Microsoft Certified: Fabric Analytics Engineer AssociatePlan and implement data analytics solutions (10-15%)Hard
A company is setting up a Microsoft Fabric Lakehouse to store sensitive customer data. They need to ensure that only authorized personnel can access specific columns containing personally identifiable information (PII) within a Delta table, even when querying through the SQL endpoint. Other users should still be able to query non-PII columns. Which security feature should be implemented?
- ARole-Based Access Control (RBAC) at the Lakehouse level.
- BWorkspace Access Control List (ACLs).
- CRow-Level Security (RLS) on the Delta table.
- DColumn-Level Security (CLS) on the Delta table.
Show answer & explanationAnswer & explanation
Correct answer: D. Column-Level Security (CLS) on the Delta table.
Column-Level Security (CLS) is specifically designed to restrict access to individual columns within a table. This allows authorized users to see all columns while others can only see non-sensitive columns, directly addressing the requirement for granular PII protection at the column level.
Why the other options are wrong
- A. RBAC at the Lakehouse level grants or denies access to the entire Lakehouse, not specific columns within its tables.
- B. Workspace ACLs control access to entire Fabric items (like the Lakehouse itself), not individual columns within a table.
- C. Row-Level Security (RLS) restricts access to *rows* based on user identity or other criteria, not *columns*.
Column-Level Security (CLS)
Column-Level Security (CLS) in data platforms like Microsoft Fabric restricts access to specific columns in a table based on the user's role or permissions, ensuring sensitive data is only visible to authorized individuals.
- Protects sensitive data at a granular level.
- Integrates with SQL endpoint and other query engines.
- Complements RLS for comprehensive data protection.
Memory trick: CLS guards your columns, RLS guards your rows.