Courseiva
Model Development →mediumMultiple Choice

Databricks-ML-Pro Model Development Practice Question

What is the best way to handle secrets (like API keys for external feature sources) within a Databricks notebook during model development?

⚠ Common exam trap

Candidates frequently suggest using environment variables or configuration files, which are insecure, rather than the Databricks-native Secrets API designed specifically for secure credential management in notebooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Databricks Secrets API to retrieve credentials at runtime.

Using the Databricks Secrets API is the only secure way to manage credentials. By referencing keys through the `dbutils.secrets.get()` function, developers ensure that sensitive information is never hardcoded or stored in clear text within the version-controlled code. This practice prevents unauthorized access to external systems and is a mandatory security requirement for any enterprise environment dealing with sensitive or paid data APIs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hardcode the keys in a configuration Python script and import it into the notebook.

    Why it's wrong here

    Hardcoding secrets in any script, even if imported, puts credentials at risk of exposure in source control. If the script is pushed to a Git repository, anyone with read access to the repo will have the keys, which is a major security vulnerability in any enterprise development environment.

  • ✓

    Use the Databricks Secrets API to retrieve credentials at runtime.

    Why this is correct

    The Databricks Secrets API allows developers to store sensitive information securely within Databricks and retrieve it programmatically. This keeps credentials out of the codebase entirely, ensuring that only users with the appropriate permissions can access them and that secrets are never logged or stored in version control systems.

  • ✗

    Store the secrets in an environment variable on the cluster config.

    Why it's wrong here

    Storing secrets in cluster configurations is less secure than using the Secrets API. Cluster variables are often visible to any user with permission to view the cluster's settings, and they lack the granular lifecycle management, auditing, and rotation capabilities provided by a dedicated secrets management service.

  • ✗

    Prompt the user to enter the secret manually when the notebook runs.

    Why it's wrong here

    Manual prompting is unsuitable for automated pipelines, which are the standard for production MLOps. A human-in-the-loop requirement breaks the ability to schedule jobs or trigger retrains via API, making it impossible to scale the training process or ensure consistent execution without constant manual intervention by data science staff.

About these practice questions

One of 300 original Databricks-ML-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-ML-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Pro exam.