Courseiva
Governance →mediumMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A GenAI engineer is building a RAG application on Databricks. They have registered a foundation model endpoint in Unity Catalog as a model. The application needs to query the endpoint, and the engineer wants to ensure that only members of the group 'genai_team' can invoke it. Which Unity Catalog privilege must be granted on the model object to allow invocation?

⚠ Common exam trap

The trap here is assuming that SELECT or USE grants invocation rights on a model, when actually EXECUTE is the specific privilege required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EXECUTE

To invoke a model registered in Unity Catalog, a user must have the EXECUTE privilege on that model. Granting EXECUTE to the genai_team group ensures that only its members can call the model endpoint, aligning with the requirement to restrict access. Other privileges like SELECT, USE, or CREATE do not authorize model invocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    USE

    Why it's wrong here

    USE grants the ability to traverse a parent object (like a catalog or schema) to access its children. It does not directly allow invoking a model. Without EXECUTE on the model itself, USE alone will not permit the genai_team to call the model endpoint.

  • ✗

    SELECT

    Why it's wrong here

    SELECT is used for reading data from tables and views, not for invoking models. While some may confuse model access with querying a table, models in Unity Catalog require EXECUTE to be called. Granting SELECT on a model does not grant the ability to invoke it.

  • ✓

    EXECUTE

    Why this is correct

    EXECUTE is the privilege required to invoke a model registered in Unity Catalog, including foundation model endpoints. Granting EXECUTE to the genai_team group on the model object allows its members to call the model endpoint from their applications, ensuring only authorized users can consume the model.

  • ✗

    CREATE

    Why it's wrong here

    CREATE allows a user to create new objects within a schema or catalog, such as tables or models. It does not grant permission to invoke an existing model. The genai_team needs to execute the model, not create one, so CREATE is irrelevant here.

About these practice questions

This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.