Courseiva
Implementing CI/CD →hardMultiple Select

Databricks-DE-Assoc Implementing CI/CD Practice Question

A platform team is setting up a CI/CD pipeline that deploys Databricks jobs and notebooks from a Git repository. They must ensure deployments are secure and auditable. (Choose two.)

⚠ Common exam trap

The trap here is treating any working credential, such as a committed personal access token, as acceptable for automation when the requirement is specifically secure and auditable deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the deployment identity only the permissions required to manage the specific jobs and notebooks it deploys.

Secure, auditable deployments rely on a dedicated non-human identity with narrowly scoped permissions. A service principal whose secret lives in the CI/CD secret store provides traceable, rotatable credentials, and least-privilege grants limit what a compromised pipeline could do while keeping audit records meaningful.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant the deployment identity only the permissions required to manage the specific jobs and notebooks it deploys.

    Why this is correct

    Least-privilege permissions limit the blast radius if the pipeline credential is compromised and keep audit logs focused on the resources the pipeline should touch. This directly supports the security requirement while preserving traceability of what the deployment identity changed.

  • ✓

    Authenticate the pipeline with a service principal and store its OAuth secret in the CI/CD system's secret store.

    Why this is correct

    A service principal is a non-human identity that can be granted least-privilege workspace access and whose activity is attributable in audit logs. Storing its OAuth secret in the CI/CD secret store keeps credentials out of code and pipeline logs, satisfying both the security and auditability requirements.

  • ✗

    Disable workspace audit logs during deployments to reduce log volume and improve pipeline speed.

    Why it's wrong here

    Audit logs are the primary record of who deployed what and when. Disabling them removes the evidence needed for compliance and incident investigation, directly contradicting the auditability requirement, and log volume has no meaningful effect on deployment speed.

  • ✗

    Use a different engineer's personal account for each environment so responsibility is clear.

    Why it's wrong here

    Tying environments to individual accounts creates fragile dependencies on people, complicates offboarding, and makes audit trails ambiguous when accounts change roles. It also conflicts with using a dedicated, least-privilege deployment identity, so it does not meet the stated security and auditability goals.

  • ✗

    Commit the workspace personal access token to the repository so all pipeline runs use the same credential.

    Why it's wrong here

    Committing a personal access token exposes it to anyone with repository read access and ties deployments to an individual's identity. It violates the security requirement, cannot be rotated safely, and produces audit records under a person rather than a pipeline identity.

About these practice questions

One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.