Databricks-DE-Assoc Implementing CI/CD Practice Question
A data engineering manager wants to ensure that all production code in Databricks is fully audited and versioned. Which TWO of the following steps are required?
⚠ Common exam trap
Candidates often suggest manual reviews or periodic audits, failing to grasp that true auditability requires programmatic enforcement via Git-based workflows and restricted Service Principal access to production environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforce a policy where only the CI/CD Service Principal can update production assets.
Ensuring auditability and versioning requires locking down the production environment and forcing all changes through a Git-based CI/CD pipeline. By disabling manual changes in production and requiring all updates to be merged through a pull request process, teams ensure that every modification is reviewed, logged, and linked to a specific version. These controls are essential for compliance, stability, and maintaining a clear history of system changes in professional data environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant developers 'Can Manage' permissions on production workspace folders.
Why it's wrong here
Granting 'Can Manage' permissions allows developers to make manual changes, which bypasses the CI/CD audit trail. To maintain strict versioning and auditability, developers should only have read or restricted access to production, ensuring that all production modifications happen exclusively through the automated CI/CD pipeline from the versioned source code.
- ✓
Enforce a policy where only the CI/CD Service Principal can update production assets.
Why this is correct
This policy ensures that human users cannot bypass the CI/CD pipeline to make unauthorized or un-audited changes. By restricting updates to a machine identity, the organization guarantees that every change is captured, reviewed, and deployed according to the defined CI/CD process, which is critical for audit compliance and environment stability.
- ✗
Store all notebook development directly in the production workspace.
Why it's wrong here
Storing development work in the production workspace is a major security and reliability risk. It muddies the audit trail, makes the production environment unstable, and prevents proper staging and testing. Development must occur in separate, isolated workspaces to maintain the integrity and auditability of the production environment.
- ✓
Enable Git integration and require pull requests for all merges into main.
Why this is correct
Pull requests provide a formal gatekeeping mechanism that records who approved the code and why. Combined with Git integration, this ensures every change is versioned and traceable. This process creates an indisputable audit trail of all production changes, directly supporting the requirement for full system auditability and configuration versioning.
- ✗
Allow administrators to use personal tokens for manual emergency hotfixes.
Why it's wrong here
Emergency hotfixes should be performed by applying a fix to the source code and going through the standard CI/CD pipeline. Allowing manual hotfixes via personal tokens creates an un-audited 'backdoor' in the system, which contradicts the goal of full auditability and stable, version-controlled production deployments.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.