Databricks-GenAI-Assoc Governance Practice Question
A data scientist is building a GenAI application that uses the OpenAI API through Databricks external model endpoints. The application must use credentials stored securely in Databricks and must not expose the API key in code or logs. Which Databricks feature should the data scientist use to store and reference the OpenAI API key?
⚠ Common exam trap
The trap here is assuming that environment variables or volumes provide sufficient security for secrets, when in fact they lack encryption and fine-grained access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Databricks secrets with a secret scope
Databricks secrets provide a secure, encrypted store for sensitive credentials such as API keys. They can be referenced in code and in external model endpoint configurations without revealing the secret value. This meets the requirement to keep the OpenAI API key secure and out of code and logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Unity Catalog volumes with restricted permissions
Why it's wrong here
Volumes are for storing files and data, not for managing secrets. While you could store a file containing the key in a volume, it would be accessible to anyone with read permissions on the volume and would not be encrypted at the field level. This does not provide the same security guarantees as a dedicated secret store.
- ✗
Hardcoding the API key in a notebook and then deleting the cell
Why it's wrong here
Hardcoding secrets in notebooks is a security anti-pattern. Even if the cell is deleted, the key may persist in notebook revision history, cluster logs, or memory. This directly violates the requirement to not expose the API key in code or logs and is not a supported secure method.
- ✓
Databricks secrets with a secret scope
Why this is correct
Databricks secrets allow storing sensitive strings like API keys in a secret scope, which is backed by an encrypted store. Secrets are referenced using dbutils.secrets.get or in endpoint configurations without exposing the value in notebooks or logs. This is the standard, secure way to manage credentials for external services in Databricks.
- ✗
Environment variables set in the cluster's Spark configuration
Why it's wrong here
Environment variables in Spark config are visible in the cluster configuration and can be exposed in logs or through the Spark UI. They are not encrypted and can be read by any user with access to the cluster. This approach violates the requirement to keep the API key secure and not expose it in logs.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.