Databricks-DE-Assoc Databricks Intelligence Platform Practice Question
A data engineer is preparing a notebook that must authenticate to cloud storage using a short-lived token that is automatically rotated by Databricks and is never written into the notebook source. The engineer wants the least administrative overhead while keeping secrets out of the code. Which approach should the engineer use?
⚠ Common exam trap
The trap here is assuming that a Databricks secret scope automatically rotates the underlying cloud credential, when in fact scopes only store and redact whatever value the engineer manually maintains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an instance profile or managed identity to the cluster and access the storage directly.
Attaching a cloud identity such as an instance profile or managed identity to the cluster is the standard Databricks pattern for credential-free storage access. The cluster's metadata service issues short-lived, automatically rotated credentials scoped to that identity, so nothing sensitive is stored in the notebook or job definition. Secret scopes and widgets still require manual credential handling and rotation, and workspace tokens do not authorize cloud storage access at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hard-code the storage account access key into a widget and pass it at runtime.
Why it's wrong here
Widgets only parameterize a notebook run; the access key still has to be typed or templated into the job definition, and it lands in run history and notebook revisions. It is not automatically rotated by Databricks and provides no scoping to a cluster or identity, so it exposes long-lived cloud credentials rather than providing short-lived, auto-rotated authentication.
- ✓
Attach an instance profile or managed identity to the cluster and access the storage directly.
Why this is correct
Attaching a cloud identity (instance profile on AWS, managed identity on Azure) to the cluster lets the notebook obtain short-lived credentials from the cloud metadata service. Databricks rotates them automatically, no secret appears in code, and access is scoped by the identity's IAM or RBAC policy. This is the lowest-overhead pattern for storage access from notebooks.
- ✗
Create a personal access token for the workspace and use it to call the storage REST API.
Why it's wrong here
A workspace personal access token authenticates to the Databricks REST API, not to the cloud storage account. It cannot read object storage directly and does not carry cloud IAM permissions, so the notebook would still need separate storage credentials. It also is long-lived and tied to a user, which conflicts with the requirement for short-lived, auto-rotated tokens.
- ✗
Store the storage key in a Databricks secret scope and reference it with dbutils.secrets.get in the notebook.
Why it's wrong here
Secret scopes protect the value at rest and redact it in output, but the engineer still must create, populate, and rotate the scope manually, and the raw key is materialized in the driver process. It is a valid pattern, yet it requires more administration than a cluster-attached cloud identity and does not deliver automatic rotation of the underlying credential.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.