Courseiva
ML Ops →mediumMultiple Choice

Databricks-ML-Pro ML Ops Practice Question

Your organization requires that all models deployed to production must be signed by a security officer. How can you enforce this requirement within the Databricks MLflow Model Registry?

⚠ Common exam trap

Candidates often suggest using manual UI approvals, ignoring the requirement for automated, audit-compliant CI/CD pipelines that enforce security officer sign-offs through programmatic controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict 'CAN_MANAGE' permissions on the model, and use an automated CI/CD pipeline for promotion.

Enforcing approval workflows is crucial for compliance and risk management in MLOps. By using MLflow's permissions and stages, you can restrict who can promote models to 'Production'. Combining this with programmatic checks or external CI/CD gates ensures that a model cannot be deployed without the necessary authorization, preventing unauthorized or unvetted code from reaching production inference services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete all models in the Production stage and only re-upload the signed models.

    Why it's wrong here

    Deleting and re-uploading models is a destructive, manual process that breaks model lineage and auditability. It does not prevent unauthorized users from uploading their own models to the registry. Proper access controls and workflow governance should be used instead of manual deletion to enforce organizational security policies effectively.

  • ✗

    Grant 'CAN_MANAGE' permissions on the registry to everyone to ensure transparency.

    Why it's wrong here

    Granting global manage permissions is a significant security risk. It allows any user to modify, delete, or promote models, which is the opposite of the restricted workflow required for security compliance. Access must be restricted to authorized individuals to maintain the integrity and security of the production model registry.

  • ✓

    Restrict 'CAN_MANAGE' permissions on the model, and use an automated CI/CD pipeline for promotion.

    Why this is correct

    Restricting permissions ensures that only authorized service principals or security officers can manage transitions. By requiring an automated CI/CD pipeline, you ensure that the promotion process is audited and validated against security policies before the model is moved to the Production stage, effectively enforcing the organization's requirements.

  • ✗

    Set the model version description to 'Signed by Security' after manual inspection.

    Why it's wrong here

    A description field is metadata and provides no functional security or gatekeeping. Any user can edit a description, meaning this approach fails to prevent unauthorized promotions. It does not provide the technical enforcement required to ensure that only approved models are transitioned to the Production stage in the registry.

About these practice questions

Courseiva writes every Databricks-ML-Pro question from scratch — 300 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Databricks exam blueprint

This Databricks-ML-Pro practice question is part of Courseiva's free Databricks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Databricks-ML-Pro exam.