Databricks-GenAI-Assoc Application Development Practice Question
A developer is creating a custom model serving endpoint that requires an external API call for data enrichment. What is the recommended way to handle sensitive API keys within the Databricks environment?
⚠ Common exam trap
Test-takers sometimes hardcode API credentials or configuration parameters directly inside the notebook or model artifact, compromising security and compliance standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Databricks Secrets API to manage and retrieve keys.
Secrets management is the cornerstone of secure application development in Databricks. By using the Databricks Secrets API, developers can decouple sensitive credentials from source code. This practice prevents the accidental disclosure of keys in version control systems and ensures that credentials are injected into the runtime environment securely, which is mandatory for maintaining a secure and audit-compliant AI development lifecycle in enterprise cloud environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store keys as environment variables in the notebook code.
Why it's wrong here
Storing keys in notebooks exposes them to anyone with access to the code, which violates basic security principles. Notebooks are often shared or stored in Git repositories, making this approach a high-risk practice that can lead to credential theft and potential unauthorized access to external services or cloud infrastructure.
- ✓
Use the Databricks Secrets API to manage and retrieve keys.
Why this is correct
The Databricks Secrets API provides a secure, centralized location for managing sensitive information. It allows for role-based access control, ensuring that only authorized users or services can access the secrets, which protects the application from credential leakage and simplifies secret rotation and management across different deployment environments.
- ✗
Hardcode the keys directly into the model serving inference function.
Why it's wrong here
Hardcoding credentials creates a permanent security risk and makes the application difficult to maintain. If a key needs to be rotated, the code would require modification and redeployment. Furthermore, anyone reviewing the code would have full access to the credentials, which is incompatible with enterprise security standards.
- ✗
Use the DBFS root directory to store key-value text files.
Why it's wrong here
Storing secrets in plain text files within DBFS is insecure because these files are accessible to users with workspace-level permissions. This approach lacks the granular control and encryption provided by the dedicated Secrets API, making it an inappropriate and unsafe method for protecting production-grade credentials and configuration data.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.