Courseiva
Application Development →mediumMultiple Choice

Databricks-GenAI-Assoc Application Development Practice Question

When building a RAG application, a developer wants to ensure that the retrieved context is strictly limited to documents the user has access to. Where should this security logic be enforced?

⚠ Common exam trap

Many candidates incorrectly assume that security logic should be handled by the LLM prompt or the application layer, ignoring that LLMs are prone to prompt injection and cannot reliably enforce data access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

At the Vector Search retrieval layer.

Access control must be enforced at the retrieval layer, ideally within the vector search engine or via a data-filtering mechanism that respects user identity. Relying on the model to enforce security is ineffective, as models cannot reliably manage authorization. Proper integration with Unity Catalog ensures that data retrieval is governed by the same permissions as the underlying tables, maintaining consistent security across the entire data-to-AI lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inside the prompt engineering layer.

    Why it's wrong here

    Prompt engineering is not a security boundary; it is a text-processing layer. Attempting to enforce security here is prone to failure, as users can potentially bypass instructions or the model might misinterpret security constraints, leading to unauthorized data exposure that could have been prevented by proper architectural controls.

  • ✓

    At the Vector Search retrieval layer.

    Why this is correct

    Enforcing access control during the retrieval phase is the most effective approach. By filtering the documents returned from the vector index based on user identity or group membership, you ensure that the generative model only receives content that the specific user is authorized to view and process.

  • ✗

    Within the final response generation phase.

    Why it's wrong here

    Enforcing security after the response is generated is too late; the model might have already been exposed to sensitive information during the context window population. This approach creates a significant security risk by allowing unauthorized data to be processed by the LLM in the first place.

  • ✗

    At the client-side browser application level.

    Why it's wrong here

    Client-side controls are easily circumvented by tech-savvy users and should never be relied upon as the sole enforcement mechanism for security. Sensitive data security must always be enforced on the server-side, ensuring that unauthorized data never leaves the secure environment, regardless of how the client application behaves.

About these practice questions

Courseiva writes every Databricks-GenAI-Assoc question from scratch — 330 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.