hardMultiple Choice
Generative AI Leader Practice Question: A financial services company needs to deploy an…
A financial services company needs to deploy an AI model that handles highly sensitive transaction data. They require that the model's predictions cannot be inspected by any third party, and the data must remain encrypted at all times, including during inference. Which Google Cloud feature should they use?
⚠ Common exam trap
Many candidates confuse encryption at rest/in transit with encryption in use, and mistakenly choose CMEK or VPC Service Controls, not realizing that only Confidential VMs protect data during active computation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confidential VMs
Confidential VMs (D) are the correct choice because they provide hardware-based memory encryption using AMD Secure Encrypted Virtualization (SEV), ensuring that data remains encrypted while in use (during inference). This meets the requirement that the model's predictions cannot be inspected by any third party, including Google Cloud operators, and that data stays encrypted at all times.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-Managed Encryption Keys (CMEK)
Why it's wrong here
CMEK encrypts data at rest with keys the customer controls, but decryption still occurs in memory during inference, so plaintext is exposed to the processing environment. It is tempting because CMEK is the standard control for key ownership over stored data, but it does not keep data encrypted while a model computes on it.
- ✗
Access Transparency logs
Why it's wrong here
Access Transparency logs record when Google personnel access customer data, providing an audit trail rather than preventing inspection or keeping data encrypted during inference. It is tempting because it addresses third-party visibility, but it is a detective logging control, not a preventive cryptographic one.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls builds a perimeter that blocks data exfiltration across project boundaries, yet it does not encrypt data during inference or hide predictions from the service operator. It is tempting because it is the go-to control for restricting access to sensitive Google Cloud resources, but it governs network reachability, not in-use encryption.
- ✓
Confidential VMs
Why this is correct
Confidential VMs encrypt memory with hardware-based keys while data is in use, so transaction data and model predictions stay inaccessible to Google or any third party during inference. This satisfies the requirement for always-encrypted data and non-inspectable predictions.
Go deeper
Related to this question
About these practice questions
One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.