Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

Which action must an administrator perform to allow a user to use Databricks SQL to query a table that is stored in an external storage location?

⚠ Common exam trap

Examinees frequently confuse table-level SELECT permissions with storage-level privileges, forgetting that querying external tables requires explicit READ FILES permissions on the external location.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the user the READ FILES privilege on the external location.

To query an external table, the user needs access to the storage location, the catalog, the schema, and the table. The administrator must grant the USAGE privilege on the catalog and schema, the SELECT privilege on the table, and the READ FILES privilege on the external location. This multi-layered approach ensures that data access is both logically and physically controlled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant the user the OWNER role for the storage credential.

    Why it's wrong here

    The owner role for a storage credential provides administrative rights to the credential object itself, not access to the data. It is a high-level privilege that should not be assigned to general users and does not grant the necessary read permissions for querying table data.

  • ✓

    Grant the user the READ FILES privilege on the external location.

    Why this is correct

    Querying an external table requires the user to have the READ FILES privilege on the external location object that manages the underlying storage path. This is in addition to the standard catalog, schema, and table privileges, ensuring that storage access is explicitly governed.

  • ✗

    Grant the user the ALL PRIVILEGES privilege on the metastore.

    Why it's wrong here

    Granting ALL PRIVILEGES on the metastore is excessive and violates the principle of least privilege. Users only require specific permissions on the relevant objects—catalog, schema, table, and external location—to perform their jobs, not administrative control over the entire metastore.

  • ✗

    Add the user to the workspace-level admin group.

    Why it's wrong here

    Workspace-level admin rights grant administrative control over the workspace configuration but do not automatically grant permissions on Unity Catalog objects. Access to data assets in Unity Catalog is managed through specific GRANT statements, regardless of the user's role within the local Databricks workspace.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.