Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question
A machine learning engineer needs to deploy a custom Mosaic AI Model Serving endpoint that requires access to a private internal database. Which mechanism should be used to securely manage the database credentials?
⚠ Common exam trap
Test-takers frequently recommend hardcoding database credentials inside model artifacts or environment variables, ignoring secure workspace secret management practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reference the credentials using the Databricks Secrets API within the model loading script.
Databricks Secrets provide a centralized, secure way to store and reference sensitive information like database credentials. By using the secret scope, the engineer avoids hardcoding sensitive data into the model code or configuration files. This practice is essential for maintaining a secure MLOps lifecycle, as it prevents credential exposure and allows for granular access control via Databricks access control lists (ACLs) on the secret scope itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode the credentials as environment variables in the model serving endpoint deployment configuration.
Why it's wrong here
Embedding credentials directly into configuration files or environment variables poses a significant security risk. Anyone with read access to the endpoint configuration could view the secrets. Databricks Secrets are specifically designed to abstract this information, ensuring that credentials remain encrypted and isolated from the primary source code.
- ✗
Inject the credentials via a public GitHub repository linked to the Databricks Git folder.
Why it's wrong here
Committing credentials to a version control system is a critical security violation. Even in private repositories, sensitive data is accessible to anyone with repository access. Secrets must be managed outside of the application codebase to prevent accidental exposure and to maintain compliance with standard security auditing practices.
- ✓
Reference the credentials using the Databricks Secrets API within the model loading script.
Why this is correct
The Databricks Secrets API allows code to retrieve sensitive values at runtime without exposing them in cleartext. This approach ensures that the credentials exist only in memory during the model execution phase. It provides a secure, auditable path for applications to authenticate with external services like private databases.
- ✗
Store the credentials in a plain-text file on the Unity Catalog volume attached to the serving endpoint.
Why it's wrong here
Storing credentials in plain-text files, even on secure volumes, is insecure because any user with read permission on that volume can access the data. Secrets should always reside in the specialized Secret Store, which enforces encrypted storage and provides specific APIs for retrieval that prevent accidental logging or display.
Visual reference
About these practice questions
This Databricks-GenAI-Assoc question is part of Courseiva's 330-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.