What you will be able to do
- Explain how Unity Catalog privileges pass down from parent to child objects, and why USE CATALOG is required
- Grant privileges from the Permissions tab in Catalog Explorer
- Certify or deprecate an object and search for certified assets
- Open a table's lineage in Catalog Explorer and know the limits of what lineage captures
1.Access controls and the Permissions tab
In Unity Catalog, a privilege granted on an object also applies to every object beneath it. Granting broad privileges on a catalog therefore has a wide effect. A catalog owner holds all privileges on the catalog and everything in it. A user with SELECT on a catalog can read any table in it. A user with CREATE TABLE on a catalog can create a table in any of its schemas. To follow least privilege, grant only on the specific object or level a user actually needs.
The USE CATALOG requirement gives catalog owners control over what owners of lower-level objects can actually share. In Catalog Explorer, you grant access from the object's page:
1. Click Catalog and select the object, such as a catalog, schema, table or view. 2. Go to the Permissions tab and click Grant. 3. Enter a user's email address or a group name, select the permissions, and click OK.
To grant privileges, you must be a metastore admin, the object's owner, the owner of its parent catalog or schema, or hold the MANAGE privilege on the object. The equivalent SQL statement is GRANT:
GRANT CREATE TABLE ON SCHEMA main.default TO `finance-team`;In the same documentation example, the group is also granted USE SCHEMA on main.default and USE CATALOG on main. That reflects the rule above: a grant on an object only works if the user can also use the containers above it.
Checkpoint 1 of 5· Exam question
A data engineering team registers an existing set of CSV files in cloud object storage as `finance.reporting.legacy_ledger` using `CREATE TABLE ... LOCATION 's3://finance-bucket/ledger/'`. A schema admin later runs `DROP TABLE finance.reporting.legacy_ledger`. What is the effect on the files at that S3 path?
Correct answer: A — The files remain in the S3 path exactly as they were, because the `LOCATION` clause makes this an external table that Unity Catalog governs only through metadata.
- A. Correct. Specifying `LOCATION` at creation makes this an external table, so Unity Catalog only tracks metadata; dropping it removes the catalog entry but leaves the S3 files untouched.
- B. Incorrect. Deleting the underlying files on drop is managed-table behavior; an external table pointing at a user-supplied location keeps its files after the metadata is removed.
- C. Incorrect. A `DROP TABLE` statement does not relocate files into managed storage or convert the table type; dropping simply removes the metastore registration.
- D. Incorrect. Unity Catalog does not place a lock on the storage path after a drop, and no `UNSET LOCATION` step is required since the files are never touched.
2.Certified and deprecated assets
A large catalog can contain many similar tables, and analysts need to know which ones to trust. Unity Catalog handles this with a system-governed tag whose key is system.certification_status. The tag has two values:
- certified: the asset meets internal standards for accuracy, completeness and trust. It shows a check mark in the workspace. - deprecated: the asset is outdated or unreliable and shouldn't be used in new work. It shows a restricted icon.
The icon appears next to the object's name and affects how the data appears in notebooks and the SQL editor. The tag isn't limited to tables. You can also apply it to catalogs, schemas, views, volumes, functions, registered models, dashboards, Genie Agents, Databricks Apps and notebooks.
To apply the tag, you need the ASSIGN permission on the system.certification_status governed tag. You also need to own the object, or hold APPLY TAG on it plus USE SCHEMA and USE CATALOG on its parents. In the UI, open the object, click the kebab menu, choose Assign certification, select Certified, Deprecated or None, and click Save. The SQL equivalent is SET TAG:
-- Apply certified tag key
SET TAG ON TABLE main.sales.transactions `system.certification_status` = `certified`;
-- Apply deprecated tag key
SET TAG ON TABLE main.sales.old_summary `system.certification_status` = `deprecated`;To find trusted data, use the certificationStatus keyword in the workspace search field, for example type:table certificationStatus:certified. You can also pick a value from the Certification status filter. Status changes can take a few minutes to show up in search results. Tag-based search does not work for dashboards, Genie Agents or Databricks apps.
Checkpoint 2 of 5· Fill the gap
Which tag value marks this table as outdated?
SET TAG ON TABLE main.sales.old_summary `system.certification_status` = ` ? `;The system.certification_status tag accepts only two values, certified and deprecated. A deprecated asset is shown with a restricted icon, but restricted is not a tag value.
Source: docs.databricks.comSources3
3.Lineage in Catalog Explorer
Lineage shows where a table's data comes from and where it goes: the queries and files that populate it, the jobs and notebooks that transform it, and the dashboards that use it. Unity Catalog captures lineage automatically, down to the column level, for queries run on Databricks, and combines it across every workspace attached to the metastore. Typical uses are impact analysis before changing a table, tracing the cause of a bad report back to its source, and tracking sensitive data for compliance.
Lineage is captured only for tables registered in Unity Catalog, and only for queries that use the Spark DataFrame API or Databricks SQL interfaces. To view a table's lineage, you need at least BROWSE on its parent catalog.
Checkpoint 3 of 5· Put it in order
Put the steps for viewing a table's lineage graph in Catalog Explorer in order
- 1.Search or browse for the table
- 2.Select the Lineage tab to see related tables
- 3.In your workspace, click Catalog
- 4.Click See Lineage Graph to open the interactive graph
You find the table first, then open its Lineage tab, then expand to the graph. The graph shows one level of connections by default, and you can expand nodes to see more.
“Select the Lineage tab. The lineage panel appears and displays related tables.”Source: docs.databricks.com
In the graph, click the icon on an edge to open the Lineage details panel, which shows the source and target tables and lets you filter related notebooks, jobs, pipelines and queries. Click a column to see the upstream columns it was derived from. On the Lineage tab, Jobs → Downstream lists the jobs that consume the table, and Dashboards lists the dashboards that do.
Catalog Explorer keeps lineage indefinitely, but only lineage captured after September 1, 2024 is available, and the time-range dropdown defaults to 1 year. The lineage system tables keep a rolling 1-year window. Some limitations are commonly tested:
- Lineage is lost when a catalog, schema, table, view or column is renamed. - Column-level lineage is not captured when the source or target is referenced by path instead of by table name. - Global temp views and RDDs are not captured.
Checkpoint 4 of 5· Check yourself
A team renames a heavily used table and then opens its Lineage tab. What should they expect?
Renaming is a documented lineage limitation. After a rename, the earlier lineage is not linked to the new name.
“Lineage is not preserved for renamed catalogs, schemas, tables, views, or columns.”Source: docs.databricks.com
Checkpoint 5 of 5· Exam question
A group named `analysts` is granted `SELECT` directly on the table `marketing.campaigns.leads`, but no other privileges are granted anywhere else. When a member of that group tries to run `SELECT * FROM marketing.campaigns.leads` in a SQL editor, the query fails with a permission error. What is the most likely cause?
Correct answer: A — The group is missing `USE CATALOG` on `marketing` and `USE SCHEMA` on `campaigns`, since those container privileges must also be held to traverse the namespace to the table.
- A. Correct. Reaching a table through the three-level namespace requires `USE CATALOG` on the catalog and `USE SCHEMA` on the schema in addition to the object-level `SELECT`, since Unity Catalog privileges do not automatically cascade downward without those container grants.
- B. Incorrect. Unity Catalog grants take effect immediately once applied; there is no propagation delay that would cause a `SELECT` privilege to intermittently fail like this.
- C. Incorrect. A certification badge is a governed-tag status indicator and does not add or change any access-control requirement on top of ordinary catalog and schema privileges.
- D. Incorrect. Serverless SQL warehouses enforce Unity Catalog privileges the same way classic warehouses do; compute type is not the source of this permission failure.
Sources4
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Granting SELECT on a table is enough for a user to query it.Why is that wrong?
The user also needs USE CATALOG on the table's parent catalog. In the documentation's GRANT example, USE SCHEMA is granted alongside it as well.
Covered in Access controls and the Permissions tab
2.Column-level lineage is captured for every query, however the table is referenced.Why is that wrong?
Column lineage is captured only when both source and target are referenced by table name. If either is referenced by path, column lineage is lost.
Covered in Lineage in Catalog Explorer
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.https://docs.databricks.com/aws/en/catalogsOfficial docs
“Because grants on any Unity Catalog object are inherited by children of that object”
↩︎ Access controls and the Permissions tab“that user cannot access that table unless they also have the USE CATALOG privilege on the catalog that contains the table.”
↩︎ Exam trap 1“that user cannot access that table unless they also have the USE CATALOG privilege on the catalog that contains the table.”
↩︎ Prediction - 2.
“Go to the Permissions tab.”
↩︎ Access controls and the Permissions tab“Metastore admin, the MANAGE privilege on the object, the owner of the object, or the owner of the catalog or schema”
↩︎ Access controls and the Permissions tab - 3.https://docs.databricks.com/aws/en/data-governance/unity-catalog/certify-deprecate-dataOfficial docs
“Certified assets display a check mark in the workspace.”
↩︎ Certified and deprecated assets“You must have the ASSIGN permission on the system.certification_status governed tag to apply it to objects.”
↩︎ Certified and deprecated assets“It might take a few minutes for certification or deprecation updates to appear in search results.”
↩︎ Certified and deprecated assets - 4.
“Unity Catalog captures lineage automatically for queries run on Databricks, down to the column level”
↩︎ Lineage in Catalog Explorer“You must have at least the BROWSE privilege on the parent catalog of the table or view.”
↩︎ Lineage in Catalog Explorer“The default selection is 1 year.”
↩︎ Lineage in Catalog Explorer“Column lineage cannot be captured if the source or the target is referenced as path”
↩︎ Exam trap 2“Select the Lineage tab. The lineage panel appears and displays related tables.”
↩︎ Checkpoint“Lineage is not preserved for renamed catalogs, schemas, tables, views, or columns.”
↩︎ Checkpoint