Databricks-DE-Assoc Governance and Security Practice Question
Which of the following best describes the purpose of 'Credential Passthrough' in Databricks?
⚠ Common exam trap
Candidates often confuse Credential Passthrough with instance profiles, mistakenly believing it allows the cluster to use a single shared administrative service principal for all users instead of individual user identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables users to access cloud storage using their own identity rather than the cluster's service principal.
Credential Passthrough allows users to authenticate to cloud storage using their own identity from the Databricks environment. By passing the user's credentials to the storage layer, Databricks ensures that the storage provider enforces access policies, creating a seamless audit trail and simplifying security management in environments that require strict alignment between user access in Databricks and direct cloud storage access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows a Databricks cluster to automatically scale based on storage latency.
Why it's wrong here
Credential Passthrough is an identity and access management feature, not a performance or infrastructure scaling feature. It concerns the authentication context between the compute cluster and the storage service, whereas cluster autoscaling is managed by the Databricks cluster manager based on resource utilization metrics and job throughput.
- ✓
It enables users to access cloud storage using their own identity rather than the cluster's service principal.
Why this is correct
This feature maps the identity of the user running a notebook or job to the storage access request. Instead of the cluster using a single shared service principal, each user's individual permissions are applied, ensuring that the cloud provider's access logs accurately reflect individual user actions during query execution.
- ✗
It encrypts data in transit between the Databricks workspace and the cloud storage.
Why it's wrong here
Encryption in transit is handled by standard TLS protocols and cloud provider encryption configurations. Credential Passthrough is specifically an identity propagation mechanism and does not perform the cryptographic operations required for data encryption, nor does it replace the underlying security protocols provided by the cloud vendor.
- ✗
It forces all notebook users to use a single shared service principal for security.
Why it's wrong here
Credential Passthrough does the exact opposite of forcing a shared principal. Its primary design goal is to move away from shared service principals toward individual user identity enforcement. This is crucial for environments where auditability and specific user-level permissions on storage resources are mandated by corporate compliance policies.
About these practice questions
One of 276 original Databricks-DE-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.