Databricks-GenAI-Assoc Governance Practice Question
A GenAI engineer has written a notebook that calls the Databricks Foundation Model APIs to summarize documents. Before the notebook can run in production, the security team wants to confirm exactly which workspace users and service principals are permitted to invoke the pay-per-token foundation model endpoints. Where should the engineer point them to review and manage those permissions?
⚠ Common exam trap
The trap here is assuming foundation model access is configured through workspace-level settings or compute policies rather than Unity Catalog privileges on the system.ai model functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Unity Catalog privileges on the system.ai schema and its model functions
Foundation Model APIs are surfaced as Unity Catalog functions in the system.ai schema, so access is controlled with Unity Catalog privileges, chiefly EXECUTE on the relevant model function, plus the usual USE CATALOG and USE SCHEMA on system.ai. Directing the security team to those grants gives an auditable, centralized view of exactly which users and service principals can invoke each pay-per-token model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Unity Catalog metastore's default storage location settings
Why it's wrong here
The metastore's default storage location determines where managed tables and volumes store their data. It has no relationship to who may call a foundation model endpoint. Reviewing or changing it would not reveal or alter invocation permissions, so it cannot answer the security team's question about endpoint access.
- ✓
The Unity Catalog privileges on the system.ai schema and its model functions
Why this is correct
Databricks exposes foundation models as Unity Catalog functions under the system.ai schema, and invocation is governed by Unity Catalog privileges such as EXECUTE on each model function. Reviewing and granting these privileges shows precisely which users and service principals may call the pay-per-token endpoints, which is exactly what the security team requested.
- ✗
The workspace admin settings page for cluster policies
Why it's wrong here
Cluster policies constrain how compute clusters can be configured, such as which instance types or libraries are allowed. They govern compute provisioning, not model endpoint invocation. A user could comply with every cluster policy and still be denied access to a foundation model endpoint, so this page does not show the relevant permissions.
- ✗
The Azure Databricks access connector assigned to the workspace
Why it's wrong here
An access connector is an Azure resource that lets Databricks access storage accounts on behalf of the workspace. It is about storage authorization, not about which principals can invoke a model endpoint. Changing it would affect data access paths and could break workloads without addressing model endpoint permissions.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.