Databricks-GenAI-Assoc Governance Practice Question
A GenAI engineer is building a RAG application on Databricks. They have registered a foundation model endpoint in Unity Catalog as a model. The application needs to query the endpoint, and the engineer wants to ensure that only members of the group 'genai_team' can invoke it. Which Unity Catalog privilege must be granted on the model object to allow invocation?
⚠ Common exam trap
The trap here is assuming that SELECT or USE grants invocation rights on a model, when actually EXECUTE is the specific privilege required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EXECUTE
To invoke a model registered in Unity Catalog, a user must have the EXECUTE privilege on that model. Granting EXECUTE to the genai_team group ensures that only its members can call the model endpoint, aligning with the requirement to restrict access. Other privileges like SELECT, USE, or CREATE do not authorize model invocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
USE
Why it's wrong here
USE grants the ability to traverse a parent object (like a catalog or schema) to access its children. It does not directly allow invoking a model. Without EXECUTE on the model itself, USE alone will not permit the genai_team to call the model endpoint.
- ✗
SELECT
Why it's wrong here
SELECT is used for reading data from tables and views, not for invoking models. While some may confuse model access with querying a table, models in Unity Catalog require EXECUTE to be called. Granting SELECT on a model does not grant the ability to invoke it.
- ✓
EXECUTE
Why this is correct
EXECUTE is the privilege required to invoke a model registered in Unity Catalog, including foundation model endpoints. Granting EXECUTE to the genai_team group on the model object allows its members to call the model endpoint from their applications, ensuring only authorized users can consume the model.
- ✗
CREATE
Why it's wrong here
CREATE allows a user to create new objects within a schema or catalog, such as tables or models. It does not grant permission to invoke an existing model. The genai_team needs to execute the model, not create one, so CREATE is irrelevant here.
About these practice questions
This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.