Courseiva

Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question

A financial services company has registered a Mosaic AI Agent application in Unity Catalog and wants to serve it through a Databricks Model Serving endpoint that queries a Delta table containing sensitive customer records. The security team requires that the endpoint access the table using a dedicated service principal with least privilege, and that the agent's LLM calls go through a governed gateway that logs usage. Which TWO configurations should the team apply to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is thinking that embedding data in the model artifact or opening a direct connection avoids governance problems, when in fact both bypass Unity Catalog and break the audit and least-privilege requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the serving endpoint's service principal SELECT on the specific customer table and its parent schema, and no broader catalog privileges.

The endpoint runs as its own service principal, so Unity Catalog grants on the specific table and schema give the agent exactly the read access it needs without broader exposure. Databricks AI Gateway on the serving endpoint provides governed routing, authentication, and logging of foundation-model calls. Together these two controls satisfy the least-privilege and governed-gateway requirements while keeping the agent's data access auditable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the table's credentials in the agent's environment variables and have the agent open a direct JDBC connection to the Delta storage account.

    Why it's wrong here

    Direct JDBC access with embedded credentials bypasses Unity Catalog, so none of the table's grants, audits, or lineage apply. Hard-coded credentials in environment variables are also a well-known secret-leakage risk and cannot be rotated without redeploying the agent. This approach fails both the least-privilege requirement and the governed-access requirement the security team set.

  • ✗

    Embed the customer records directly into the agent's MLflow model artifact so the endpoint never queries Unity Catalog at runtime.

    Why it's wrong here

    Baking sensitive customer records into the model artifact bypasses Unity Catalog governance entirely and creates a second, unmanaged copy of the data. It also violates least privilege because anyone who can download the artifact effectively has the data. This is the opposite of the controlled, auditable access the security team wants, and it makes revocation of access impossible.

  • ✗

    Disable Unity Catalog enforcement on the endpoint so the agent can read the table with the workspace owner's inherited permissions.

    Why it's wrong here

    Unity Catalog enforcement cannot be selectively disabled for a serving endpoint, and relying on inherited workspace-owner permissions would grant far more access than the table alone. This directly contradicts the least-privilege and dedicated-service-principal requirements in the scenario. It would also break the audit trail the security team depends on for sensitive customer records.

  • ✓

    Grant the serving endpoint's service principal SELECT on the specific customer table and its parent schema, and no broader catalog privileges.

    Why this is correct

    Model Serving endpoints execute under a service principal, and Unity Catalog enforces that principal's grants at query time. Granting SELECT only on the specific table and its parent schema satisfies least privilege while still allowing the agent's retriever to read the records it needs. Broader catalog-wide grants would violate the security team's requirement and expose unrelated tables to the endpoint.

  • ✓

    Configure a Databricks AI Gateway on the serving endpoint so that requests to the foundation model are routed, authenticated, and logged centrally.

    Why this is correct

    AI Gateway sits in front of the model and provides governed routing, authentication, rate limiting, and usage logging for inference traffic. Attaching it to the serving endpoint meets the requirement that LLM calls pass through a governed gateway that records usage. It also lets the team swap or fall back between model providers without changing the agent code.

About these practice questions

This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.