Courseiva

Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question

An engineer is deploying a RAG application whose retrieval step calls an external vector database over the public internet. The serving endpoint must reach that database, but corporate policy forbids exposing credentials in the model artifact and forbids public egress from the serving environment. Which configuration satisfies both constraints?

⚠ Common exam trap

The trap here is solving only the credential problem and assuming network egress is automatically handled, when private connectivity to the external database must be configured separately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the database credential in a Databricks secret scope, reference it from the endpoint configuration, and enable network connectivity through a private link or VPC configuration for the serving endpoint.

Credentials belong in a Databricks secret scope so they are injected at runtime rather than stored in the artifact, and reaching a private external service from Model Serving requires explicit private connectivity rather than default public routing. Satisfying both constraints means combining secret injection with a private network path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Have the retrieval function read the credential from a Delta table at query time and rely on the default public internet route for database access.

    Why it's wrong here

    Reading a credential from a Delta table still exposes it to anyone with table read access, which does not satisfy the artifact-and-secrets policy, and the default route uses public egress, which the scenario explicitly forbids. Neither constraint is met.

  • ✗

    Embed the database credential as an environment variable inside the logged MLflow model so the serving container can read it at startup.

    Why it's wrong here

    Environment variables baked into the logged model become part of the artifact and are visible to anyone who can read the model version, violating the policy against credentials in artifacts. It also does nothing to address the prohibition on public egress.

  • ✓

    Store the database credential in a Databricks secret scope, reference it from the endpoint configuration, and enable network connectivity through a private link or VPC configuration for the serving endpoint.

    Why this is correct

    Secret scopes keep credentials out of the artifact and inject them at runtime, while private connectivity settings for Model Serving allow egress to the external database without traversing the public internet. Together they meet both the credential and network policy requirements.

  • ✗

    Package the credential into a Python wheel installed as a model dependency and configure the endpoint with serverless compute only.

    Why it's wrong here

    A wheel is part of the model artifact, so embedding a credential there directly violates the stated policy. Serverless-only configuration also does not by itself provide the private network path the external database requires, leaving the egress constraint unmet.

About these practice questions

One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.