Which TWO of the following statements correctly describe the capabilities of a Databricks metastore in Unity Catalog?
Trap 1: It can be managed independently for each workspace without…
Unity Catalog requires a centralized metastore per region that is linked to a Databricks account. It is not designed to be managed independently per workspace, as this would prevent cross-workspace governance, sharing, and centralized auditing, which are core value propositions of the Unity Catalog architecture.
Trap 2: It enforces access control policies exclusively at the file-system…
Unity Catalog enforces access control primarily at the logical object level (catalogs, schemas, tables, and views), not just the file-system level. By abstracting permissions away from the underlying cloud storage, it simplifies administration and ensures that security policies remain consistent regardless of the underlying storage implementation.
Trap 3: It forces data storage into the root of the metastore's default…
While a metastore has a root storage location, Unity Catalog allows for external locations and storage credentials. Data can be stored in various locations across cloud providers, and the metastore simply registers and manages the metadata, providing flexibility in storage architecture without forcing all data into one location.
- A
It can be managed independently for each workspace without account-level synchronization.
Why it fails: Unity Catalog requires a centralized metastore per region that is linked to a Databricks account. It is not designed to be managed independently per workspace, as this would prevent cross-workspace governance, sharing, and centralized auditing, which are core value propositions of the Unity Catalog architecture.
- B
It supports a three-level namespace (catalog.schema.table) for data assets.
Unity Catalog introduces a three-level namespace structure, consisting of catalog, schema, and table. This hierarchy allows organizations to logically organize their data assets across different business units, environments, and projects, enabling granular access control and easier discovery compared to the legacy two-level metastore structure.
- C
It enforces access control policies exclusively at the file-system level.
Why it fails: Unity Catalog enforces access control primarily at the logical object level (catalogs, schemas, tables, and views), not just the file-system level. By abstracting permissions away from the underlying cloud storage, it simplifies administration and ensures that security policies remain consistent regardless of the underlying storage implementation.
- D
It provides a centralized audit log for all data access events across the metastore.
One of the primary benefits of the Unity Catalog metastore is centralized audit logging. All access requests, policy changes, and administrative actions are logged at the account level, providing compliance teams with a comprehensive view of data usage and security posture across all linked workspaces and users.
- E
It forces data storage into the root of the metastore's default storage bucket.
Why it fails: While a metastore has a root storage location, Unity Catalog allows for external locations and storage credentials. Data can be stored in various locations across cloud providers, and the metastore simply registers and manages the metadata, providing flexibility in storage architecture without forcing all data into one location.