Courseiva
Implementing CI/CD →mediumMultiple Choice

Databricks-DE-Assoc Implementing CI/CD Practice Question

A data engineering team stores notebooks in a Git repository and wants automated deployments to a Databricks workspace. They configure a GitHub Actions workflow that runs a Databricks CLI command to deploy Databricks Asset Bundles. The workflow authenticates using a service principal OAuth token stored in GitHub Secrets. After the first successful run, subsequent runs fail with an authentication error. The token was created with a 1-hour lifetime. What should the team do to ensure the workflow can authenticate reliably on every run?

⚠ Common exam trap

The trap here is assuming that any token stored in GitHub Secrets will remain valid indefinitely, when short-lived service principal OAuth tokens expire and must be regenerated per run.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the GitHub Actions workflow to obtain a short-lived OAuth token dynamically from the identity provider using a federated identity or client credentials flow before each deployment.

Short-lived OAuth tokens expire, so a CI/CD pipeline must fetch a new token at the start of each run. Using the client credentials flow or workload identity federation with the service principal allows the GitHub Actions workflow to authenticate dynamically without storing a long-lived secret. This is the secure, maintainable pattern for automated Databricks deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run the GitHub Actions workflow on a self-hosted runner inside the Databricks workspace network so that the CLI can use an instance profile for authentication.

    Why it's wrong here

    Instance profiles provide cloud IAM credentials for accessing cloud storage, not Databricks workspace API authentication. Placing a runner inside the workspace network does not grant the Databricks CLI the ability to authenticate as a service principal. The CLI still needs a Databricks token or federated credential to call workspace APIs.

  • ✗

    Increase the service principal OAuth token lifetime to 24 hours in the Databricks account console and update the secret in GitHub.

    Why it's wrong here

    Databricks service principal OAuth token lifetimes are not user-configurable to arbitrary long durations in the account console. Even if a longer lifetime were possible, storing a long-lived static token in GitHub Secrets still requires rotation and increases exposure risk. This does not solve the underlying automation requirement for dynamic token acquisition.

  • ✓

    Configure the GitHub Actions workflow to obtain a short-lived OAuth token dynamically from the identity provider using a federated identity or client credentials flow before each deployment.

    Why this is correct

    Service principal OAuth tokens are short-lived. To authenticate reliably on every run, the pipeline must request a fresh token at runtime rather than reuse a static secret. Using a client credentials flow or workload identity federation with the identity provider lets the workflow mint a token per run, avoiding expiration failures and manual rotation.

  • ✗

    Replace the service principal OAuth token with a personal access token (PAT) generated for a workspace admin user and store it in GitHub Secrets.

    Why it's wrong here

    A workspace admin PAT is tied to a user identity, not a service principal. If that user leaves or the PAT is revoked, the pipeline breaks, and it violates the least-privilege principle. It also doesn't address token lifetime in a secure, automated way. This is not the recommended CI/CD authentication pattern for Databricks.

About these practice questions

This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.