Databricks-GenAI-Assoc Assembling and Deploying Apps Practice Question
When deploying a Python-based application that interacts with Unity Catalog, which step is essential to ensure the code can authenticate securely to external services without hardcoding tokens?
⚠ Common exam trap
Test-takers often select environment variables or configuration files, ignoring the Databricks security best practice of utilizing Secret Scopes to handle credentials safely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using Databricks Secret Scopes to retrieve credentials.
Using secret scopes within Databricks is the recommended best practice for handling authentication credentials. Secrets allow code to retrieve sensitive information like API keys or database passwords at runtime, keeping these credentials out of the source code. This is a critical security requirement in any production application, as it prevents accidental exposure of sensitive keys in version control systems and allows for centralized management of authentication lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcoding tokens as environment variables in the notebook.
Why it's wrong here
Hardcoding credentials, even as environment variables in a notebook, is a major security risk. These variables can be easily exposed if the notebook is shared or exported. Enterprise standards dictate the use of secret management services to inject credentials securely into the runtime environment at execution time.
- ✓
Using Databricks Secret Scopes to retrieve credentials.
Why this is correct
Secret scopes are the secure way to store and access sensitive information in Databricks. By using the 'dbutils.secrets.get' function, the code retrieves credentials at runtime from a secure vault. This ensures that application logic remains decoupled from specific security credentials, facilitating safer code promotion across different environments.
- ✗
Storing tokens in a plain text file inside the bundle.
Why it's wrong here
Storing credentials in plain text files within a deployment bundle is highly insecure. Anyone with access to the source code repository or the bundle would gain full access to the target systems. Security best practices mandate that credentials must never be committed to version control, regardless of the format.
- ✗
Creating a public access policy for the external service.
Why it's wrong here
Public access policies are insecure and rarely applicable for production data systems. Access should always follow the principle of least privilege, requiring authenticated, authorized connections. Relying on public access would expose the external service to unauthorized users and is not a valid strategy for securing enterprise applications.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.