Databricks-DE-Assoc Databricks Intelligence Platform Practice Question
A data engineer needs to run a Databricks notebook that processes data stored in an external ADLS Gen2 location. The notebook must access the data securely without embedding credentials in the notebook code. The engineer has already configured a Unity Catalog external location with a storage credential. Which method should the engineer use to read the data?
⚠ Common exam trap
The trap here is assuming that mounting to DBFS or manually configuring OAuth properties is necessary, when Unity Catalog external locations already provide a seamless and secure way to access data without additional credential management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reference the external location path directly in the notebook using the Unity Catalog external location URL.
Unity Catalog external locations are designed to provide secure access to cloud storage using storage credentials managed by Unity Catalog. Once an external location is configured, data engineers can reference the path directly in their notebooks, and Unity Catalog handles authentication and authorization. This approach avoids embedding credentials in code, aligns with security best practices, and ensures that access is governed by Unity Catalog permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reference the external location path directly in the notebook using the Unity Catalog external location URL.
Why this is correct
Unity Catalog external locations allow direct access to cloud storage using the storage credential configured for the location. The engineer can reference the path (e.g., abfss://container@storage.dfs.core.windows.net/path) in Spark read operations, and Unity Catalog will handle authentication and authorization, ensuring secure access without embedding credentials.
- ✗
Use a personal access token (PAT) stored in Databricks secrets to authenticate to ADLS Gen2.
Why it's wrong here
Personal access tokens are for authenticating to Databricks APIs, not for direct access to ADLS Gen2. Using a PAT to access ADLS Gen2 is not a supported authentication method. The engineer should use Unity Catalog's storage credential, which is already configured, to access the external location without managing secrets.
- ✗
Set Spark configuration spark.hadoop.fs.azure.account.oauth2.client.id and related properties in the notebook to authenticate.
Why it's wrong here
Manually setting Spark OAuth properties requires embedding client IDs and secrets in the notebook or cluster configuration, which violates the requirement to avoid embedding credentials. Unity Catalog external locations abstract this away, providing a secure and governed way to access storage without exposing credentials in code.
- ✗
Mount the ADLS Gen2 container to DBFS using a service principal and then read the data from the mount point.
Why it's wrong here
Mounting to DBFS is a legacy approach that bypasses Unity Catalog governance. Since the engineer already configured an external location, mounting would duplicate configuration and potentially expose data outside Unity Catalog's access controls. The preferred method is to reference the external location directly in the notebook.
About these practice questions
This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.