Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A GenAI engineer has built a Retrieval Augmented Generation (RAG) application using Databricks Vector Search. The index is created on a Delta table that contains sensitive customer support transcripts. Company policy requires that end users can only retrieve chunks from documents they are authorized to view. The engineer wants to enforce this at query time without duplicating the index. Which approach should the engineer use?

⚠ Common exam trap

The trap here is assuming that Unity Catalog row filters and column masks on the source table automatically apply to Vector Search index queries, when in fact the index is a separate serving layer that requires its own query-time filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Databricks Vector Search with the 'filter' parameter in the query, based on user attributes passed from the application.

Databricks Vector Search enables document-level security by allowing metadata filtering at query time. The engineer can include authorization attributes (such as group memberships) as metadata fields when creating the index, then pass a filter expression in the query that matches the user's attributes. This enforces access control without duplicating the index, aligning with the requirement to keep a single index while restricting retrieval to authorized documents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a separate Vector Search index for each user group and route queries based on the user's group membership.

    Why it's wrong here

    Creating separate indexes per user group increases operational overhead and storage costs, and it does not scale well as groups change. More importantly, it duplicates the embeddings and requires maintaining multiple indexes, which the engineer explicitly wanted to avoid. Query-time filtering on a single index is the recommended approach for document-level security in RAG applications.

  • ✓

    Use Databricks Vector Search with the 'filter' parameter in the query, based on user attributes passed from the application.

    Why this is correct

    Databricks Vector Search supports query-time filtering on metadata columns. The engineer can include user authorization attributes as metadata during index creation and then pass a filter expression at query time (e.g., 'allowed_groups' containing the user's group). This enforces document-level security without duplicating the index, directly satisfying the policy requirement while keeping a single index for all users.

  • ✗

    Apply Unity Catalog column masks on the embedding column of the source Delta table to redact sensitive text before vectorization.

    Why it's wrong here

    Column masks on the source table affect how data is read from the table, but the Vector Search index is built from the table's data and stores its own copy of the embeddings and metadata. Masking the embedding column would either break vectorization or not affect the already-built index. It also does not provide per-user filtering at query time, so unauthorized users could still retrieve sensitive chunks.

  • ✗

    Enable Attribute-Based Access Control (ABAC) on the source Delta table using row filter and column mask functions.

    Why it's wrong here

    ABAC on the source Delta table governs access to the underlying table, not the Vector Search index. The RAG application queries the index directly, so table-level row filters and column masks are not applied to vector search results, leaving sensitive chunks retrievable. The engineer needs a mechanism that filters at query time within the vector index itself, not just on the source table.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.