Databricks-DE-Assoc Implementing CI/CD Practice Question
A team stores Databricks notebooks and job definitions in a Git repository and wants every merge to the main branch to automatically deploy to production. Which combination of practices should the pipeline implement to achieve this safely?
⚠ Common exam trap
The trap here is focusing on the authentication method alone and overlooking that the workflow trigger must be scoped to the main branch to prevent unreviewed code from reaching production.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trigger the deployment workflow on pushes to the main branch, authenticate with a service principal whose credentials are stored in the CI system's secret manager, and run databricks bundle deploy.
Safe continuous deployment requires two things: a trigger scoped to the main branch so only reviewed, merged code reaches production, and non-interactive authentication via a service principal stored in the CI secret manager. Running databricks bundle deploy from the merged commit then applies the bundle definition reproducibly. Scheduling, branch-agnostic triggers, and personal tokens all undermine control or automation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trigger the deployment workflow on a nightly schedule and use a personal access token for authentication so the deployment uses the developer's existing permissions.
Why it's wrong here
A nightly schedule decouples deployment from merges, so production can lag behind main and hotfixes are delayed. Using a personal access token ties automation to an individual's permissions and lifecycle, which breaks when that person leaves or rotates the token. This does not satisfy the requirement for every merge to deploy safely to production.
- ✗
Trigger the deployment workflow on pushes to any branch and use the Databricks CLI with interactive browser login to authenticate to the production workspace.
Why it's wrong here
Deploying from any branch would push feature work to production without review, and interactive browser login cannot run unattended in a CI pipeline. Both elements are unworkable for automated deployment. The pipeline needs a branch-scoped trigger and a non-interactive credential, neither of which this approach provides.
- ✗
Trigger the deployment workflow on pull requests and use the developer's personal access token stored in the repository as a plaintext secret.
Why it's wrong here
Triggering deployment on pull requests would push unreviewed code to production, and storing a personal access token in plaintext exposes credentials that are tied to an individual. This combination is both unsafe and incorrect for production promotion, which should happen only after merge using a dedicated, securely stored service principal credential.
- ✓
Trigger the deployment workflow on pushes to the main branch, authenticate with a service principal whose credentials are stored in the CI system's secret manager, and run databricks bundle deploy.
Why this is correct
Deploying on pushes to main ensures only merged code reaches production, and a service principal stored in the CI secret manager provides non-interactive, auditable authentication. Running databricks bundle deploy applies the bundle definition from the merged commit. This combination enforces the review gate, keeps credentials out of the repository, and makes deployments reproducible and traceable.
About these practice questions
This Databricks-DE-Assoc question is part of Courseiva's 276-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.