Courseiva
mediumMultiple Choice

Generative AI Leader Practice Question: A financial institution wants to use Gemini to…

A financial institution wants to use Gemini to analyze customer support transcripts and generate summaries. They need to ensure that personally identifiable information (PII) is not included in the summaries. Which approach should they take?

⚠ Common exam trap

Google often tests the misconception that prompt engineering or post-processing can reliably handle security requirements, when in fact a dedicated data loss prevention service like Cloud DLP is the only robust approach for guaranteed PII redaction before model inference.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preprocess the transcripts with Cloud DLP API to redact PII before sending to Gemini

The Cloud Data Loss Prevention (DLP) API provides a purpose-built, scalable service to detect and redact PII from text before it reaches the Gemini model. This ensures that sensitive data is removed at the source, preventing any possibility of leakage in the generated summary, regardless of model behavior or prompt engineering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Preprocess the transcripts with Cloud DLP API to redact PII before sending to Gemini

    Why this is correct

    Cloud DLP API performs deterministic de-identification — infoType detectors plus redaction or replacement — on the transcript text before any prompt reaches Gemini, so PII never enters the model's context and cannot surface in generated summaries. This satisfies the stem's requirement that summaries exclude PII, rather than relying on post-hoc filtering.

  • ✗

    Use a carefully engineered prompt instructing Gemini not to include PII

    Why it's wrong here

    Prompt instructions are probabilistic guidance, not a deterministic control, so Gemini can still emit PII present in the transcript. Prompting suits shaping tone, format or style, but the stem demands guaranteed exclusion, which requires detection and redaction before or after generation.

  • ✗

    Post‑process the generated summaries with a regex filter to remove PII

    Why it's wrong here

    Regex matching only catches PII conforming to known patterns, missing names, addresses and context-dependent identifiers, so residual PII reaches the summary. Regex filtering suits scrubbing structured fields such as card or phone numbers, not the stem's requirement to guarantee no PII in free-text output.

  • ✗

    Fine‑tune Gemini to avoid generating PII

    Why it's wrong here

    Fine-tuning adjusts model weights and behaviour but cannot guarantee suppression of PII that appears verbatim in the input transcript. Fine-tuning suits adapting tone, domain vocabulary or task format; the stem needs deterministic detection and removal of identifiers, which fine-tuning does not provide.

About these practice questions

One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.