Databricks-GenAI-Assoc Design Applications Practice Question
A generative AI engineer is building a RAG chain on Databricks using LangChain. The chain must call an external LLM provider via a Databricks Model Serving endpoint that proxies the provider, and the engineer wants to avoid hardcoding credentials in notebooks. Which approach should the engineer use to authenticate calls from the chain to the serving endpoint?
⚠ Common exam trap
The trap here is assuming the provider API key must be retrieved in the notebook, when the serving endpoint is designed to store and use that credential on the client's behalf.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the serving endpoint with the provider credential stored as a secret in the endpoint's environment, and call the endpoint using the Databricks SDK or LangChain's Databricks LLM class with workspace authentication.
The serving endpoint is the correct place to hold the external provider credential because it centralizes secret storage, rotation, and auditing. Clients then authenticate to the endpoint with workspace identity rather than the provider key. LangChain's Databricks LLM integration and the Databricks SDK both support this pattern, keeping credentials out of notebooks and enabling Unity Catalog governance over the endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass the provider API key as a plaintext argument in the LangChain ChatOpenAI constructor and rely on notebook access controls to protect it.
Why it's wrong here
Plaintext keys in code are exposed in notebook revisions, cluster logs, and version control. Notebook ACLs do not protect the key from users with cluster access or from accidental commits. This approach also prevents centralized rotation and auditing of the provider credential.
- ✗
Use a personal access token generated for a service principal and embed it in the chain's prompt template so the LLM can forward it to the provider.
Why it's wrong here
Embedding a token in a prompt exposes it to the LLM provider and to anyone who can read prompt logs. Personal access tokens are also user-scoped and not designed for service-to-service authentication. The serving endpoint should authenticate with its own configured credential, not a token passed through the prompt.
- ✓
Configure the serving endpoint with the provider credential stored as a secret in the endpoint's environment, and call the endpoint using the Databricks SDK or LangChain's Databricks LLM class with workspace authentication.
Why this is correct
Model Serving endpoints can hold provider credentials as secrets in their environment, so the client only needs a Databricks token. LangChain's Databricks LLM integration and the Databricks SDK both use workspace authentication, keeping the provider key out of notebooks and enabling centralized governance and rotation.
- ✗
Store the provider API key in a Databricks secret scope and reference it with dbutils.secrets.get inside the notebook before instantiating the LLM client.
Why it's wrong here
This still embeds the credential in the notebook runtime and does not leverage the serving endpoint's own authentication. The endpoint should be called with a Databricks token, not the downstream provider key, and secrets in notebook variables can leak into logs or outputs. It also bypasses Unity Catalog and endpoint-level governance.
About these practice questions
Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.