Concept and mechanism
Unity Catalog organizes catalogs, schemas, and objects. Querying a table involves different roles for container usage privileges and data access; USE CATALOG alone does not grant SELECT. Use appropriate groups and service principals and inspect direct and inherited grants. Revoking a table grant does not eliminate an independent grant inherited from its schema. Managed tables have platform-managed file lifecycles; for an external table, DROP removes metadata without deleting files. Direct access to external storage can bypass Unity Catalog query policies, so cloud controls are also needed.
Guided application
In a fictional case, analysts should see only their region and masked identifiers. Row filters and column masks govern visible content; ABAC associates policies with attributes expressed through governed tags. Control who assigns tags and validate authorized and unauthorized identities. The exam guide mentions DENY, but the legacy SQL DENY command applies to hive_metastore rather than Unity Catalog. ABAC DENY policies in beta are different and, in inspected documentation, restrict MANAGE ACCESS CONTROL rather than SELECT or MODIFY. Do not invent a universal DENY SELECT to fix an overly broad grant. When retiring managed tables, confirm the applicable recovery period before asynchronous file deletion; seven days is the default rather than an immutable rule.
Revoking direct access can leave inherited access active.
Common pitfalls
USE treated as SELECT; external DROP treated as deletion; ungoverned tags; legacy DENY applied to UC.
Related topics: Platform, compute, and data contracts · Incremental ingestion, state, and schema · Transformation, grain, and quality
Check effective access, policy scope, and the actual data destination.
Reference: Manage Unity Catalog privileges · 2026-05-04