Courseiva

Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question

A team maintains a Mosaic AI Agent application whose endpoint must call an external LLM provider through a secret stored in a Databricks secret scope. During a deployment pipeline run, the endpoint build step fails while resolving the credential, even though the secret scope exists and the notebook test works. Which configuration should the engineer verify first?

⚠ Common exam trap

The trap here is assuming a working notebook proves the endpoint identity can read the secret, when serving runs under a different principal with its own ACLs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

That the serving endpoint's service principal or the deploying user has READ permission on the secret scope and that the code reads the secret at load time using the correct scope and key.

Credential resolution in Model Serving depends on the identity that loads the model having READ access to the secret scope and on the code requesting the correct scope and key. A notebook author with access may succeed while the endpoint identity fails, and a typo in scope or key produces the same symptom. Checking permissions and the retrieval call resolves the failure without restructuring the deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    That the secret scope is replicated into the Unity Catalog metastore attached to the serving endpoint.

    Why it's wrong here

    Secret scopes are workspace-level objects and are not replicated into a Unity Catalog metastore. There is no concept of attaching a secret scope to an endpoint through the metastore. This misunderstanding leads the engineer away from the real issues of scope permissions and correct secret retrieval in code.

  • ✗

    That the endpoint has been configured with a personal access token embedded directly in the model signature.

    Why it's wrong here

    Embedding credentials in the model signature or artifacts is insecure and unsupported; signatures describe input and output schemas, not authentication. Storing a long-lived token in artifacts also risks leakage. This approach neither explains the load-time failure nor follows Databricks security guidance for serving credentials.

  • ✓

    That the serving endpoint's service principal or the deploying user has READ permission on the secret scope and that the code reads the secret at load time using the correct scope and key.

    Why this is correct

    Serving endpoints run under a service principal or the deploying identity, and secret access requires explicit READ permission on the scope. If the notebook author had access but the endpoint identity does not, or the scope or key name is wrong in the model code, credential resolution fails during load. Verifying permissions and the exact scope/key names targets the most common cause.

  • ✗

    That the secret scope is mounted as a Databricks secret scope in the serving endpoint's environment variables.

    Why it's wrong here

    Secret scopes are not mounted into serving environments. They are accessed from the model code through the Databricks SDK or the dbutils.secrets interface using the scope and key names. Treating a scope as a mount point misidentifies how secrets are exposed to a served model and will not resolve the failure.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.