DP-600 · Analytics Security and Governance
19 cards
Workspace and Item Access Controls
-
Quick check
A user needs broad access across many items in the same workspace. Which mechanism fits?
AAn item permission
An item permission applies to one shared item, so it does not cover the rest of the workspace.
BA workspace role, which applies to every item there
Right. Workspace roles apply to every item in the workspace, which is exactly the broad access described.
CA lakehouse Read permission granted separately on each item in turn
Repeating an item permission item by item is the item-scoped mechanism used in the wrong place.
2 / 19
-
Quick check
A data engineer must create and modify items throughout a workspace, but must not share content or manage permissions. Which role is the least-privileged fit?
AContributor, which creates and modifies without sharing
Right. Contributor covers workspace-wide creation and modification and stops short of both excluded capabilities.
BMember
Member adds the sharing capability that the requirement explicitly rules out.
CViewer
Viewer cannot create or modify the items the engineer has to work on.
5 / 19
-
Quick check
What does a Viewer get by default in a Fabric workspace?
AThe ability to modify workspace content, but no SQL access
Viewer can view all workspace content but cannot modify it; modification starts at Contributor.
BSharing rights, plus access to the underlying OneLake data
Viewer includes neither sharing nor default access to the underlying OneLake data.
CA view of listed content, with no OneLake data access
Right. Viewers see the items listed in the workspace and have no underlying OneLake data access by default.
7 / 19
-
Keep your progress in the app
That’s 3 of 8 quick checks. In the app they stay answered, and every lesson remembers where you left off.
-
Quick check
Where do you enter a user and give them a workspace role?
AManage permissions
Manage permissions configures access to one selected item rather than membership of a workspace role.
BManage access, in the workspace
Right. Manage access is the workspace surface for entering a user and choosing their role.
CRead all SQL endpoint data, on the lakehouse
That is a sharing capability on one lakehouse, not a place where workspace roles are assigned.
9 / 19
-
Quick check
A user needs one lakehouse and nothing else in the workspace. What do you use?
AItem permissions, configured from the item's Manage permissions menu
Right. Item permissions apply to a single item, which is what sharing one lakehouse requires.
BThe Contributor workspace role
Contributor reaches every item in the workspace and adds create and modify capabilities as well.
CThe Viewer workspace role
Viewer still applies across the whole workspace rather than to the single item requested.
11 / 19
-
Quick check
An analyst must see one lakehouse's metadata and associated reports, but must not query its underlying data or reach other workspace items. What do you grant?
AViewer, plus Read all SQL endpoint data on the lakehouse
Viewer spans the whole workspace, and the SQL endpoint permission would allow the queries the requirement forbids.
BThe lakehouse shared with Apache Spark and event access
The Apache Spark permission grants underlying data access, which this scenario excludes.
CThe lakehouse shared with Read
Right. Read covers item metadata and associated reports on that one lakehouse and nothing underneath it.
14 / 19
-
Quick check
A contractor needs T-SQL access to all data in one lakehouse, but no Spark access and no workspace membership. What do you configure?
AShare the lakehouse and add Read all SQL endpoint data
Right. That permission supplies T-SQL reads at item scope, without the separate Spark path or workspace-wide membership.
BShare the lakehouse with Read alone
Read alone exposes metadata and associated reports and provides no underlying T-SQL access.
CAssign the Viewer workspace role
Viewer is workspace-scoped and provides no underlying OneLake data access by default.
17 / 19
-
Quick check
Which summary keeps the scopes and the lakehouse permissions straight?
AItem permissions cover the workspace, and lakehouse Read already includes SQL and OneLake data
Both halves are wrong: item permissions apply to a single item, and Read stops short of the underlying data.
BWorkspace roles cover every item, item permissions target one, and lakehouse Read stops at metadata and reports
Right. Broad scope, narrow scope, and the boundary of what a shared lakehouse's Read actually exposes.
CWorkspace roles target one item, item permissions cover the workspace, and Contributor is the role that manages permissions for everyone else
The two scopes are swapped, and permission management belongs to Admin rather than Contributor.
19 / 19
-
8 quick checks · then the test
In the app, finishing the quick checks opens this lesson’s 10-question test, and the ones you miss come back exactly when you’re about to forget them.
The whole course, on your phone
Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.