Courseiva
hardMultiple Choice

Generative AI Leader Practice Question: A financial services company needs to deploy an…

A financial services company needs to deploy an AI model that handles highly sensitive transaction data. They require that the model's predictions cannot be inspected by any third party, and the data must remain encrypted at all times, including during inference. Which Google Cloud feature should they use?

⚠ Common exam trap

Many candidates confuse encryption at rest/in transit with encryption in use, and mistakenly choose CMEK or VPC Service Controls, not realizing that only Confidential VMs protect data during active computation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Confidential VMs

Confidential VMs (D) are the correct choice because they provide hardware-based memory encryption using AMD Secure Encrypted Virtualization (SEV), ensuring that data remains encrypted while in use (during inference). This meets the requirement that the model's predictions cannot be inspected by any third party, including Google Cloud operators, and that data stays encrypted at all times.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Customer-Managed Encryption Keys (CMEK)

    Why it's wrong here

    CMEK encrypts data at rest with keys the customer controls, but decryption still occurs in memory during inference, so plaintext is exposed to the processing environment. It is tempting because CMEK is the standard control for key ownership over stored data, but it does not keep data encrypted while a model computes on it.

  • ✗

    Access Transparency logs

    Why it's wrong here

    Access Transparency logs record when Google personnel access customer data, providing an audit trail rather than preventing inspection or keeping data encrypted during inference. It is tempting because it addresses third-party visibility, but it is a detective logging control, not a preventive cryptographic one.

  • ✗

    VPC Service Controls

    Why it's wrong here

    VPC Service Controls builds a perimeter that blocks data exfiltration across project boundaries, yet it does not encrypt data during inference or hide predictions from the service operator. It is tempting because it is the go-to control for restricting access to sensitive Google Cloud resources, but it governs network reachability, not in-use encryption.

  • ✓

    Confidential VMs

    Why this is correct

    Confidential VMs encrypt memory with hardware-based keys while data is in use, so transaction data and model predictions stay inaccessible to Google or any third party during inference. This satisfies the requirement for always-encrypted data and non-inspectable predictions.

About these practice questions

One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.