Courseiva
Governance and Security →mediumMultiple Choice

Databricks-DE-Assoc Governance and Security Practice Question

Which of the following is the best practice for managing service principals in a Databricks workspace?

⚠ Common exam trap

Candidates mistakenly suggest using a personal user account for jobs, failing to realize that service principals are the only secure, non-human identity recommended for automated production workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the service principal a dedicated identity with scoped permissions.

Service principals are non-human identities used for automated processes. The best practice is to assign them only the minimum privileges required for the task (least privilege), store their credentials in a secure secrets manager (like Databricks Secrets or Azure Key Vault), and treat them as distinct entities from human users to ensure that automated jobs are isolated and easily auditable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the workspace admin's personal access token for all automated jobs.

    Why it's wrong here

    Using a personal access token (PAT) for automated jobs is a major security risk. If the user leaves the organization or the token is compromised, the jobs will fail or become a security liability. Service principals are specifically designed to be robust, long-lived, and decoupled from human user accounts.

  • ✗

    Store service principal credentials in plaintext variables within notebook code.

    Why it's wrong here

    Storing credentials in plaintext is a severe security violation that exposes the identity to anyone with access to the notebook or the source control system. Always use a dedicated secrets manager to encrypt and retrieve credentials, ensuring that secrets are never visible in the code base or logs.

  • ✓

    Assign the service principal a dedicated identity with scoped permissions.

    Why this is correct

    Assigning a dedicated identity allows for granular control over what the automated job can access. By applying the principle of least privilege, you limit the blast radius if the service principal's credentials are ever leaked, ensuring that the automation can only access the specific resources required for its task.

  • ✗

    Grant the service principal 'Admin' rights to avoid configuration errors.

    Why it's wrong here

    Granting administrative rights to a service principal is dangerous and violates security principles. An account with admin rights can modify security settings, delete data, or change access policies. Always grant the minimum set of permissions required for the specific job function to ensure a secure and resilient architecture.

About these practice questions

Courseiva writes every Databricks-DE-Assoc question from scratch — 276 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-DE-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Assoc exam.