Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A data scientist is building a GenAI application that uses the OpenAI API through Databricks external model endpoints. The application must use credentials stored securely in Databricks and must not expose the API key in code or logs. Which Databricks feature should the data scientist use to store and reference the OpenAI API key?

⚠ Common exam trap

The trap here is assuming that environment variables or volumes provide sufficient security for secrets, when in fact they lack encryption and fine-grained access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Databricks secrets with a secret scope

Databricks secrets provide a secure, encrypted store for sensitive credentials such as API keys. They can be referenced in code and in external model endpoint configurations without revealing the secret value. This meets the requirement to keep the OpenAI API key secure and out of code and logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unity Catalog volumes with restricted permissions

    Why it's wrong here

    Volumes are for storing files and data, not for managing secrets. While you could store a file containing the key in a volume, it would be accessible to anyone with read permissions on the volume and would not be encrypted at the field level. This does not provide the same security guarantees as a dedicated secret store.

  • ✗

    Hardcoding the API key in a notebook and then deleting the cell

    Why it's wrong here

    Hardcoding secrets in notebooks is a security anti-pattern. Even if the cell is deleted, the key may persist in notebook revision history, cluster logs, or memory. This directly violates the requirement to not expose the API key in code or logs and is not a supported secure method.

  • ✓

    Databricks secrets with a secret scope

    Why this is correct

    Databricks secrets allow storing sensitive strings like API keys in a secret scope, which is backed by an encrypted store. Secrets are referenced using dbutils.secrets.get or in endpoint configurations without exposing the value in notebooks or logs. This is the standard, secure way to manage credentials for external services in Databricks.

  • ✗

    Environment variables set in the cluster's Spark configuration

    Why it's wrong here

    Environment variables in Spark config are visible in the cluster configuration and can be exposed in logs or through the Spark UI. They are not encrypted and can be read by any user with access to the cluster. This approach violates the requirement to keep the API key secure and not expose it in logs.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.