores.list' operates on individual catalogs rather than account-level metastores available to the specific user.

24
MCQeasy

Which Unity Catalog object is used to link a specific cloud storage path to a catalog, schema, or table, allowing users to create tables without managing individual storage credentials?

A.Storage Credential
B.External Location
C.Managed Table
D.Unity Catalog Volume
AnswerB

The external location object defines the specific path in cloud storage and associates it with a storage credential. It is the primary mechanism for accessing data in Unity Catalog that is stored in user-managed cloud accounts, providing a governed interface for data engineers to register data assets.

Why this answer

An External Location in Unity Catalog acts as a secure bridge between Databricks and a specific path in cloud storage (e.g., S3 or ADLS). By using a Storage Credential, the external location allows data engineers to manage storage access at a high level. This simplifies data governance by abstracting cloud-specific permissions into Databricks-native access controls.

Exam trap

Candidates often confuse 'External Location' with 'Storage Credential', failing to distinguish between the object that maps a path and the object that holds the authentication secret.

25
MCQeasy

What is the primary function of a Storage Credential in Unity Catalog?

A.To store user passwords for Databricks.
B.To authorize Databricks to access specific cloud storage.
C.To define the schema of a table.
D.To cache table data for faster query performance.
AnswerB

A storage credential provides the necessary authentication (like a service principal or IAM role) for the Databricks platform to communicate with cloud storage. It acts as the secure identity that Unity Catalog uses to perform read and write operations on behalf of the authorized users.

Why this answer

A Storage Credential serves as a secure container for the cloud-provider credentials required to access external storage locations. By separating the credential from the data objects, Unity Catalog allows administrators to manage access to cloud storage in a centralized, governed way without exposing secrets to individual users. This is a fundamental security practice that prevents credential leakage.

Exam trap

Candidates often think Storage Credentials are used to manage table permissions directly, rather than acting as the underlying authentication mechanism for external storage locations.

26
MCQeasy

A data scientist is developing a GenAI application that uses a foundation model served via Databricks Model Serving. The model endpoint is configured to log inference tables for monitoring. The data science team wants to ensure that the inference logs, which may contain sensitive user prompts, are protected according to Unity Catalog policies. Which Unity Catalog object should be used to store and govern the inference tables?

A.A managed table in a Unity Catalog schema with appropriate grants and column masks.
B.A volume in Unity Catalog with file-level access controls.
C.An external table pointing to a cloud storage location with a storage credential.
D.A view that dynamically redacts sensitive columns from the inference logs.
AnswerA

Inference tables logged by Databricks Model Serving are Delta tables that can be stored in Unity Catalog. By storing them as managed tables in a Unity Catalog schema, the team can apply Unity Catalog governance, including grants, row filters, and column masks, to protect sensitive prompt data. This integrates inference logging with the existing security model, ensuring that access to logs is controlled and auditable.

Why this answer

Inference tables logged by Databricks Model Serving are Delta tables that can be stored in Unity Catalog. Using a managed table in a Unity Catalog schema allows the team to apply Unity Catalog governance features such as grants, column masks, and row filters to protect sensitive data. This ensures that the inference logs are subject to the same security policies as other data assets, providing centralized governance and auditability.

Exam trap

The trap here is thinking that inference logs are automatically governed or that a volume is appropriate; inference logs are tabular Delta tables and should be stored as Unity Catalog tables to leverage fine-grained access controls.

27
MCQhard

A healthcare company uses Databricks to build a GenAI chatbot that answers questions from patient records stored in a Delta table. The records contain PHI, and the company must ensure that the chatbot never returns PHI to unauthorized users. The security team wants to enforce policies at the data layer so that even if the LLM is manipulated, it cannot access PHI. Which Unity Catalog feature should be used to dynamically redact PHI columns based on the user's group membership?

A.Row-level security with a filter function that excludes rows containing PHI.
B.Attribute-based access control (ABAC) policies defined on the catalog to deny access to PHI columns.
C.Column masks using a user-defined function that returns redacted values for unauthorized groups.
D.Dynamic view that joins the patient records with a permissions table and filters out PHI columns.
AnswerC

Unity Catalog column masks allow dynamic redaction of column values based on the invoking user's group membership. A mask function can check 'is_account_group_member()' and return a redacted value (e.g., 'REDACTED') for users not in an authorized group, while returning the original value for authorized users. This enforces PHI protection at the data layer, ensuring the chatbot cannot retrieve PHI for unauthorized users even if the LLM is manipulated.

Why this answer

Unity Catalog column masks are designed to dynamically redact column values based on the user's identity or group membership. By applying a mask function to PHI columns, the healthcare company can ensure that unauthorized users see redacted values while authorized users see the actual data. This enforcement occurs at the data layer, preventing PHI leakage even if the LLM is manipulated, and it applies to all queries against the table.

Exam trap

The trap here is confusing row-level security with column-level security; row filters remove entire rows, while column masks selectively redact values within columns, which is necessary when only specific fields contain PHI.

28
MCQmedium

A GenAI engineer is building a RAG application on Databricks. They have registered a foundation model endpoint in Unity Catalog as a model. The application needs to query the endpoint, and the engineer wants to ensure that only members of the group 'genai_team' can invoke it. Which Unity Catalog privilege must be granted on the model object to allow invocation?

A.USE
B.SELECT
C.EXECUTE
D.CREATE
AnswerC

EXECUTE is the privilege required to invoke a model registered in Unity Catalog, including foundation model endpoints. Granting EXECUTE to the genai_team group on the model object allows its members to call the model endpoint from their applications, ensuring only authorized users can consume the model.

Why this answer

To invoke a model registered in Unity Catalog, a user must have the EXECUTE privilege on that model. Granting EXECUTE to the genai_team group ensures that only its members can call the model endpoint, aligning with the requirement to restrict access. Other privileges like SELECT, USE, or CREATE do not authorize model invocation.

Exam trap

The trap here is assuming that SELECT or USE grants invocation rights on a model, when actually EXECUTE is the specific privilege required.

29
MCQmedium

Which Unity Catalog feature is best suited for sharing data assets with users outside of your Databricks account?

A.Unity Catalog cross-account roles
B.Delta Sharing
C.External locations
D.Workspace federation
AnswerB

Delta Sharing is designed specifically for secure data sharing with entities outside your organization. It supports sharing data from your Unity Catalog metastore to any Delta Sharing recipient, even if they do not use Databricks, providing a platform-agnostic way to collaborate on large datasets.

Why this answer

Delta Sharing is an open-protocol standard that allows organizations to share data with users regardless of whether they have a Databricks account. It enables secure, read-only data sharing across different platforms and cloud environments. This is essential for organizations that need to collaborate with partners, vendors, or external clients while maintaining centralized control and auditability within Unity Catalog.

Exam trap

Candidates often suggest 'Unity Catalog' or 'Workspace Sharing', not realizing that Delta Sharing is the specific protocol designed for cross-account and cross-platform data distribution.

30
MCQmedium

A data scientist is using Databricks to fine-tune a large language model. The training data is stored in a Unity Catalog table that contains sensitive customer information. The data scientist needs to read the table but should not be able to see the raw values of certain columns. Which Unity Catalog feature should be used to dynamically mask the sensitive columns based on the user's group membership?

A.Dynamic column masking
B.Column-level encryption
C.Attribute-based access control
D.Row-level security
AnswerA

Dynamic column masking allows you to define a masking function that returns different values depending on the user's group membership. This enables sensitive columns to be masked for unauthorized users while remaining visible to authorized ones, exactly matching the scenario.

Why this answer

Dynamic column masking in Unity Catalog enables the data scientist to see masked values for sensitive columns based on their group membership. By applying a column mask that checks group membership, the raw values are hidden from unauthorized users while still allowing the data scientist to read the table for fine-tuning.

Exam trap

The trap here is confusing row-level security with column-level masking, or assuming that encryption provides dynamic masking.

31
MCQmedium

A data engineer needs to ensure that sensitive PII columns are masked for specific groups while remaining visible to analysts. Which Unity Catalog feature should be used to implement this requirement?

A.Row-level security filters
B.Dynamic data masking
C.Credential passthrough
D.Attribute-based access control (ABAC)
AnswerB

Dynamic data masking is specifically designed to redact or transform sensitive column data in real-time based on the user's identity or group. By attaching a masking function to a column in Unity Catalog, data engineers can ensure that analysts see masked results without modifying the underlying data files.

Why this answer

Unity Catalog dynamic data masking allows administrators to apply functions to columns that redact or obfuscate data based on the user's role or group membership. By using SQL functions like mask_email or custom UDFs within a masking policy, the data remains consistent at the physical layer while presenting transformed values at query time. This ensures compliance with privacy regulations without creating multiple copies of datasets.

Exam trap

Candidates often suggest creating multiple views or tables with filtered data. This is inefficient and prone to errors; dynamic data masking is the correct, centralized feature for this.

32
MCQhard

Refer to the exhibit. Why did the analyst group lose access after the table was recreated?

A.The catalog owner needs to refresh the table metadata.
B.The analyst group needs to be re-added to the schema permissions.
C.The new table is a different object, so the GRANT statement must be repeated.
D.The user who recreated the table is not the catalog owner.
AnswerC

Unity Catalog treats the newly created table as a entirely new resource with a fresh identity. Any permissions applied to the previous version of the table do not carry over to the replacement, requiring administrators to re-issue GRANT commands for the new object.

Why this answer

In Unity Catalog, privileges are bound to the specific object ID. When a table is dropped and re-created, it becomes a new object with a new unique identifier. The previous GRANT statements, which were associated with the original object ID, do not automatically apply to the new table.

This mechanism protects against security drift by ensuring that every new object must have its permissions explicitly managed.

Exam trap

Candidates mistakenly believe that object permissions persist even if the underlying table is dropped and recreated, forgetting that Unity Catalog treats a new table as a distinct object ID.

33
MCQhard

Refer to the exhibit. The user is a member of the 'finance_team'. Why might the user encounter an access error when executing this join query?

A.The user lacks the SELECT privilege on the schema object.
B.The user lacks the USAGE privilege on the 'sales' schema.
C.The user requires the MODIFY privilege to perform joins.
D.The user needs to be an owner of the tables to perform joins.
AnswerB

Accessing any object in Unity Catalog requires the USAGE privilege on all containing objects, including the schema. Even if a user has explicit SELECT rights on the tables, the query will fail if they have not been granted USAGE on the parent schema container.

Why this answer

In Unity Catalog, users require the USAGE privilege on all parent objects—the catalog and the schema—to access a table. While the user has USAGE on the catalog and SELECT on the tables, they lack the USAGE privilege on the 'sales' schema. Without explicit USAGE permission on the schema, the user cannot traverse the hierarchy to reference the tables, causing a permission denied error.

Exam trap

Candidates often assume that having 'SELECT' on a table is enough to query it, overlooking the mandatory 'USAGE' permission required at the schema and catalog levels.

34
Multi-Selectmedium

A company is preparing a generative AI application for production and must demonstrate that model inputs and outputs are traceable and that access to sensitive prompt data is controlled. Which TWO Unity Catalog capabilities should the team rely on to meet these governance objectives? (Choose two.)

Select 2 answers
A.Fine-grained privileges on catalogs, schemas, tables, and models
B.Embedding caching to reduce inference latency
C.Vector index partitioning by document topic
D.Audit logs that record which principals accessed governed tables and models
E.Automatic hyperparameter tuning of registered models
AnswersA, D

Unity Catalog's privilege model lets administrators grant narrowly scoped rights such as SELECT on a table or EXECUTE on a model to specific groups. This enforces least privilege on sensitive prompt data and model invocation, which is the second governance objective in the scenario and complements the audit trail.

Why this answer

Meeting the governance objectives requires both an enforcement mechanism and an evidence trail. Fine-grained privileges on the relevant catalogs, schemas, tables, and models enforce least-privilege access to sensitive prompt data, while Unity Catalog audit logs record which principals accessed those governed objects, providing the traceability that production compliance reviews demand.

Exam trap

The trap here is selecting performance features like caching or tuning as governance controls, when governance needs enforcement plus audit evidence.

35
MCQhard

Refer to the exhibit. What is the current permission state for the 'analyst_group' after the execution of the REVOKE statement?

A.The group retains access because they are still mentioned in the grant history.
B.The group loses access to the table.
C.The group retains access due to the order of operations in the metastore.
D.The group can still access the table if they are members of the manager_group.
AnswerB

The REVOKE command removes the SELECT privilege that was previously granted to the group. Unity Catalog follows the most recent explicit command for a privilege, so once the revoke command is successfully applied, the group's access rights are removed, and they can no longer query the table.

Why this answer

Unity Catalog employs a standard additive-subtractive permission model. When a user or group is explicitly denied or revoked a privilege, the revocation takes precedence. After the REVOKE command is executed, the SELECT privilege is removed from 'analyst_group'.

Even if the group was previously granted access, the REVOKE command effectively clears that privilege, ensuring the group can no longer access the specified table.

Exam trap

Candidates often assume that permissions are additive only or that a group might retain access through another role, ignoring that a specific REVOKE command overrides previous grants.

36
MCQeasy

A GenAI engineer has written a notebook that calls the Databricks Foundation Model APIs to summarize documents. Before the notebook can run in production, the security team wants to confirm exactly which workspace users and service principals are permitted to invoke the pay-per-token foundation model endpoints. Where should the engineer point them to review and manage those permissions?

A.The Unity Catalog metastore's default storage location settings
B.The Unity Catalog privileges on the system.ai schema and its model functions
C.The workspace admin settings page for cluster policies
D.The Azure Databricks access connector assigned to the workspace
AnswerB

Databricks exposes foundation models as Unity Catalog functions under the system.ai schema, and invocation is governed by Unity Catalog privileges such as EXECUTE on each model function. Reviewing and granting these privileges shows precisely which users and service principals may call the pay-per-token endpoints, which is exactly what the security team requested.

Why this answer

Foundation Model APIs are surfaced as Unity Catalog functions in the system.ai schema, so access is controlled with Unity Catalog privileges, chiefly EXECUTE on the relevant model function, plus the usual USE CATALOG and USE SCHEMA on system.ai. Directing the security team to those grants gives an auditable, centralized view of exactly which users and service principals can invoke each pay-per-token model.

Exam trap

The trap here is assuming foundation model access is configured through workspace-level settings or compute policies rather than Unity Catalog privileges on the system.ai model functions.

37
MCQhard

A healthcare company uses Databricks to build a RAG application over clinical notes stored in a Unity Catalog table. An auditor requires proof that only authorized personnel can view raw note text, while the RAG application must use embeddings generated from those notes. The team wants to avoid copying data outside Unity Catalog. Which approach best satisfies the auditor while preserving RAG functionality?

A.Move the clinical notes to an external location outside Unity Catalog and grant access via cloud IAM roles.
B.Create a column mask on the note text column that returns a redacted value for unauthorized users, and grant the RAG service principal access to a separate embeddings table derived from the notes.
C.Grant the RAG application's service principal SELECT on the table and rely on the application to redact note text in its responses.
D.Use a dynamic view that filters rows based on the user's group and grant the RAG service principal access to that view.
AnswerB

A column mask on the note text column ensures that only authorized users see raw PHI, satisfying the auditor. The RAG application can read embeddings from a derived table without needing raw text, so it continues to function. Unity Catalog enforces the mask at query time based on identity, providing auditable, centralized control.

Why this answer

A column mask on the sensitive note text column enforces redaction for unauthorized identities at query time, which is auditable. By having the RAG application consume a derived embeddings table instead of raw text, the application retains functionality while raw PHI remains protected. This keeps governance within Unity Catalog and satisfies the auditor's requirement.

Exam trap

The trap here is thinking that application-level redaction or IAM roles can substitute for Unity Catalog column masks when an auditor demands provable data-layer controls.

38
MCQhard

A GenAI engineer registers a fine-tuned model in Unity Catalog and wants a downstream application to call it through the Databricks Model Serving endpoint without embedding a long-lived personal access token in the application. The application runs on Azure Databricks and must authenticate as its own identity, and the security team requires that credentials be short-lived and automatically rotated. Which authentication approach should the engineer implement?

A.Create a Databricks service principal, generate a personal access token for it, and store that token in the application's environment variables
B.Use OAuth machine-to-machine authentication with the service principal's client ID and client secret to obtain a short-lived token
C.Configure the application to use the workspace user's username and password for basic authentication
D.Embed a Microsoft Entra ID managed identity token directly in the application source code
AnswerB

Databricks supports OAuth 2.0 client credentials flow for service principals, where the application exchanges its client ID and secret for an access token that expires in about an hour. The application authenticates as its own identity and never stores a durable bearer token. This matches the requirement for short-lived, automatically refreshed credentials and is the recommended pattern for unattended workloads.

Why this answer

OAuth machine-to-machine authentication lets an application present a service principal's client ID and secret to the Databricks OAuth token endpoint and receive an access token with a limited lifetime. The application has its own Unity Catalog identity, permissions can be granted to that principal on the registered model and serving endpoint, and token refresh happens automatically. This is the supported pattern for non-interactive workloads that must avoid long-lived secrets.

Exam trap

The trap here is treating a service principal's personal access token as equivalent to OAuth client credentials, when only the latter yields automatically rotated short-lived tokens.

39
Multi-Selectmedium

A GenAI engineer is deploying a RAG application that uses Databricks Vector Search and a Foundation Model API. The solution must comply with governance policies that require all data access and model invocations to be auditable and access-controlled at a fine-grained level. Which two Unity Catalog features should the engineer leverage to meet these requirements? (Choose two.)

Select 2 answers
A.Unity Catalog volumes to store the model weights and configuration files.
B.Cluster policies to restrict the types of clusters that can access the data.
C.Unity Catalog privileges on the Vector Search index and the source Delta table.
D.Inference tables for the Foundation Model API endpoint to log requests and responses.
E.Databricks SQL dashboards to visualize access patterns and model usage.
AnswersC, D

Unity Catalog privileges on the Vector Search index and the source Delta table allow fine-grained access control. You can grant SELECT on the index to specific groups and restrict access to the underlying table. This ensures that only authorized users can retrieve data and perform searches, meeting the access-control requirement for the RAG application.

Why this answer

Unity Catalog privileges on the Vector Search index and source table provide fine-grained access control, ensuring only authorized users can retrieve data. Inference tables for the Foundation Model API automatically log requests and responses, including user identity, creating an audit trail. Together, these features meet the access-control and auditability requirements for the RAG application.

Exam trap

The trap here is assuming that storing model weights in Volumes or using cluster policies provides governance, but these do not enforce access control or audit model invocations.

Ready to test yourself?

Try a timed practice session using only Governance questions.