Courseiva
Model Deployment →mediumMultiple Select

Databricks-ML-Assoc Model Deployment Practice Question

A platform team is rolling out a new Databricks Model Serving endpoint for a churn model. They must ensure the endpoint can be queried by an external application and that only authorized callers can invoke it. Which TWO actions should they take? (Choose two.)

⚠ Common exam trap

The trap here is assuming that enabling logging or another observability feature provides access control, when authentication and permissions must be configured explicitly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the calling principal permission on the served model or endpoint and issue a Databricks personal access token or OAuth token for authentication.

Securing an endpoint for external use requires both an authenticated identity and a permission grant. A service principal with an OAuth token is the preferred machine identity, and granting it permission on the endpoint or served model enforces authorization. Using a personal access token for a human or service identity works similarly. Together these actions let the external application reach the endpoint while ensuring unauthorized callers are rejected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Expose the endpoint only through a cluster-scoped init script that writes the scoring URL into the application's configuration.

    Why it's wrong here

    Init scripts run during cluster startup and are unrelated to serving endpoint exposure or caller authorization. Writing a URL into configuration does not authenticate the caller and provides no access control. This option confuses cluster provisioning with endpoint security and would leave the endpoint reachable only by whoever already has credentials, without establishing the required authorization model.

  • ✓

    Grant the calling principal permission on the served model or endpoint and issue a Databricks personal access token or OAuth token for authentication.

    Why this is correct

    Model Serving endpoints are protected by Databricks authentication and Unity Catalog or workspace permissions. Granting the caller permission and supplying a bearer token ensures requests are authenticated and authorized. This combination is the supported way to expose an endpoint to an external application while enforcing access control, satisfying both the reachability and the authorization requirements in the scenario.

  • ✗

    Disable authentication on the endpoint so the external application can call the REST API without credentials.

    Why it's wrong here

    Model Serving endpoints do not offer an option to turn off authentication. Even if such a setting existed, it would violate the requirement that only authorized callers invoke the model. This choice directly contradicts the security objective and would expose the endpoint to unauthenticated traffic, so it cannot be part of a correct solution.

  • ✗

    Enable inference tables on the endpoint so that requests are logged and therefore implicitly authenticated.

    Why it's wrong here

    Inference tables record request and response payloads for observability and governance. Logging occurs after a request is accepted; it does not authenticate or authorize callers. Enabling logging would not restrict access to the endpoint, so it fails to meet the requirement that only authorized callers can invoke the model, and it is orthogonal to the authentication mechanism.

  • ✓

    Create a service principal, grant it appropriate permissions, and have the external application authenticate as that service principal.

    Why this is correct

    A service principal provides a non-human identity suitable for machine-to-machine calls. Granting it permission on the endpoint or model and having the external app obtain an OAuth token for that principal enforces least privilege and supports credential rotation. This is a standard production pattern for external integrations and satisfies the authorization requirement without embedding human credentials.

About these practice questions

This Databricks-ML-Assoc question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-ML-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Assoc exam.