mediumMultiple Choice
Generative AI Leader Data Residency Practice Question
A company is developing a generative AI application that will be used by customers in multiple countries, including those with strict data residency laws. How should they approach data governance?
⚠ Common exam trap
A common misconception is that technical workarounds like VPNs or anonymization can substitute for native data residency enforcement, when in fact only infrastructure-level controls provide the auditable, deterministic compliance required by law.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use data residency controls to keep data in specified regions
Data residency controls, such as those provided by Google Cloud Organization Policies, Assured Workloads, or Cloud Storage location constraints, allow the company to enforce that data is stored and processed only within specified geographic regions. This directly addresses strict data residency laws by preventing data from leaving the jurisdiction, which is a fundamental requirement for compliance with regulations like GDPR or Brazil's LGPD. Unlike workarounds, this approach provides native, auditable enforcement at the infrastructure level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store all data in a single central data center to simplify management
Why it's wrong here
A single central data centre conflicts with residency laws requiring data to remain within specific jurisdictions. It tempts because centralisation simplifies operations and cost, but that benefit is irrelevant when legal obligations mandate regional storage; governance must instead map data location to each country's requirements.
- ✗
Use a VPN to route data through compliant regions
Why it's wrong here
A VPN only encrypts data in transit; it does not change where processing or storage physically occurs, so residency obligations remain unmet. It is tempting because VPNs are commonly used for secure cross-border connectivity, and would suit scenarios needing encrypted links rather than lawful data localisation.
- ✓
Use data residency controls to keep data in specified regions
Why this is correct
Data residency controls pin storage and processing to approved geographic regions, directly satisfying the strict residency laws named in the stem. This keeps training and inference data within mandated jurisdictions, unlike encryption or consent mechanisms, which address confidentiality and lawful basis rather than the physical location of data.
- ✗
Anonymize all data before processing to avoid residency issues
Why it's wrong here
Anonymisation does not satisfy residency law, which governs where data is processed regardless of identifiability, and generative models often need personal context. It is tempting because anonymisation reduces privacy risk, and would be correct where the requirement is minimising personal data rather than controlling processing location.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.