Courseiva

Databricks-GenAI-Assoc · topic practice

Governance practice questions

Governance on Databricks covers Unity Catalog privileges, model serving endpoint access, and secure data handling for GenAI workloads. Questions present access errors or permission scenarios involving catalogs, schemas, tables, registered models, and serving endpoints, asking you to identify the missing grant, ownership issue, or privilege inheritance rule causing the failure.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Governance

What the exam tests

What to know about Governance

Be able to trace an access error to the exact missing Unity Catalog privilege and grant it correctly. The single most important thing: privileges require USE CATALOG and USE SCHEMA on parents, and grants vanish when objects are dropped and recreated.

Granting USE CATALOG, USE SCHEMA, and SELECT privileges for RAG data access

Querying foundation model serving endpoints registered in Unity Catalog as models

Fine-tuning on sensitive Unity Catalog tables using row filters and column masks

Diagnosing access errors from table recreation, ownership changes, and group membership

Watch out for

Common Governance exam traps

  • ▸Assuming SELECT alone suffices; USE CATALOG and USE SCHEMA are also required on parent objects.
  • ▸Forgetting that recreating a table drops its prior grants, so groups silently lose access.
  • ▸Overlooking that serving endpoint access needs explicit grants, not just model registration.

Practice set

Governance questions

20 questions · select your answer, then reveal the explanation

Question 1mediummulti select
Read the full Governance explanation →

Which TWO of the following statements correctly describe the capabilities of a Databricks metastore in Unity Catalog?

Question 2mediummultiple choice
Read the full Governance explanation →

A company requires that all data access in Databricks be restricted to a specific region for regulatory compliance. Which Unity Catalog feature should they use to enforce this?

Question 3mediummultiple choice
Read the full Governance explanation →

A GenAI engineer is building a Retrieval-Augmented Generation (RAG) application with Databricks Vector Search. The index is created in Unity Catalog and points to a Delta table containing confidential customer support transcripts. The engineer wants to ensure that only members of the 'genai_team' group can query the index, while other users in the workspace cannot see it. What is the correct way to enforce this access control?

Question 4hardmultiple choice
Read the full Governance explanation →

A GenAI engineer is using Databricks Foundation Model APIs to serve a Llama 3 model. The engineer needs to log all inference requests and responses for auditing purposes, including the user identity and the model version. The logs must be stored in a Unity Catalog table with column-level encryption for the request text. Which combination of features should the engineer use?

Question 5mediummultiple choice
Read the full Governance explanation →

A GenAI engineer has built a Retrieval-Augmented Generation (RAG) application in a Databricks notebook. The application uses the `databricks-bge-large-en` Foundation Model for embedding queries and retrieves documents from a Delta table. The security team requires that all calls to the embedding model be logged with the user identity for audit purposes, without changing any application code. Which Unity Catalog feature should the engineer implement?

Question 6mediummultiple choice
Read the full Governance explanation →

A GenAI engineer has built a retrieval-augmented generation (RAG) application that stores its document embeddings in a Databricks Vector Search index backed by a Delta table in Unity Catalog. The source Delta table contains confidential customer contracts. The organization wants to ensure that end users querying the vector index only retrieve embeddings for documents they are permitted to see, without duplicating the index. Which Unity Catalog capability should the engineer configure on the Vector Search index?

Question 7easymultiple choice
Read the full Governance explanation →

A data scientist wants to use Databricks Assistant to generate SQL queries on a table that contains sensitive financial data. The organization requires that the Assistant must not see the actual data values, only the schema and metadata. Which Unity Catalog feature should be enabled to meet this requirement?

Question 8hardmultiple choice
Read the full Governance explanation →

A company has deployed a RAG chatbot that uses a Vector Search index in Databricks. The index is built from a Delta table containing confidential customer support tickets. The security team wants to ensure that users can only retrieve documents from the index that they are authorized to see, based on row-level filters defined in Unity Catalog. Which approach should the GenAI engineer take?

Question 9mediummultiple choice
Read the full Governance explanation →

A Databricks workspace uses Unity Catalog, and a GenAI engineer has built a Retrieval-Augmented Generation (RAG) application backed by a Databricks Vector Search index. The source Delta table contains customer support transcripts, some of which include internal-only escalation notes. Compliance requires that users querying the RAG endpoint never receive internal-only notes in retrieved chunks, while data scientists must still be able to read the full table for model evaluation. Which Unity Catalog feature should the engineer use to enforce this at query time?

Question 10mediummulti select
Read the full Governance explanation →

A GenAI team is deploying a model serving endpoint that calls a foundation model API. The security team requires that all prompts and completions be logged for audit and that access to the endpoint be restricted to a specific group. Which two Unity Catalog features should the team use to meet these requirements? (Choose two.)

Question 11mediummulti select
Read the full Governance explanation →

A GenAI engineer is building a RAG pipeline that uses a Foundation Model API to generate answers. The model is hosted in a Databricks workspace and accessed via a serving endpoint. The security team requires that all data sent to the model is governed by Unity Catalog, and that the engineer can track which users or groups have permission to query the endpoint. Which two actions should the engineer take to meet these requirements? (Choose two.)

Question 12hardmulti select
Read the full Governance explanation →

A GenAI engineer is using Databricks to fine-tune a large language model on a dataset that contains personally identifiable information (PII). The engineer must ensure that the fine-tuning process complies with governance policies. The policies require that PII is not stored in plaintext in the training data used by the fine-tuning job, and that access to the fine-tuned model is restricted to a specific group. Which TWO actions should the engineer take to meet these requirements? (Choose two.)

Question 13mediummulti select
Read the full Governance explanation →

A GenAI engineer is building a RAG pipeline that uses a Delta table as the source for a Vector Search index. The table contains confidential documents, and the engineer must ensure that the vector index respects Unity Catalog permissions so that only authorized users can query the index. Which two actions must the engineer take? (Choose two.)

Question 14hardmultiple choice
Read the full Governance explanation →

A GenAI engineer is building an agent that must call an external HTTP API to retrieve inventory levels. The API requires a secret key. The engineer wants the notebook and the deployed Databricks Model Serving endpoint to read the key without ever storing it in code or in the notebook output, and the security team wants the key to be manageable from Unity Catalog. Which approach should the engineer use?

Question 15hardmultiple choice
Read the full Governance explanation →

A GenAI engineer builds a RAG application whose vector index is served through a Databricks Model Serving endpoint. Security requires that every retrieval and every chat completion be attributable to the individual end user, and that the same users who can query the underlying Delta source table can query the endpoint. Which Unity Catalog mechanism should the engineer configure to satisfy both requirements?

Question 16mediummultiple choice
Read the full Governance explanation →

A data engineer needs to ensure that sensitive PII columns are masked for specific groups while remaining visible to analysts. Which Unity Catalog feature should be used to implement this requirement?

Question 17hardmultiple choice
Read the full Governance explanation →

Refer to the exhibit. The user is a member of the 'finance_team'. Why might the user encounter an access error when executing this join query?

Exhibit

GRANT USAGE ON CATALOG main TO `finance_team`;
GRANT SELECT ON TABLE main.sales.data TO `finance_team`;
GRANT SELECT ON TABLE main.sales.summary TO `finance_team`;
-- User attempts to join the two tables in a query:
SELECT * FROM main.sales.data d JOIN main.sales.summary s ON d.id = s.id;
Question 18easymultiple choice
Read the full Governance explanation →

Which Unity Catalog object is used to link a specific cloud storage path to a catalog, schema, or table, allowing users to create tables without managing individual storage credentials?

Question 19hardmulti select
Read the full Governance explanation →

Which THREE conditions must be met for a user to successfully create a new table in a Unity Catalog schema?

Question 20mediummultiple choice
Read the full Governance explanation →

Which action must an administrator perform to allow a user to use Databricks SQL to query a table that is stored in an external storage location?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Governance sessions

Start a Governance only practice session

Every question in these sessions is drawn from the Governance domain — nothing else.

Related practice questions

Related Databricks-GenAI-Assoc topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the Databricks-GenAI-Assoc exam test about Governance?
Be able to trace an access error to the exact missing Unity Catalog privilege and grant it correctly. The single most important thing: privileges require USE CATALOG and USE SCHEMA on parents, and grants vanish when objects are dropped and recreated.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Governance questions in a focused session?
Yes — the session launcher on this page draws every question from the Governance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other Databricks-GenAI-Assoc topics?
Use the topic links above to move to related areas, or go back to the Databricks-GenAI-Assoc question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the Databricks-GenAI-Assoc exam covers. They are not copied from any real exam or dump site.