Courseiva
Application Development →mediumMultiple Choice

Databricks-GenAI-Assoc Application Development Practice Question

A developer is building a RAG application using Mosaic AI Model Serving. They need to ensure that the embedding model endpoint is strictly accessed only by specific service principals within the workspace. Which feature should the developer configure to enforce this security requirement?

⚠ Common exam trap

Candidates often confuse workspace-level access controls or IAM roles with endpoint-specific permissions. They mistakenly select broad settings like 'Workspace Admin' or 'Can View' instead of the specific 'Can query' permission required for inference.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Model Serving Permissions

To restrict access to Mosaic AI Model Serving endpoints, developers should use Model Serving Permissions. By navigating to the Permissions tab of the specific endpoint, they can grant 'Can query' access exclusively to authorized service principals. This ensures that only authenticated and authorized applications can retrieve embeddings, protecting the model from unauthorized inference calls while maintaining a secure development lifecycle in Databricks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network Security Groups

    Why it's wrong here

    Network Security Groups operate at the cloud infrastructure layer to manage ingress and egress traffic for virtual machines. They do not provide the granular, identity-based access control required to manage specific model serving endpoints within the Databricks workspace environment, making them unsuitable for managing individual service principal permissions.

  • ✗

    Unity Catalog External Locations

    Why it's wrong here

    External Locations in Unity Catalog are designed to manage access to cloud storage buckets for reading or writing data files. They have no functional relationship with Model Serving endpoints or the authorization logic governing how service principals interact with specific inference APIs provided by the Databricks platform.

  • ✓

    Model Serving Permissions

    Why this is correct

    Model Serving Permissions allow administrators to define precise access control lists for each inference endpoint. By assigning 'Can query' privileges only to the required service principals, the developer effectively secures the endpoint, ensuring that unauthorized entities cannot perform inference operations against the deployed embedding model in the production environment.

  • ✗

    Cluster Access Control Lists

    Why it's wrong here

    Cluster Access Control Lists define which users or groups can create, manage, or use specific compute clusters. While they govern compute usage, they do not manage access to standalone Model Serving endpoints, which operate independently of interactive or job clusters within the Databricks workspace architecture.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.