A data scientist is building a GenAI application that uses the OpenAI API through Databricks external model endpoints. The application must use credentials stored securely in Databricks and must not expose the API key in code or logs. Which Databricks feature should the data scientist use to store and reference the OpenAI API key?
Databricks secrets allow storing sensitive strings like API keys in a secret scope, which is backed by an encrypted store. Secrets are referenced using dbutils.secrets.get or in endpoint configurations without exposing the value in notebooks or logs. This is the standard, secure way to manage credentials for external services in Databricks.
Why this answer
Databricks secrets provide a secure, encrypted store for sensitive credentials such as API keys. They can be referenced in code and in external model endpoint configurations without revealing the secret value. This meets the requirement to keep the OpenAI API key secure and out of code and logs.
Exam trap
The trap here is assuming that environment variables or volumes provide sufficient security for secrets, when in fact they lack encryption and fine-grained access control.