Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question
A GenAI team's Mosaic AI Agent application is deployed via a Databricks Asset Bundle and served through a Model Serving endpoint. They need the endpoint to call a Unity Catalog function as a tool during inference, and the function reads from a table the endpoint's service principal cannot currently access. What should the engineer do?
⚠ Common exam trap
The trap here is assuming that serving configuration fields like `workload_type` or `auto_capture_config` influence permissions, when access is governed by Unity Catalog grants to the endpoint's service principal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the endpoint's service principal the required privileges on the table and on the Unity Catalog function, then redeploy the bundle.
Unity Catalog functions invoked as tools by a Model Serving endpoint execute under the endpoint's identity, which is a service principal. For the function to read its underlying table, that principal needs EXECUTE on the function plus the appropriate privileges on the table and its parent catalog and schema. Granting those privileges and redeploying the bundle resolves the access failure while keeping credentials out of the code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant the endpoint's service principal the required privileges on the table and on the Unity Catalog function, then redeploy the bundle.
Why this is correct
When a Model Serving endpoint invokes a Unity Catalog function as a tool, the call executes under the endpoint's identity. The service principal therefore needs EXECUTE on the function and the relevant SELECT or USE privileges on the underlying table. Granting those privileges and redeploying the bundle ensures the endpoint can resolve and execute the function at inference time, which is the correct fix for the access failure.
- ✗
Embed the service principal's personal access token in the agent code so the function can authenticate at runtime.
Why it's wrong here
Embedding a personal access token in agent code exposes a long-lived credential in source control and the model artifact, which is a serious security risk. Model Serving endpoints authenticate using their own service principal identity, not embedded tokens. This approach would also fail if the token is rotated and does not grant the service principal the Unity Catalog privileges the function requires.
- ✗
Add the function's source table to the endpoint's `auto_capture_config` so the endpoint can read it during inference.
Why it's wrong here
`auto_capture_config` controls where inference request and response payloads are logged for monitoring; it does not grant read access to any table. Adding the table there would not let the endpoint read it during function execution. The endpoint still needs explicit Unity Catalog privileges for its service principal, so this configuration change would not fix the failure.
- ✗
Change the endpoint's `workload_type` to `GPU_LARGE` so the endpoint runs with elevated permissions.
Why it's wrong here
`workload_type` selects the hardware class for the served model; it has no relationship to permissions or identity. Changing it to `GPU_LARGE` only affects compute, not Unity Catalog privileges. The endpoint would still execute the function under its service principal and still fail the table access check, so this does not resolve the access problem.
Visual reference
About these practice questions
This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.