Databricks-GenAI-Assoc Application Development Practice Question
A developer is building a RAG application using Mosaic AI Model Serving. They need to ensure that the embedding model endpoint is strictly accessed only by specific service principals within the workspace. Which feature should the developer configure to enforce this security requirement?
⚠ Common exam trap
Candidates often confuse workspace-level access controls or IAM roles with endpoint-specific permissions. They mistakenly select broad settings like 'Workspace Admin' or 'Can View' instead of the specific 'Can query' permission required for inference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Model Serving Permissions
To restrict access to Mosaic AI Model Serving endpoints, developers should use Model Serving Permissions. By navigating to the Permissions tab of the specific endpoint, they can grant 'Can query' access exclusively to authorized service principals. This ensures that only authenticated and authorized applications can retrieve embeddings, protecting the model from unauthorized inference calls while maintaining a secure development lifecycle in Databricks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network Security Groups
Why it's wrong here
Network Security Groups operate at the cloud infrastructure layer to manage ingress and egress traffic for virtual machines. They do not provide the granular, identity-based access control required to manage specific model serving endpoints within the Databricks workspace environment, making them unsuitable for managing individual service principal permissions.
- ✗
Unity Catalog External Locations
Why it's wrong here
External Locations in Unity Catalog are designed to manage access to cloud storage buckets for reading or writing data files. They have no functional relationship with Model Serving endpoints or the authorization logic governing how service principals interact with specific inference APIs provided by the Databricks platform.
- ✓
Model Serving Permissions
Why this is correct
Model Serving Permissions allow administrators to define precise access control lists for each inference endpoint. By assigning 'Can query' privileges only to the required service principals, the developer effectively secures the endpoint, ensuring that unauthorized entities cannot perform inference operations against the deployed embedding model in the production environment.
- ✗
Cluster Access Control Lists
Why it's wrong here
Cluster Access Control Lists define which users or groups can create, manage, or use specific compute clusters. While they govern compute usage, they do not manage access to standalone Model Serving endpoints, which operate independently of interactive or job clusters within the Databricks workspace architecture.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.