Generative AI Leader Practice Question: Business Strategies for Generative AI Solutions
A financial services firm wants to deploy a generative AI assistant that summarizes analyst research for internal advisors. The security team requires that the assistant never expose confidential client data in its responses, and the business wants to move quickly without building a custom model from scratch. Which approach best balances speed, control, and data protection on Google Cloud?
⚠ Common exam trap
The trap here is assuming that network perimeter controls or fine-tuning alone protect confidential data, when the real risk is sensitive content appearing in model context or generated responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a managed foundation model with grounding on an access-controlled document store and Sensitive Data Protection filters on inputs and outputs.
Combining a managed foundation model with grounded retrieval over an access-controlled store and Sensitive Data Protection filtering keeps confidential client data out of model weights and out of responses. Advisors receive summaries only from documents they are authorized to view, and inspection adds detection and redaction for sensitive identifiers. This satisfies the security requirement while avoiding the cost and delay of training a custom model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fine-tune a foundation model on all historical analyst reports, including confidential client sections.
Why it's wrong here
Fine-tuning on confidential client data embeds sensitive content into model weights, creating a persistent leakage risk that cannot be easily scoped or revoked. It also requires substantial data preparation and training time, which conflicts with the goal of moving quickly. For advisors who only need summaries, this approach adds cost and governance burden while failing to guarantee that client data will never appear in generated output.
- ✗
Deploy an open-source model on a single Compute Engine VM and rely on network firewalls for data protection.
Why it's wrong here
Network firewalls control traffic to the VM but do nothing to prevent the model from reproducing confidential client data that appears in its context or training. Hosting an open-source model also shifts patching, scaling, and safety tuning onto the firm, slowing delivery. In this scenario, the requirement is about what the assistant says, not only who can reach the server, so firewall-only protection leaves the core risk unaddressed.
- ✗
Store all analyst reports in a public Cloud Storage bucket so the model can retrieve them without authentication.
Why it's wrong here
Making the corpus public removes authentication and authorization, directly violating the security team's requirement to protect confidential client data. Even if the model only summarizes, any user or service with the bucket URL could retrieve the source documents. This approach also undermines least-privilege access and would fail a financial services audit, so it cannot satisfy the balance of speed and data protection the firm needs.
- ✓
Use a managed foundation model with grounding on an access-controlled document store and Sensitive Data Protection filters on inputs and outputs.
Why this is correct
Grounding the assistant on an access-controlled corpus ensures it summarizes only documents the advisor is permitted to see, while Sensitive Data Protection inspection on prompts and responses adds a layer that can detect and redact confidential client identifiers. This uses managed models, so the firm avoids building from scratch, and it keeps sensitive data out of model weights, which supports both speed and the security team's non-exposure requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.