certslothcertsloth
DP-750/Topic 02

Azure / Associate

Security, lineage and sharing

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Grant access to the object and its path.

Must remember

  • Grant Unity Catalog privileges to groups or service principals at the required object scope. Ownership, USE CATALOG/SCHEMA and object privileges serve different purposes.
  • Use row filters and column masks for supported fine-grained controls. ABAC tags and policies can centralize supported classification-based rules; test effective results for representative identities.
  • Storage credentials/external locations and managed identities provide governed storage access. Service principals suit automation; use Key Vault-backed or supported secret handling without printing secret values.
  • Capture table/column descriptions, lineage, history and dependencies in Catalog Explorer. Lineage helps impact analysis, but coverage depends on supported workloads and recorded operations.
  • Audit administrative and data activity according to requirements, with controlled log access and retention. Data-retention policy must coordinate table history, underlying files and legal requirements.
  • Delta Sharing provides governed data sharing across supported recipients. Scope shared objects, recipient authentication and revocation; a data export or recipient copy may outlive future access removal.

Choose under exam pressure

Requirement Choice and reason
Analysts may see only their region A tested row filter with identity-aware policy.
Production jobs access Azure storage A scoped workload identity and governed storage location, not an embedded account key.

Traps

  • Masking a column is not the same as deleting or encrypting the underlying value.
  • Revoking future sharing does not erase copies already lawfully exported.

Active recall

1. Why use groups for grants?

They simplify consistent access lifecycle and reduce individual permission drift.

2. What does lineage help answer?

Where data came from and which downstream objects may be affected by change.

3. Why protect audit logs?

They can reveal sensitive activity and must remain trustworthy for investigation.

4. What must be tested for ABAC?

Tag assignment, policy applicability, effective access and unsupported paths.

5. How should a job retrieve a secret?

Through a supported secret/identity mechanism with least privilege and no log exposure.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.