Databricks-GenAI-Assoc Governance Practice Question
A GenAI engineer is building a chatbot using Databricks Model Serving and needs to ensure that the endpoint can only be invoked by users who have been granted the 'genai_users' group. The endpoint is registered in Unity Catalog. Which configuration is required to enforce this access control?
⚠ Common exam trap
The trap here is assuming that USE CATALOG/USE SCHEMA or cluster permissions control endpoint invocation, but the EXECUTE privilege is the specific grant needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant EXECUTE on the model serving endpoint to the 'genai_users' group.
Model serving endpoints registered in Unity Catalog are secured with the EXECUTE privilege. To allow only the 'genai_users' group to invoke the endpoint, an administrator must grant EXECUTE on the endpoint to that group. This ensures that only authorized users can call the endpoint, meeting the access-control requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant USE CATALOG and USE SCHEMA on the catalog and schema containing the endpoint to the 'genai_users' group.
Why it's wrong here
Granting USE CATALOG and USE SCHEMA allows users to navigate the catalog and schema but does not grant permission to invoke the serving endpoint. The EXECUTE privilege is specifically required to call the endpoint. Without EXECUTE, users in the group still cannot invoke it, so this configuration is insufficient.
- ✓
Grant EXECUTE on the model serving endpoint to the 'genai_users' group.
Why this is correct
In Unity Catalog, model serving endpoints are securable objects that support the EXECUTE privilege. Granting EXECUTE to the 'genai_users' group allows only those users to invoke the endpoint. Without this grant, other users cannot call the endpoint, thus enforcing the required access control.
- ✗
Attach the endpoint to a cluster that has been granted CAN ATTACH TO for the 'genai_users' group.
Why it's wrong here
Model serving endpoints are not attached to clusters; they are serverless resources. Cluster permissions control who can use a cluster for computation, not who can invoke a serving endpoint. This approach does not apply to model serving and therefore does not enforce the required access control.
- ✗
Set the endpoint's owner to the 'genai_users' group and rely on ownership for access.
Why it's wrong here
Ownership of a serving endpoint grants management privileges but does not automatically allow all members of the owning group to invoke it. Invocation requires the EXECUTE privilege. Relying solely on ownership would not restrict access to only the group members, as ownership is typically assigned to a single user or group but does not confer invocation rights to all members.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.