Generative AI Leader Fundamentals of Generative AI Practice Question
A developer is using Vertex AI PaLM API to generate code snippets. The responses sometimes contain security vulnerabilities. What is the best practice to mitigate this?
⚠ Common exam trap
Many exam-takers think increasing token limits or disabling filters improves output quality, when in fact the core issue is controlling content safety through validation and filtering, not adjusting generation parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement input validation and output filtering with safety attributes
Input validation and output filtering with safety attributes directly address security vulnerabilities by sanitizing user inputs and filtering model outputs for harmful content. The Vertex AI PaLM API provides safety attribute scores (e.g., toxicity, harassment) that allow developers to programmatically block or flag responses that exceed defined thresholds, reducing the risk of generating insecure code snippets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement input validation and output filtering with safety attributes
Why this is correct
Input validation rejects malicious prompts, while output filtering with safety attributes screens generated code for insecure patterns before delivery. This layered control mitigates vulnerable snippets at both ends, satisfying the requirement to reduce security flaws in Vertex AI PaLM responses.
- ✗
Disable safety filters to allow more output
Why it's wrong here
Disabling filters removes the guardrails entirely, permitting more unsafe content rather than fewer vulnerabilities. It is tempting because filters can truncate responses, and disabling them would be correct when legitimate prompts are wrongly blocked, not when generated code needs security review.
- ✗
Increase the max output tokens
Why it's wrong here
Max output tokens caps response length; it does not inspect or remediate insecure code. Raising it is tempting because longer completions sometimes help, and that would be correct when responses are being cut off mid-function rather than when they contain security flaws.
- ✗
Set safety settings to block all categories
Why it's wrong here
Blocking all safety categories filters harmful text, not insecure code patterns, and would suppress legitimate output. It is tempting because safety settings are the visible content control, and they would be correct for preventing toxic or dangerous prose rather than code vulnerabilities.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.