hardMultiple Choice
Generative AI Leader Practice Question: Deploying a GenAI contract analysis system that…
A company is deploying a GenAI contract analysis system that processes confidential legal documents. They need to ensure that the model does not retain or train on customer data. Which configuration is REQUIRED?
⚠ Common exam trap
Candidates often confuse data security measures (encryption, context window, model size) with data privacy controls (opt-out of logging and retention), leading them to select technically valid but irrelevant options for the specific requirement of preventing data retention and training.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Opt out of model logging and data retention in the API settings
The primary requirement is to prevent the GenAI model from retaining or training on confidential legal documents. In Google Cloud's Vertex AI, customers can configure data governance settings to disable model logging and data retention, ensuring that prompts and responses are not stored or used for model improvement. This configuration directly addresses the compliance need for data confidentiality in contract analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Select a model with a context window large enough to hold the entire contract
Why it's wrong here
Context window size governs how much text the model can process in one prompt; it has no bearing on whether prompts or outputs are retained or used for training. It is tempting because long contracts genuinely require large context, but retention is controlled by the endpoint's data-handling terms, not token limits.
- ✗
Use a public model endpoint with data encryption in transit
Why it's wrong here
Encryption in transit protects data on the wire but does nothing about the provider retaining prompts or training on them afterwards. It is tempting because public endpoints are convenient and encryption is a genuine control, yet the requirement is no retention and no training, which needs a private endpoint with explicit data-handling commitments.
- ✓
Opt out of model logging and data retention in the API settings
Why this is correct
Disabling model logging and data retention in the API settings prevents the provider from storing prompts or outputs, so confidential legal documents are neither retained nor used for training. This directly satisfies the stem's requirement that the model must not retain or train on customer data.
- ✗
Use a smaller model to reduce the risk of data memorization
Why it's wrong here
Model size affects parameter count and compute cost, not whether the provider stores prompts or trains on them; small models can still log and retain inputs. It is tempting because memorisation risk does scale with parameters, but the requirement is contractual no-retention and no-training, which only a private endpoint with those terms guarantees.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.