Databricks-ML-Assoc Model Deployment Practice Question
Exhibit
{
"error": "Forbidden",
"message": "User does not have CAN_MANAGE permission on the model"
}Refer to the exhibit. A user attempts to update a model stage in the Model Registry and receives this error. What is the most appropriate action to resolve this?
⚠ Common exam trap
Candidates often try to modify model code or rewrite endpoint configurations to fix permission errors, failing to recognize that access control lists (ACLs) restrict registry actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the workspace admin to update the model ACLs
The error clearly indicates a lack of permission to modify the model's state. In Databricks, access control lists (ACLs) are strictly enforced on objects in the registry. To perform administrative actions like changing a model's stage, the user must be assigned the appropriate permission level (CAN_MANAGE) by an owner or admin. This enforces the principle of least privilege, preventing unauthorized users from promoting unvetted models to production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Re-register the model under a new name
Why it's wrong here
Re-registering the model does not grant the user the necessary permissions to manage the original model or even the new one. If the user lacks permissions, they will face the same issue again. This is a workaround that bypasses security best practices instead of addressing the underlying authorization conflict.
- ✓
Request the workspace admin to update the model ACLs
Why this is correct
The correct administrative path is to update the Access Control List (ACL) for the specific model object. A workspace administrator or the current owner has the authority to grant the required 'CAN_MANAGE' permission to the user, allowing them to perform the requested stage transition securely and officially.
- ✗
Upgrade the model to a higher version
Why it's wrong here
Upgrading the version does not change the user's permissions. The error is related to authorization on the resource, not the content of the model itself. Creating a new version would likely be blocked by the same permissions check, as the user still lacks the necessary access to the registry object.
- ✗
Switch to a different Databricks cluster
Why it's wrong here
Permissions in Databricks are tied to the user identity and the object ACLs, not to the compute resources being used. Running the code on a different cluster will not change the authorization outcome. The issue resides in the security layer of the Model Registry service, which is independent of the compute cluster.
Visual reference
About these practice questions
Courseiva writes every Databricks-ML-Assoc question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-ML-Assoc practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Assoc exam.