Databricks-GenAI-Assoc Application Development Practice Question
A team is designing an LLM application that requires strict data privacy. Which TWO approaches ensure that sensitive data is not leaked during the model inference process or training?
⚠ Common exam trap
Candidates assume that server-side data encryption alone is sufficient for privacy, missing that client-side PII redaction and granular access controls are necessary to prevent leaks during inference and training.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redact PII from prompts using local libraries before sending data to the model.
Data privacy in GenAI necessitates both input sanitization and secure environment configuration. By using PII redaction libraries before sending tokens to the model and enforcing Unity Catalog access controls on training datasets, developers create a robust defense-in-depth posture. These techniques protect against prompt injection and unauthorized data exposure, which are critical security considerations when deploying large language models within enterprise-grade environments where compliance and data sovereignty are top priorities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Redact PII from prompts using local libraries before sending data to the model.
Why this is correct
Sanitizing prompts locally ensures that sensitive information is stripped away before it enters the model inference pipeline. This prevents the model from processing or accidentally memorizing PII, providing a critical layer of security that mitigates the risks associated with data leakage in third-party or internal LLM deployments.
- ✗
Enable public access on all input data buckets for faster retrieval.
Why it's wrong here
Enabling public access on data buckets exposes the entire dataset to external risks, violating basic security principles and compliance regulations. Even if the data is intended for training, it must be protected via strictly defined access controls to ensure that only authorized services and users can interact with it.
- ✓
Restrict training data access using Unity Catalog fine-grained permissions.
Why this is correct
Unity Catalog allows for column-level and row-level security, ensuring that only the relevant subsets of data are accessible to the training process. This minimizes the attack surface and ensures that sensitive data is logically separated from the training pipeline, maintaining adherence to strict corporate data governance and security policies.
- ✗
Store all API keys as plain text in notebook variables.
Why it's wrong here
Hardcoding credentials or storing them in plain text notebooks exposes sensitive tokens to any user with read access to the code. This is a severe security vulnerability that could lead to unauthorized API usage, unexpected billing spikes, or potential compromise of the entire application environment and infrastructure.
- ✗
Use the model provider's default logging for all user queries.
Why it's wrong here
Default logging often captures raw user inputs, which may include PII or sensitive corporate data. Relying on provider-side logging without thorough vetting or masking risks exposing proprietary information to the model vendor, which is typically unacceptable in enterprise environments that require full control over data handling and security.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.