Databricks-ML-Pro Model Development Practice Question
What is the best way to handle secrets (like API keys for external feature sources) within a Databricks notebook during model development?
⚠ Common exam trap
Candidates frequently suggest using environment variables or configuration files, which are insecure, rather than the Databricks-native Secrets API designed specifically for secure credential management in notebooks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the Databricks Secrets API to retrieve credentials at runtime.
Using the Databricks Secrets API is the only secure way to manage credentials. By referencing keys through the `dbutils.secrets.get()` function, developers ensure that sensitive information is never hardcoded or stored in clear text within the version-controlled code. This practice prevents unauthorized access to external systems and is a mandatory security requirement for any enterprise environment dealing with sensitive or paid data APIs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode the keys in a configuration Python script and import it into the notebook.
Why it's wrong here
Hardcoding secrets in any script, even if imported, puts credentials at risk of exposure in source control. If the script is pushed to a Git repository, anyone with read access to the repo will have the keys, which is a major security vulnerability in any enterprise development environment.
- ✓
Use the Databricks Secrets API to retrieve credentials at runtime.
Why this is correct
The Databricks Secrets API allows developers to store sensitive information securely within Databricks and retrieve it programmatically. This keeps credentials out of the codebase entirely, ensuring that only users with the appropriate permissions can access them and that secrets are never logged or stored in version control systems.
- ✗
Store the secrets in an environment variable on the cluster config.
Why it's wrong here
Storing secrets in cluster configurations is less secure than using the Secrets API. Cluster variables are often visible to any user with permission to view the cluster's settings, and they lack the granular lifecycle management, auditing, and rotation capabilities provided by a dedicated secrets management service.
- ✗
Prompt the user to enter the secret manually when the notebook runs.
Why it's wrong here
Manual prompting is unsuitable for automated pipelines, which are the standard for production MLOps. A human-in-the-loop requirement breaks the ability to schedule jobs or trigger retrains via API, making it impossible to scale the training process or ensure consistent execution without constant manual intervention by data science staff.
About these practice questions
One of 300 original Databricks-ML-Pro practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Databricks exam blueprint
This Databricks-ML-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Pro exam.