Databricks-DE-Pro Developing Code (Python/SQL) Practice Question
An engineer is writing a Python function to process data in a Databricks Notebook. Which command should they use to ensure that secrets, such as API keys, are not hardcoded or exposed in the plain text of the notebook?
⚠ Common exam trap
Candidates often suggest using environment variables or hardcoded strings, failing to realize these are easily exposed in notebook logs or version control, violating security best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dbutils.secrets.get(scope='my_scope', key='my_key')
The dbutils.secrets.get() utility is the standard, secure way to retrieve sensitive information stored in Databricks Secret Scopes. By referencing the scope and key name, the secret value is fetched at runtime and remains masked in the notebook output, preventing accidental exposure of credentials. This is a mandatory practice in any secure data engineering environment to comply with security policies and prevent unauthorized access to downstream data sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
os.environ.get('API_KEY')
Why it's wrong here
Environment variables are not a secure way to store secrets in Databricks. They are often logged or accessible to all users running code on the cluster. Using Secret Scopes is the only supported and auditable way to manage sensitive credentials, ensuring that access is controlled through RBAC and the secrets API.
- ✓
dbutils.secrets.get(scope='my_scope', key='my_key')
Why this is correct
This is the correct function to retrieve a secret value securely. The value returned by this function is automatically redacted if printed in the notebook logs, providing a layer of protection against accidental exposure. It integrates directly with Databricks Secret Scopes, ensuring centralized management and controlled access to sensitive credentials used in code.
- ✗
open('/secret/path').read()
Why it's wrong here
Reading secrets from the local file system is unsafe and prone to errors. File permissions are harder to manage than Secret Scope access policies. Storing credentials in plain text files within the workspace storage is a security vulnerability that contradicts the Databricks best practice of using encrypted, centralized Secret Scopes for all sensitive data.
- ✗
spark.conf.get('secret_key')
Why it's wrong here
The spark.conf interface is for session-level settings, not for sensitive credential retrieval. While one could technically put a secret in the spark configuration, it would be stored as plain text in the job configuration or cluster settings, making it visible to anyone with access to the UI. This is a major security risk.
About these practice questions
Courseiva writes every Databricks-DE-Pro question from scratch — 267 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-DE-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-DE-Pro exam.