Courseiva

Generative AI Leader Google Cloud's Generative AI Offerings Practice Question

A company is using Gemini Pro for code generation. They want to ensure that the generated code does not contain security vulnerabilities. Which approach should they implement?

⚠ Common exam trap

Many candidates confuse content safety filters (which block toxic or harmful text) with code security vulnerability scanning, leading them to incorrectly select options that rely on Vertex AI safety settings or grounding, which are not designed to detect code-level security flaws.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a human-in-the-loop review with automated scanning

Combining human-in-the-loop review with automated scanning directly addresses the need to catch security vulnerabilities in AI-generated code. Human reviewers can identify logic flaws and context-specific risks that automated tools miss, while automated scanners provide consistent, rapid detection of known vulnerability patterns (e.g., OWASP Top 10). This layered approach is a best practice for production-grade code generation with Gemini Pro, as it mitigates the inherent limitations of relying solely on AI safety filters or static analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable grounding with security scanning tools

    Why it's wrong here

    Grounding retrieves external context to improve factual accuracy; it does not statically analyse generated code for vulnerabilities. It is tempting because grounding with trusted sources reduces hallucination, and would be correct when the requirement is accurate, current answers rather than secure code.

  • ✗

    Use the Vertex AI Codey API with safety settings

    Why it's wrong here

    Codey safety settings filter harmful content categories such as harassment and dangerous material; they do not analyse generated code for injection flaws or insecure patterns. It is tempting because it is the Vertex AI surface for content policy enforcement, and would be correct when the requirement is blocking toxic or disallowed outputs.

  • ✓

    Implement a human-in-the-loop review with automated scanning

    Why this is correct

    Automated scanning catches known vulnerability patterns such as injection flaws, while human review judges context and logic that scanners miss. Combining both satisfies the requirement that generated code contain no security vulnerabilities, since neither control alone covers the full risk surface.

  • ✗

    Use a custom safety attribute filter

    Why it's wrong here

    Custom safety attribute filters classify and block content against policy categories, not code-level weaknesses like unsanitised input or hardcoded credentials. It is tempting because it offers tunable control over model output, and would be correct when the requirement is enforcing organisation-specific content restrictions.

About these practice questions

Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.