Courseiva
Governance →hardMultiple Choice

Databricks-GenAI-Assoc Governance Practice Question

A GenAI engineer registers a fine-tuned model in Unity Catalog and wants a downstream application to call it through the Databricks Model Serving endpoint without embedding a long-lived personal access token in the application. The application runs on Azure Databricks and must authenticate as its own identity, and the security team requires that credentials be short-lived and automatically rotated. Which authentication approach should the engineer implement?

⚠ Common exam trap

The trap here is treating a service principal's personal access token as equivalent to OAuth client credentials, when only the latter yields automatically rotated short-lived tokens.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use OAuth machine-to-machine authentication with the service principal's client ID and client secret to obtain a short-lived token

OAuth machine-to-machine authentication lets an application present a service principal's client ID and secret to the Databricks OAuth token endpoint and receive an access token with a limited lifetime. The application has its own Unity Catalog identity, permissions can be granted to that principal on the registered model and serving endpoint, and token refresh happens automatically. This is the supported pattern for non-interactive workloads that must avoid long-lived secrets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Databricks service principal, generate a personal access token for it, and store that token in the application's environment variables

    Why it's wrong here

    A service principal is the right identity, but a personal access token for it is a long-lived bearer credential. If it leaks, an attacker can impersonate the service principal until the token is manually revoked, and there is no automatic rotation. This conflicts with the requirement for short-lived, automatically rotated credentials, so it does not satisfy the security team's constraint.

  • ✓

    Use OAuth machine-to-machine authentication with the service principal's client ID and client secret to obtain a short-lived token

    Why this is correct

    Databricks supports OAuth 2.0 client credentials flow for service principals, where the application exchanges its client ID and secret for an access token that expires in about an hour. The application authenticates as its own identity and never stores a durable bearer token. This matches the requirement for short-lived, automatically refreshed credentials and is the recommended pattern for unattended workloads.

  • ✗

    Configure the application to use the workspace user's username and password for basic authentication

    Why it's wrong here

    Azure Databricks does not support basic username and password authentication for REST API or Model Serving calls, and using an interactive user's credentials for an unattended application is an anti-pattern. It also violates the requirement that the application have its own identity, and password-based credentials are neither short-lived nor automatically rotated.

  • ✗

    Embed a Microsoft Entra ID managed identity token directly in the application source code

    Why it's wrong here

    Managed identities are a valid way for Azure resources to obtain tokens, but hardcoding a token into source code defeats the purpose. Tokens expire quickly, so the embedded value would stop working, and committing secrets to source control is a security violation. The application should acquire tokens at runtime from the platform rather than carry a static value.

About these practice questions

This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.