Courseiva
mediumMultiple Choice

Generative AI Leader Data Residency Practice Question

A company is developing a generative AI application that will be used by customers in multiple countries, including those with strict data residency laws. How should they approach data governance?

⚠ Common exam trap

A common misconception is that technical workarounds like VPNs or anonymization can substitute for native data residency enforcement, when in fact only infrastructure-level controls provide the auditable, deterministic compliance required by law.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use data residency controls to keep data in specified regions

Data residency controls, such as those provided by Google Cloud Organization Policies, Assured Workloads, or Cloud Storage location constraints, allow the company to enforce that data is stored and processed only within specified geographic regions. This directly addresses strict data residency laws by preventing data from leaving the jurisdiction, which is a fundamental requirement for compliance with regulations like GDPR or Brazil's LGPD. Unlike workarounds, this approach provides native, auditable enforcement at the infrastructure level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store all data in a single central data center to simplify management

    Why it's wrong here

    A single central data centre conflicts with residency laws requiring data to remain within specific jurisdictions. It tempts because centralisation simplifies operations and cost, but that benefit is irrelevant when legal obligations mandate regional storage; governance must instead map data location to each country's requirements.

  • ✗

    Use a VPN to route data through compliant regions

    Why it's wrong here

    A VPN only encrypts data in transit; it does not change where processing or storage physically occurs, so residency obligations remain unmet. It is tempting because VPNs are commonly used for secure cross-border connectivity, and would suit scenarios needing encrypted links rather than lawful data localisation.

  • ✓

    Use data residency controls to keep data in specified regions

    Why this is correct

    Data residency controls pin storage and processing to approved geographic regions, directly satisfying the strict residency laws named in the stem. This keeps training and inference data within mandated jurisdictions, unlike encryption or consent mechanisms, which address confidentiality and lawful basis rather than the physical location of data.

  • ✗

    Anonymize all data before processing to avoid residency issues

    Why it's wrong here

    Anonymisation does not satisfy residency law, which governs where data is processed regardless of identifiability, and generative models often need personal context. It is tempting because anonymisation reduces privacy risk, and would be correct where the requirement is minimising personal data rather than controlling processing location.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.