Courseiva

Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question

A team deploys a Mosaic AI Agent application through Databricks Apps and must let the app call a Model Serving endpoint that enforces Unity Catalog permissions on the underlying model. Which TWO configurations are required for the app to authenticate and be authorized to query that endpoint? (Choose two.)

⚠ Common exam trap

The trap here is treating network exposure or data-sharing features as substitutes for authenticating the app's service principal and granting it endpoint privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the app's service principal the appropriate privileges on the serving endpoint and the model it serves.

Querying a Unity Catalog-governed serving endpoint requires both a valid identity and the right privileges. The app must present an OAuth token for its service principal so the request is authenticated, and that service principal must be granted access to the endpoint and the served model so authorization succeeds. Together these let the app call the endpoint without embedding human credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant the app's service principal the appropriate privileges on the serving endpoint and the model it serves.

    Why this is correct

    Databricks Apps run under a service principal, and Unity Catalog-governed serving endpoints check that identity's privileges. Granting the app's service principal access to the endpoint and the served model is what authorizes the call. Without those grants the app authenticates successfully but receives a permission error, so this is a required authorization step rather than an optional hardening measure.

  • ✓

    Configure the app to obtain an OAuth token for its service principal and pass it as a bearer token when calling the endpoint.

    Why this is correct

    Calls to a governed serving endpoint must carry a valid OAuth token representing an authorized identity. Databricks Apps can obtain a token for their own service principal and present it as a bearer token on the request, which lets the endpoint evaluate Unity Catalog privileges for that identity. Without a token the request is unauthenticated and rejected before authorization is even considered.

  • ✗

    Register the app as a Delta Sharing recipient and share the model with it.

    Why it's wrong here

    Delta Sharing governs data sharing across organizations and recipients; it is not the mechanism that authorizes an application to invoke a Model Serving endpoint. Registering the app as a recipient would not grant serving privileges and would not produce a token for the endpoint call. This confuses a data-sharing feature with model-serving authorization and fails to address the scenario.

  • ✗

    Enable public network access on the serving endpoint so the app can reach it without a token.

    Why it's wrong here

    Network accessibility and identity authorization are separate concerns. Opening public access does not supply an identity for Unity Catalog permission checks, so a governed endpoint would still reject an unauthenticated call. This setting also weakens the security posture and is unrelated to whether the app can query the endpoint, making it neither required nor helpful here.

  • ✗

    Embed a personal access token for a workspace admin in the app source so the endpoint always resolves an admin identity.

    Why it's wrong here

    Embedding a personal access token in source is a credential exposure risk and ties the app to a human identity that can be rotated or deactivated. It also bypasses the intended service-principal authorization model, granting far more privilege than the app needs. The endpoint would authenticate, but this is neither required nor acceptable practice for a deployed application.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.