Databricks Data Engineer Associate Unity Catalog Governance Security Managed External Tables Practice Test

 

Skill 7 • 60 original questions

This Databricks Certified Data Engineer Associate practice test focuses on unity catalog governance security managed external tables privileges masking and abac through original data-engineering scenarios aligned to the exam guide effective May 4, 2026. Databricks does not publish section percentages in this guide, so the complete ExamSnap collection distributes questions according to objective breadth while covering every published objective explicitly. For broader exam preparation, review the Databricks Certified Data Engineer Associate Exam Dumps page.

Instructions: Select the best answer for each question unless the stem says Select TWO. Review the explanation after answering; every option includes a reason it is or is not the best fit for that scenario.

Question 1

The analytics engineering team at Adventure Works is comparing implementation options. They must implement the skill described by differentiate and operate managed and external unity catalog tables. Which option best matches the requirement and the goal to improve auditability? The choice must be defensible in a security and governance review.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use the appropriate Lakeflow Connect connector and governed destination to ingest supported enterprise source data reliably into Unity Catalog tables
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Configure Lakeflow Connect for enterprise sources. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 2

Proseware is reviewing a production configuration. The DevOps team must choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which choice most directly satisfies the requirement while trying to apply the narrowest effective control? The implementation should avoid adding a control that does not address the stated constraint.

  1. Parse and normalize JSON, nested, semi-structured, or unstructured source data with a supported managed or code-based ingestion path before landing it in Unity Catalog governed Delta tables
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Ingest semi-structured and unstructured data into governed Delta tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 3

The data engineering team at Litware is comparing implementation options. They must choose the most accurate administrative approach for this requirement: use column masking and row filters for group-based data visibility. Which option best matches the requirement and the goal to support repeatable administration? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Use the Jobs UI and DAG to locate failed or blocked tasks, understand upstream dependencies, and assess pipeline runtime and failure-rate health
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Monitor pipeline health using Lakeflow Jobs status DAG runtime and failure information. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 4

The BI team at Litware is comparing implementation options. They must select an implementation consistent with this objective: use unity catalog abac policies for centralized row filtering and column masking. Which option best matches the requirement and the goal to reduce user disruption? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use JDBC, ODBC, or REST when a supported API/client is the practical ingestion path, then orchestrate and schedule the notebook or task with Lakeflow Jobs
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use JDBC ODBC or REST clients in notebooks and orchestrate with Lakeflow Jobs. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 5

For an upcoming rollout at Litware, the platform team needs to make a decision that correctly reflects this requirement: differentiate and operate managed and external unity catalog tables. Which response is most appropriate if the solution should also avoid unnecessary complexity? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use job control-flow capabilities such as retries, conditional tasks, and loops to express recoverable and data-dependent orchestration logic
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Implement retries conditional branches and loops with Lakeflow Jobs. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 6

For an upcoming rollout at Adventure Works, the analytics engineering team needs to select an implementation consistent with this objective: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which response is most appropriate if the solution should also avoid unnecessary complexity? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Choose the join or union semantics that preserve the intended row set and schema, using broadcast joins only when the smaller-side characteristics make them appropriate
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Combine DataFrames with joins unions and multiple-key operations. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 7

During an implementation review at Wingtip Toys, the governance team needs to implement the skill described by use column masking and row filters for group-based data visibility. Which approach is the strongest fit when the organization also wants to preserve least privilege? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Use Liquid Clustering for flexible data layout optimization and predictive optimization where Databricks can automatically apply supported table-maintenance optimizations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Understand Liquid Clustering and predictive optimization. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 8

An administration ticket for Adventure Works states: choose the most accurate administrative approach for this requirement: use unity catalog abac policies for centralized row filtering and column masking. Which decision should the analytics engineering team make to meet the stated compliance requirement? The implementation should avoid adding a control that does not address the stated constraint.

  1. Use DataFrame or SQL operations to add, drop, split, rename, filter, and explode data while preserving the required schema and row semantics
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Manipulate columns rows and table structures. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 9

The data engineering team at Alpine Ski House is comparing implementation options. They must choose the most accurate administrative approach for this requirement: differentiate and operate managed and external unity catalog tables. Which option best matches the requirement and the goal to reduce user disruption? The choice must be defensible in a security and governance review.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Choose and configure a scheduled, file-arrival, or table-update trigger based on the event that should start the workflow

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Implement schedules and understand scheduled file-arrival and table-update triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 10

The data engineering team at Fourth Coffee is comparing implementation options. They must identify the feature or practice that best addresses this need: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use supported Databricks CLI bundle commands to validate, deploy, run, and manage bundles as part of automated CI/CD workflows
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Databricks CLI for validation deployment and bundle management. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 11

The platform team at Trey Research is comparing implementation options. They must choose the most accurate administrative approach for this requirement: use column masking and row filters for group-based data visibility. Which option best matches the requirement and the goal to support repeatable administration? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use Liquid Clustering for flexible data layout optimization and predictive optimization where Databricks can automatically apply supported table-maintenance optimizations
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Understand Liquid Clustering and predictive optimization. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 12

For an upcoming rollout at Adventure Works, the BI team needs to select an implementation consistent with this objective: use unity catalog abac policies for centralized row filtering and column masking. Which response is most appropriate if the solution should also reduce user disruption? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Use supported Databricks CLI bundle commands to validate, deploy, run, and manage bundles as part of automated CI/CD workflows
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Databricks CLI for validation deployment and bundle management. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 13

During an implementation review at Litware, the BI team needs to make a decision that correctly reflects this requirement: differentiate and operate managed and external unity catalog tables. Which approach is the strongest fit when the organization also wants to meet the stated compliance requirement? The choice must be defensible in a security and governance review.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Use COPY INTO for idempotent incremental file ingestion from supported cloud object storage into governed Delta tables when its file-tracking model fits the source
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Use COPY INTO for incremental cloud-object-storage loading into Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 14

A change request at Trey Research has one non-negotiable requirement: implement the skill described by configure privileges with grant revoke and deny at appropriate hierarchy levels. What should the data engineering team choose if the priority is to apply the narrowest effective control? The implementation should avoid adding a control that does not address the stated constraint.

  1. Package and deploy Lakeflow Jobs, Lakeflow Spark Declarative Pipelines, and supported workspace assets in a version-controlled bundle for repeatable promotion
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Deploy Declarative Automation Bundles for jobs pipelines and workspace assets. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 15

A change request at Fabrikam has one non-negotiable requirement: implement the skill described by use column masking and row filters for group-based data visibility. What should the governance team choose if the priority is to reduce user disruption? The implementation should avoid adding a control that does not address the stated constraint.

  1. Apply deterministic deduplication and the correct aggregate functions such as count, approximate distinct count, mean, or summary for the analytical requirement
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Deduplicate and aggregate DataFrames. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 16

An administration ticket for Fourth Coffee states: identify the feature or practice that best addresses this need: use unity catalog abac policies for centralized row filtering and column masking. Which decision should the BI team make to preserve least privilege? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Define and enforce validation rules at appropriate pipeline stages so invalid data is detected, handled, and measurable before Silver or Gold data is trusted
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Apply data quality checks and validation rules. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 17

Fourth Coffee is reviewing a production configuration. The data engineering team must choose the most accurate administrative approach for this requirement: differentiate and operate managed and external unity catalog tables. Which choice most directly satisfies the requirement while trying to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Interpret stage, task, shuffle, and spill metrics in Spark UI to distinguish skew, excessive shuffling, and memory pressure from unrelated bottlenecks

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Identify data skew shuffling and disk spilling using Spark UI. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 18

During an implementation review at Fabrikam, the analytics engineering team needs to select an implementation consistent with this objective: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which approach is the strongest fit when the organization also wants to meet the stated compliance requirement? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Create the required task types and dependency graph so Lakeflow Jobs runs tasks in the intended order and exposes upstream/downstream status clearly
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure notebook SQL dashboard and pipeline tasks with DAG dependencies. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 19

For an upcoming rollout at Proseware, the platform team needs to make a decision that correctly reflects this requirement: use column masking and row filters for group-based data visibility. Which response is most appropriate if the solution should also improve auditability? The team will validate the decision with operational evidence after rollout.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 20

For an upcoming rollout at Wingtip Toys, the BI team needs to identify the feature or practice that best addresses this need: use unity catalog abac policies for centralized row filtering and column masking. Which response is most appropriate if the solution should also apply the narrowest effective control? The choice must be defensible in a security and governance review.

  1. Use job control-flow capabilities such as retries, conditional tasks, and loops to express recoverable and data-dependent orchestration logic
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Implement retries conditional branches and loops with Lakeflow Jobs. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 21

For an upcoming rollout at Woodgrove Bank, the BI team needs to select an implementation consistent with this objective: differentiate and operate managed and external unity catalog tables. Which response is most appropriate if the solution should also preserve least privilege? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use cluster event logs, dependency resolution information, driver/executor logs, and memory behavior to isolate startup, library, or OOM root causes before changing configuration

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Diagnose cluster startup failures library conflicts and out-of-memory issues. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 22

An administration ticket for Wingtip Toys states: select an implementation consistent with this objective: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which decision should the platform team make to keep the design manageable at scale? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use the appropriate Lakeflow Connect connector and governed destination to ingest supported enterprise source data reliably into Unity Catalog tables
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure Lakeflow Connect for enterprise sources. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 23

For an upcoming rollout at Tailspin Toys, the DevOps team needs to implement the skill described by use column masking and row filters for group-based data visibility. Which response is most appropriate if the solution should also support repeatable administration? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Tune shuffle partitions, default parallelism, driver/executor memory, or auto-broadcast threshold only from observed workload behavior and validate changes by re-measuring performance
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use basic Spark tuning parameters and re-measure performance. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 24

During an implementation review at Trey Research, the platform team needs to select an implementation consistent with this objective: use unity catalog abac policies for centralized row filtering and column masking. Which approach is the strongest fit when the organization also wants to reduce user disruption? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use job control-flow capabilities such as retries, conditional tasks, and loops to express recoverable and data-dependent orchestration logic
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Implement retries conditional branches and loops with Lakeflow Jobs. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 25

Contoso is reviewing a production configuration. The governance team must choose the most accurate administrative approach for this requirement: differentiate and operate managed and external unity catalog tables. Which choice most directly satisfies the requirement while trying to support repeatable administration? The team will validate the decision with operational evidence after rollout.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Create the required task types and dependency graph so Lakeflow Jobs runs tasks in the intended order and exposes upstream/downstream status clearly

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure notebook SQL dashboard and pipeline tasks with DAG dependencies. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 26

Proseware is reviewing a production configuration. The DevOps team must choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which choice most directly satisfies the requirement while trying to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 27

The data engineering team at Trey Research is comparing implementation options. They must choose the most accurate administrative approach for this requirement: use column masking and row filters for group-based data visibility. Which option best matches the requirement and the goal to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Package and deploy Lakeflow Jobs, Lakeflow Spark Declarative Pipelines, and supported workspace assets in a version-controlled bundle for repeatable promotion
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Deploy Declarative Automation Bundles for jobs pipelines and workspace assets. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 28

A change request at Wingtip Toys has one non-negotiable requirement: choose the most accurate administrative approach for this requirement: use unity catalog abac policies for centralized row filtering and column masking. What should the analytics engineering team choose if the priority is to keep the design manageable at scale? The implementation should avoid adding a control that does not address the stated constraint.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use the platform architecture, Delta Lake transaction/storage capabilities, and Unity Catalog governance model together to select the right platform component for the workload
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Understand core Databricks Data Intelligence Platform components including architecture Delta Lake and Unity Catalog. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 29

The DevOps team at Northwind Traders is comparing implementation options. They must select an implementation consistent with this objective: differentiate and operate managed and external unity catalog tables. Which option best matches the requirement and the goal to minimize operational overhead? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use cluster event logs, dependency resolution information, driver/executor logs, and memory behavior to isolate startup, library, or OOM root causes before changing configuration
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Diagnose cluster startup failures library conflicts and out-of-memory issues. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 30

The platform team at Contoso is comparing implementation options. They must choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to improve auditability? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Select batch, streaming, or incremental ingestion according to source behavior, latency, scale, and reliability requirements
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use batch streaming and incremental ingestion patterns from supported local and Lakeflow Connect sources. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 31

During an implementation review at Woodgrove Bank, the data engineering team needs to select an implementation consistent with this objective: use column masking and row filters for group-based data visibility. Which approach is the strongest fit when the organization also wants to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Use the platform architecture, Delta Lake transaction/storage capabilities, and Unity Catalog governance model together to select the right platform component for the workload
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Understand core Databricks Data Intelligence Platform components including architecture Delta Lake and Unity Catalog. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 32

Fourth Coffee is reviewing a production configuration. The data engineering team must choose the most accurate administrative approach for this requirement: use unity catalog abac policies for centralized row filtering and column masking. Which choice most directly satisfies the requirement while trying to preserve least privilege? The implementation should avoid adding a control that does not address the stated constraint.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Compare current and historical run durations, retries, task timings, and failures to identify regressions and recurring performance patterns
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Identify job performance trends using Lakeflow Jobs run history. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 33

For an upcoming rollout at Tailspin Toys, the analytics engineering team needs to select an implementation consistent with this objective: differentiate and operate managed and external unity catalog tables. Which response is most appropriate if the solution should also improve auditability? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Choose and configure a scheduled, file-arrival, or table-update trigger based on the event that should start the workflow
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Implement schedules and understand scheduled file-arrival and table-update triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 34

A change request at Tailspin Toys has one non-negotiable requirement: make a decision that correctly reflects this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. What should the governance team choose if the priority is to meet the stated compliance requirement? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Create the required task types and dependency graph so Lakeflow Jobs runs tasks in the intended order and exposes upstream/downstream status clearly
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure notebook SQL dashboard and pipeline tasks with DAG dependencies. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 35

During an implementation review at Tailspin Toys, the analytics engineering team needs to select an implementation consistent with this objective: use column masking and row filters for group-based data visibility. Which approach is the strongest fit when the organization also wants to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Choose and configure a scheduled, file-arrival, or table-update trigger based on the event that should start the workflow

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Implement schedules and understand scheduled file-arrival and table-update triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 36

A change request at Contoso has one non-negotiable requirement: select an implementation consistent with this objective: use unity catalog abac policies for centralized row filtering and column masking. What should the analytics engineering team choose if the priority is to minimize operational overhead? The choice must be defensible in a security and governance review.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use DataFrame or SQL operations to add, drop, split, rename, filter, and explode data while preserving the required schema and row semantics
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Manipulate columns rows and table structures. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 37

The DevOps team at Northwind Traders is comparing implementation options. They must identify the feature or practice that best addresses this need: differentiate and operate managed and external unity catalog tables. Which option best matches the requirement and the goal to keep the design manageable at scale? The team will validate the decision with operational evidence after rollout.

  1. Interpret stage, task, shuffle, and spill metrics in Spark UI to distinguish skew, excessive shuffling, and memory pressure from unrelated bottlenecks
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Identify data skew shuffling and disk spilling using Spark UI. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 38

During an implementation review at Wingtip Toys, the data engineering team needs to choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which approach is the strongest fit when the organization also wants to reduce user disruption? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Apply deterministic deduplication and the correct aggregate functions such as count, approximate distinct count, mean, or summary for the analytical requirement
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Deduplicate and aggregate DataFrames. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 39

An administration ticket for Trey Research states: implement the skill described by use column masking and row filters for group-based data visibility. Which decision should the data engineering team make to avoid unnecessary complexity? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Use the Jobs UI and DAG to locate failed or blocked tasks, understand upstream dependencies, and assess pipeline runtime and failure-rate health

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Monitor pipeline health using Lakeflow Jobs status DAG runtime and failure information. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 40

The BI team at Tailspin Toys is comparing implementation options. They must make a decision that correctly reflects this requirement: use unity catalog abac policies for centralized row filtering and column masking. Which option best matches the requirement and the goal to apply the narrowest effective control? The implementation should avoid adding a control that does not address the stated constraint.

  1. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 41

The platform team at Alpine Ski House is comparing implementation options. They must identify the feature or practice that best addresses this need: differentiate and operate managed and external unity catalog tables. Which option best matches the requirement and the goal to avoid unnecessary complexity? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Read bronze data, handle nulls and malformed values, standardize types and fields, and write validated silver Delta tables
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Clean bronze data and write standardized silver tables with PySpark or SQL. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 42

The BI team at Woodgrove Bank is comparing implementation options. They must choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to support repeatable administration? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 43

An administration ticket for Litware states: make a decision that correctly reflects this requirement: use column masking and row filters for group-based data visibility. Which decision should the BI team make to apply the narrowest effective control? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Configure Auto Loader with the appropriate discovery mode, checkpoint/schema location, enforcement, and evolution behavior for scalable incremental file ingestion
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Auto Loader with schema enforcement and evolution in batch modes. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 44

An administration ticket for Alpine Ski House states: select an implementation consistent with this objective: use unity catalog abac policies for centralized row filtering and column masking. Which decision should the data engineering team make to minimize operational overhead? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Use the Jobs UI and DAG to locate failed or blocked tasks, understand upstream dependencies, and assess pipeline runtime and failure-rate health
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Monitor pipeline health using Lakeflow Jobs status DAG runtime and failure information. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 45

During an implementation review at Fabrikam, the analytics engineering team needs to implement the skill described by differentiate and operate managed and external unity catalog tables. Which approach is the strongest fit when the organization also wants to support repeatable administration? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 46

A change request at Litware has one non-negotiable requirement: choose the most accurate administrative approach for this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. What should the analytics engineering team choose if the priority is to support repeatable administration? The team will validate the decision with operational evidence after rollout.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Parse and normalize JSON, nested, semi-structured, or unstructured source data with a supported managed or code-based ingestion path before landing it in Unity Catalog governed Delta tables
  5. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Ingest semi-structured and unstructured data into governed Delta tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 47

During an implementation review at Wingtip Toys, the data engineering team needs to select an implementation consistent with this objective: use column masking and row filters for group-based data visibility. Which approach is the strongest fit when the organization also wants to keep the design manageable at scale? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Select batch, streaming, or incremental ingestion according to source behavior, latency, scale, and reliability requirements
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use batch streaming and incremental ingestion patterns from supported local and Lakeflow Connect sources. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 48

A change request at Wingtip Toys has one non-negotiable requirement: implement the skill described by use unity catalog abac policies for centralized row filtering and column masking. What should the data engineering team choose if the priority is to minimize operational overhead? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Choose among materialized views, views, streaming tables, and tables according to freshness, recomputation, query, and BI consumption requirements in Unity Catalog
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Build appropriate Gold layer objects for BI and analytics. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 49

An administration ticket for Fabrikam states: select an implementation consistent with this objective: differentiate and operate managed and external unity catalog tables. Which decision should the BI team make to avoid unnecessary complexity? The team will validate the decision with operational evidence after rollout.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  3. Use time-based triggers for clock-driven SLAs and data-driven triggers when execution should follow actual data arrival or table updates
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Choose time-based or data-driven triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 50

The data engineering team at Wingtip Toys is comparing implementation options. They must identify the feature or practice that best addresses this need: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Use job control-flow capabilities such as retries, conditional tasks, and loops to express recoverable and data-dependent orchestration logic

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Implement retries conditional branches and loops with Lakeflow Jobs. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 51

Adventure Works is reviewing a production configuration. The DevOps team must implement the skill described by use column masking and row filters for group-based data visibility. Which choice most directly satisfies the requirement while trying to minimize operational overhead? The team will validate the decision with operational evidence after rollout.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Use the platform architecture, Delta Lake transaction/storage capabilities, and Unity Catalog governance model together to select the right platform component for the workload
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Understand core Databricks Data Intelligence Platform components including architecture Delta Lake and Unity Catalog. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 52

A change request at Fourth Coffee has one non-negotiable requirement: choose the most accurate administrative approach for this requirement: use unity catalog abac policies for centralized row filtering and column masking. What should the analytics engineering team choose if the priority is to reduce security risk? The team will validate the decision with operational evidence after rollout.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Parameterize environment-specific values with Declarative Automation Bundle variables, targets, and overrides so the same source can be promoted across dev, test, and production
  3. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  4. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use Automation Bundle variables and overrides for environment-specific configuration. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 53

For an upcoming rollout at Proseware, the DevOps team needs to choose the most accurate administrative approach for this requirement: differentiate and operate managed and external unity catalog tables. Which response is most appropriate if the solution should also reduce user disruption? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Create the required task types and dependency graph so Lakeflow Jobs runs tasks in the intended order and exposes upstream/downstream status clearly

Correct answer: D

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement. | E: This is the control, feature, or practice that directly implements the stated skill: Configure notebook SQL dashboard and pipeline tasks with DAG dependencies. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 54

The DevOps team at Wingtip Toys is comparing implementation options. They must make a decision that correctly reflects this requirement: configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to keep the design manageable at scale? The team wants the decision to match the exact control boundary rather than the most feature-rich option.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use cluster event logs, dependency resolution information, driver/executor logs, and memory behavior to isolate startup, library, or OOM root causes before changing configuration
  5. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Diagnose cluster startup failures library conflicts and out-of-memory issues. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 55

During an implementation review at Litware, the platform team needs to choose the most accurate administrative approach for this requirement: use column masking and row filters for group-based data visibility. Which approach is the strongest fit when the organization also wants to minimize operational overhead? The implementation should avoid adding a control that does not address the stated constraint.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Interpret stage, task, shuffle, and spill metrics in Spark UI to distinguish skew, excessive shuffling, and memory pressure from unrelated bottlenecks
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Identify data skew shuffling and disk spilling using Spark UI. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 56

A change request at Northwind Traders has one non-negotiable requirement: make a decision that correctly reflects this requirement: use unity catalog abac policies for centralized row filtering and column masking. What should the platform team choose if the priority is to support repeatable administration? The implementation should avoid adding a control that does not address the stated constraint.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  5. Choose and configure a scheduled, file-arrival, or table-update trigger based on the event that should start the workflow

Correct answer: C

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | D: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Implement schedules and understand scheduled file-arrival and table-update triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Question 57

During an implementation review at Adventure Works, the analytics engineering team needs to make a decision that correctly reflects this requirement: differentiate and operate managed and external unity catalog tables. Which approach is the strongest fit when the organization also wants to apply the narrowest effective control? The administrator must distinguish the requested feature from adjacent controls that solve a different problem.

  1. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  2. Use Liquid Clustering for flexible data layout optimization and predictive optimization where Databricks can automatically apply supported table-maintenance optimizations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: E

Why: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Understand Liquid Clustering and predictive optimization. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. This directly matches the scenario requirement.

Learning point: Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Question 58

The BI team at Fourth Coffee is comparing implementation options. They must implement the skill described by configure privileges with grant revoke and deny at appropriate hierarchy levels. Which option best matches the requirement and the goal to improve auditability? The implementation should avoid adding a control that does not address the stated constraint.

  1. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  2. Tune shuffle partitions, default parallelism, driver/executor memory, or auto-broadcast threshold only from observed workload behavior and validate changes by re-measuring performance
  3. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Use basic Spark tuning parameters and re-measure performance. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it

Question 59

Proseware is reviewing a production configuration. The governance team must implement the skill described by use column masking and row filters for group-based data visibility. Which choice most directly satisfies the requirement while trying to meet the stated compliance requirement? The implementation should avoid adding a control that does not address the stated constraint.

  1. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  2. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  5. Read bronze data, handle nulls and malformed values, standardize types and fields, and write validated silver Delta tables

Correct answer: A

Why: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. This directly matches the scenario requirement. | B: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Clean bronze data and write standardized silver tables with PySpark or SQL. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Apply governed row filters and column masks when users should see different rows or protected values from the same governed table

Question 60

An administration ticket for Northwind Traders states: identify the feature or practice that best addresses this need: use unity catalog abac policies for centralized row filtering and column masking. Which decision should the DevOps team make to reduce user disruption? The team will validate the decision with operational evidence after rollout.

  1. Use managed tables when Databricks should manage data lifecycle and external tables when data lifecycle/location must remain externally managed, applying supported create modify delete and conversion operations
  2. Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data
  3. Grant the least privileges needed to users, groups, and service principals at catalog, schema, table, or other supported scopes, using REVOKE or DENY where governance requires it
  4. Apply governed row filters and column masks when users should see different rows or protected values from the same governed table
  5. Choose and configure a scheduled, file-arrival, or table-update trigger based on the event that should start the workflow

Correct answer: B

Why: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement.

Option review: A: This is the control, feature, or practice that directly implements the stated skill: Differentiate and operate managed and external Unity Catalog tables. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | B: This is the control, feature, or practice that directly implements the stated skill: Use Unity Catalog ABAC policies for centralized row filtering and column masking. This directly matches the scenario requirement. | C: This is the control, feature, or practice that directly implements the stated skill: Configure privileges with GRANT REVOKE and DENY at appropriate hierarchy levels. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | D: This is the control, feature, or practice that directly implements the stated skill: Use column masking and row filters for group-based data visibility. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here. | E: This is the control, feature, or practice that directly implements the stated skill: Implement schedules and understand scheduled file-arrival and table-update triggers. It can be appropriate for a different objective, but it does not most directly address the requirement being tested here.

Learning point: Use ABAC policies and governed tags or attributes when row-filtering and column-masking policy should be centrally defined and consistently enforced across matching data

Popular posts

img