Databricks-GenAI-Assoc Governance Practice Question
Exhibit
GRANT SELECT ON TABLE main.sales.data TO `analyst_group`; GRANT SELECT ON TABLE main.sales.data TO `manager_group`; REVOKE SELECT ON TABLE main.sales.data FROM `analyst_group`;
Refer to the exhibit. What is the current permission state for the 'analyst_group' after the execution of the REVOKE statement?
⚠ Common exam trap
Candidates often assume that permissions are additive only or that a group might retain access through another role, ignoring that a specific REVOKE command overrides previous grants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The group loses access to the table.
Unity Catalog employs a standard additive-subtractive permission model. When a user or group is explicitly denied or revoked a privilege, the revocation takes precedence. After the REVOKE command is executed, the SELECT privilege is removed from 'analyst_group'. Even if the group was previously granted access, the REVOKE command effectively clears that privilege, ensuring the group can no longer access the specified table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The group retains access because they are still mentioned in the grant history.
Why it's wrong here
The grant history is a record of past actions, not a reflection of current state. The REVOKE command explicitly removes the privilege, and the historical GRANT is effectively overridden by the subsequent REVOKE, meaning the group no longer has the necessary rights to access the table.
- ✓
The group loses access to the table.
Why this is correct
The REVOKE command removes the SELECT privilege that was previously granted to the group. Unity Catalog follows the most recent explicit command for a privilege, so once the revoke command is successfully applied, the group's access rights are removed, and they can no longer query the table.
- ✗
The group retains access due to the order of operations in the metastore.
Why it's wrong here
The order of operations is chronological based on execution time. The REVOKE command is the most recent operation, so it takes precedence over the prior GRANT. Access is revoked immediately upon the successful completion of the REVOKE statement, regardless of previous successful GRANT commands.
- ✗
The group can still access the table if they are members of the manager_group.
Why it's wrong here
While this is true if the group is a member of another group that has access, the question asks about the group's own specific revoked privilege. The revocation of the SELECT privilege for the analyst group itself remains in effect, regardless of any other groups they might belong to.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.