Databricks-ML-Pro ML Ops Practice Question
Exhibit
{
"model_name": "revenue_forecast",
"version": 12,
"status": "PENDING_REGISTRATION",
"error": "PERMISSION_DENIED",
"details": "User lacks 'CAN_MANAGE' on Model Registry"
}Refer to the exhibit. A data scientist attempted to register a new model version but received the error shown in the exhibit. Which step should be taken to resolve this issue?
⚠ Common exam trap
Candidates often suggest re-training the model or checking the code, overlooking that this is an IAM/RBAC issue within the Databricks Workspace specific to the Model Registry.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ask an administrator to grant 'CAN_MANAGE' or 'CAN_EDIT' permissions on the model in the MLflow UI.
The error indicates a lack of necessary permissions to perform operations on the MLflow Model Registry in the Databricks workspace. Access control in Databricks is granular; even if a user can write code, they need specific registry-level permissions to promote or register models. This is a common MLOps governance issue where security policies must be correctly balanced with developer autonomy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Upgrade the user's Databricks entitlement to 'Workspace Admin'.
Why it's wrong here
Granting administrative privileges is a major security violation based on the principle of least privilege. Permissions should be managed at the specific object level (Model Registry) rather than broad workspace access. Administrative rights should never be assigned to resolve routine model registration permission errors in a production environment.
- ✗
Update the MLflow experiment tracking URI to point to an external database.
Why it's wrong here
Changing the tracking URI does not solve underlying permission issues within the Databricks Workspace. The error is specific to the Model Registry's access control list (ACL). External databases do not circumvent local Databricks identity and access management policies, and this action would likely break the existing integration entirely.
- ✓
Ask an administrator to grant 'CAN_MANAGE' or 'CAN_EDIT' permissions on the model in the MLflow UI.
Why this is correct
Databricks implements model-specific permissions. To register or modify model versions, the user must have the appropriate permission level assigned to that specific model object. This follows standard security best practices by limiting access to authorized users without granting excessive, unnecessary privileges across the entire workspace or environment.
- ✗
Re-run the training notebook using the cluster owner's credentials.
Why it's wrong here
Using cluster owner credentials for task execution is an anti-pattern that creates security holes. It obscures actual user activity and bypasses auditing. The correct approach is to assign explicit permissions to the individual or service principal performing the task, ensuring accountability and adherence to corporate security and compliance policies.
Visual reference
About these practice questions
Courseiva writes every Databricks-ML-Pro question from scratch — 300 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-ML-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Pro exam.