Databricks-GenAI-Assoc Governance Practice Question
A generative AI engineer registers a model in Unity Catalog and wants a downstream application to call it for inference without granting the application broad workspace access. The engineer is told to grant a specific Unity Catalog privilege on the registered model so the application can invoke it. Which privilege should be granted?
⚠ Common exam trap
The trap here is assuming table-style privileges like SELECT also govern model invocation, when models require EXECUTE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EXECUTE
Registered models in Unity Catalog are invoked under the EXECUTE privilege, which authorizes a principal to call the model without granting ownership or modification rights. Granting EXECUTE to the application's identity, alongside any needed USE CATALOG and USE SCHEMA to resolve the path, provides least-privilege inference access for the downstream application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SELECT
Why it's wrong here
SELECT governs read access to tables and views, not invocation of a registered model. Granting SELECT would be meaningless for the model object and would not authorize inference, so the application would still be denied when it attempts to call the model endpoint, making this the wrong privilege for the scenario.
- ✗
MODIFY
Why it's wrong here
MODIFY authorizes changes to an object's metadata or data, such as altering properties, not calling a model for predictions. Granting MODIFY to an inference application would be over-privileged and still would not confer invocation rights, so it neither meets the requirement nor follows least privilege.
- ✓
EXECUTE
Why this is correct
EXECUTE is the Unity Catalog privilege that authorizes a principal to invoke a registered model or function. Granting EXECUTE on the model to the application's principal allows inference calls while keeping catalog and schema browsing rights separate, which is the least-privilege path for serving a model registered in Unity Catalog.
- ✗
USE CATALOG
Why it's wrong here
USE CATALOG only allows a principal to reference objects within a catalog; it does not by itself permit invoking a model. Without EXECUTE on the model, the application can resolve the object's path but still cannot run inference, so this grant is necessary at most as a companion privilege and insufficient on its own.
Visual reference
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.