Prepstellar

DP-600 · Practice set 2 of 8

Granular Data Access Controls: 10 practice questions

10 questions · Untimed · Free

10 free DP-600 practice questions on Granular Data Access Controls, with an explanation for every answer. Untimed. The full mock exam and the timed version are in the app.

Set 2 · Granular Data Access Controls · 10 questions Read the lesson
  1. Question 1 of 10

    Which granular control determines which records a user can access through the SQL analytics endpoint?

    1. ARow-level security applied through T-SQL
    2. BColumn-level security applied through T-SQL
    3. CA workspace Contributor role assignment
    4. DRead item permission on the lakehouse
    Show the answer

    Row-level security addresses record visibility through the SQL analytics endpoint; column-level security addresses fields, while item and workspace permissions are broader scopes.

    Next → 1 / 10
  2. Question 2 of 10

    Which OneLake security role component holds an optional column filter?

    1. AMembers
    2. BData
    3. CConstraints
    4. DPermission
    Show the answer

    Constraints hold optional row or column filters; the other components identify scope, access level, and role membership.

    Next → 2 / 10
  3. Question 3 of 10

    Which mechanism applies granular permissions when a user queries lakehouse data through the SQL analytics endpoint?

    1. AT-SQL permissions using DCL commands
    2. BA workspace-wide role
    3. CAn item permission shared on the lakehouse
    4. DA DefaultReader membership for OneLake data
    Show the answer

    T-SQL permissions are compute permissions for the SQL analytics endpoint and use DCL commands such as GRANT, DENY, and REVOKE.

    Next → 3 / 10
  4. Question 4 of 10

    An analyst uses T-SQL and must see permitted patient records while other records remain inaccessible. Which control fits?

    1. AAssign the analyst the Contributor workspace role
    2. BApply row-level security through T-SQL
    3. CApply column-level security through T-SQL
    4. DGrant Read item permission on the lakehouse
    Show the answer

    The requirement changes record visibility through the SQL endpoint, so row-level security is the matching granular control.

    Next → 4 / 10
  5. Question 5 of 10

    A SQL analytics endpoint user must access a table without receiving access to its confidential fields. Which control fits?

    1. AApply row-level security through T-SQL
    2. BApply column-level security through T-SQL
    3. CAssign the user the Member workspace role
    4. DGrant Read item permission on the lakehouse
    Show the answer

    The requirement concerns access to fields through the SQL endpoint, which is the scope of column-level security.

    Next → 5 / 10
  6. Keep the ones you got wrong

    In the app, every question you miss comes back exactly when you’re about to forget it.

  7. Question 6 of 10

    A Viewer needs access to one selected table through Spark, SQL, and OneLake APIs. Which configuration meets the requirement?

    1. AA Contributor role on the containing workspace
    2. BA lakehouse item permission granting all data
    3. CA custom OneLake role selecting one folder
    4. DA custom OneLake role selecting the table with Read
    Show the answer

    A OneLake role can select a table and is enforced across all three named engines, making it the cross-engine object scope.

    Next → 6 / 10
  8. Question 7 of 10

    A Viewer must view files in one selected folder through Spark and OneLake APIs without editing them. Which role definition fits?

    1. ASelect a table and assign Read permission
    2. BSelect the folder and assign Read permission
    3. CSelect the folder and assign ReadWrite permission
    4. DShare only the lakehouse Read item permission
    Show the answer

    The Data component should select the folder and the Permission component should be Read for view-only access.

    Next → 7 / 10
  9. Question 8 of 10

    A custom OneLake role has a row constraint, but a user assigned as Contributor still reads every row. What explains the result?

    1. AOneLake roles enforce constraints only through Spark
    2. BContributor access is not restricted by OneLake roles
    3. CThe role needs ReadWrite instead of Read permission
    4. DRow constraints are supported only for workspace Admins
    Show the answer

    Admin, Member, and Contributor already have full OneLake read and write access, so a custom OneLake role cannot restrict that workspace-role access.

    Next → 8 / 10
  10. Question 9 of 10

    A Viewer was shared a lakehouse with Read all Apache Spark and subscribe to events, then added to a custom folder role. The user still reads every file. What should the administrator do?

    1. AReplace the folder selection with a table selection
    2. BAssign the user the Contributor workspace role
    3. CChange the custom role permission to ReadWrite
    4. DRemove the user from the DefaultReader role
    Show the answer

    The sharing permission added the user to DefaultReader, which preserves read access to all data despite the narrower custom role.

    Next → 9 / 10
  11. Question 10 of 10

    A Viewer must be blocked from confidential columns through Spark, SQL, and OneLake APIs. Which configuration provides the required cross-engine control?

    1. AA Member workspace role with full data access
    2. BAn item permission that grants all lakehouse data
    3. CA OneLake role with an optional column constraint
    4. DA OneLake role with an optional row constraint
    Show the answer

    A column constraint in a OneLake role is enforced across the three engines named in the requirement.

    Next → 10 / 10
  12. You’ve finished this set

    That’s 10 questions on Granular Data Access Controls. In the app the ones you miss come back exactly when you’re about to forget them.

The whole course, on your phone

Lessons you can read, audio you can listen to on the way to work, and practice that remembers what you got wrong.