Databricks-GenAI-Assoc Design Applications Practice Question
A GenAI engineer is building a customer-support assistant on Databricks. The assistant must invoke an external LLM endpoint that requires an API token, and the token must not appear in notebook source or logs. The engineer wants to store the token once and let notebooks and Databricks Jobs reference it by name. Which Databricks capability should the engineer use to satisfy this requirement?
⚠ Common exam trap
The trap here is assuming any file or variable accessible from a notebook is safe for credentials, when only a purpose-built secret store redacts values and enforces access control and auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Databricks secrets backed by a secret scope
Databricks secrets provide a governed, auditable store for sensitive values and expose them through dbutils.secrets.get or secret references, so the external LLM token is never embedded in code or logs. Other storage locations either expose plaintext to readers or serve a different purpose, such as authenticating to the workspace rather than to an external provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Unity Catalog volume mounted at /Volumes/secure/token.txt
Why it's wrong here
Unity Catalog volumes store files with access controls, but the token would still be readable as plaintext by any principal with volume access and could be printed into notebook output or logs. Volumes are designed for data files, not for secret redaction, so they do not meet the requirement that the token never appear in logs or source.
- ✗
A workspace environment variable set in the cluster Spark configuration
Why it's wrong here
Spark configuration values are visible to anyone who can view the cluster configuration and are commonly echoed in logs and notebooks, so the token would be exposed. Environment variables also lack per-user access control and auditability, making them unsuitable for protecting an external LLM provider token in a shared workspace.
- ✗
A personal access token stored in the Databricks CLI configuration file
Why it's wrong here
A Databricks personal access token authenticates to the Databricks workspace itself; it cannot be used as the external LLM provider credential and does not provide a named reference that notebooks and jobs can resolve. Storing it in a CLI config file also places a plaintext credential on disk outside the governed secret store.
- ✓
Databricks secrets backed by a secret scope
Why this is correct
Databricks secrets store sensitive values in a secret scope and expose them only through dbutils.secrets.get or secret references, so the token never appears in notebook source, logs, or job definitions. This satisfies the requirement of storing the token once and referencing it by name from notebooks and jobs while keeping it out of version control.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.