Generative AI Leader Fundamentals of Generative AI Practice Question
A financial services firm is deploying a generative AI chatbot to answer employee questions about internal policies. The firm must ensure that the chatbot does not reveal sensitive information from other departments. Which technique should they implement?
⚠ Common exam trap
The trap here is thinking that fine-tuning or larger context windows can enforce security, when in fact access control must be applied at the retrieval layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use retrieval-augmented generation with document-level access controls.
Retrieval-augmented generation can be combined with access control lists so that the retrieval step only returns documents the requesting user is permitted to view. This ensures the model's context is limited to authorized information, preventing leakage across departments. Fine-tuning or context expansion without access controls would not solve the security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fine-tune the model on all internal documents to improve accuracy.
Why it's wrong here
Fine-tuning on all documents would embed sensitive information into the model weights, making it accessible to any user who can query the model. This increases the risk of data leakage across departments. The goal is to restrict access, not to broaden the model's knowledge. Fine-tuning is not a security control.
- ✗
Set the temperature to a low value to reduce creative responses.
Why it's wrong here
Lowering temperature makes outputs more deterministic but does not prevent the model from repeating sensitive information it has learned or retrieved. It is a generation parameter, not a security mechanism. The risk is unauthorized data exposure, which requires access controls, not sampling adjustments.
- ✗
Increase the model's context window to include more documents.
Why it's wrong here
A larger context window allows more text to be processed but does not enforce access restrictions. If all documents are included, the model could still reveal sensitive information. The issue is authorization, not capacity. Expanding context without access control would worsen the problem.
- ✓
Use retrieval-augmented generation with document-level access controls.
Why this is correct
RAG can retrieve documents from a source that enforces access permissions based on the user's identity. By integrating with an identity-aware search or filtering retrieved documents by department, the chatbot only supplies context the user is authorized to see. This prevents cross-department information leakage while still providing accurate answers.
Visual reference
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.