Databricks-GenAI-Assoc Application Development Practice Question
When integrating an external LLM via a Databricks Model Serving endpoint, how should the API credentials be managed to ensure they are not exposed in the application code?
⚠ Common exam trap
Candidates often suggest environment variables or hardcoded config files. Neither is secure in a collaborative Databricks workspace; Secrets are the only approved way to manage sensitive credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Databricks Secrets to reference credentials at runtime.
Databricks Secrets provide a secure way to reference sensitive information like API keys without hardcoding them in notebooks or source files. By using the 'dbutils.secrets.get' function, the application pulls the key at runtime from a secure vault. This is a best practice for developers to ensure security and prevent credentials from being accidentally committed to version control systems or visible to unauthorized users within the workspace.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store credentials as environment variables in the notebook directly.
Why it's wrong here
Storing credentials as plain text variables in a notebook is insecure, as they are visible to anyone with access to the notebook. Even if the variables are defined during execution, they can easily be exported, logged, or viewed by other users, violating basic security principles for credential management.
- ✓
Use Databricks Secrets to reference credentials at runtime.
Why this is correct
Databricks Secrets are designed to securely store and manage sensitive credentials. Using the secret utility API, developers can inject keys into their code at runtime without the keys ever being written to the source code or persisted in plain text, maintaining high security standards for application integrations.
- ✗
Hardcode the credentials in a hidden Python module.
Why it's wrong here
Hardcoding credentials, even in a separate module, is a dangerous practice that leaves the data vulnerable. If the module is checked into version control, the credentials will be exposed. This approach provides a false sense of security and does not comply with enterprise requirements for secret management.
- ✗
Encrypt credentials and store them in a JSON file within the repo.
Why it's wrong here
Storing encrypted credentials in a repository requires managing the decryption key, which introduces a new security challenge. Furthermore, the credentials are still present in the repository, making them susceptible to theft. Using a managed secret store is always preferred over manual encryption methods for enterprise-grade applications.
About these practice questions
One of 330 original Databricks-GenAI-Assoc practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-GenAI-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-GenAI-Assoc exam.