Generative AI Leader Google Cloud's Generative AI Offerings Practice Question
A global bank wants to use Gemini models in Vertex AI to summarize sensitive customer emails. The security team requires that prompts and responses never leave the bank's controlled network perimeter and that access is restricted to approved projects. Which Google Cloud capability should they configure?
⚠ Common exam trap
The trap here is assuming that private connectivity or edge security services such as Cloud Interconnect or Cloud Armor prevent data exfiltration from managed AI APIs, when perimeter controls are what actually enforce service boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Service Controls
VPC Service Controls let organizations define a service perimeter around Google Cloud services, including Vertex AI. Resources inside the perimeter can communicate, but access from outside is blocked, which prevents data exfiltration. Combined with IAM policies limiting access to approved projects, this satisfies the bank's requirement that sensitive prompts and responses remain within a controlled boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPC Service Controls
Why this is correct
VPC Service Controls create a service perimeter that restricts access to Google Cloud services such as Vertex AI, preventing data exfiltration outside the defined boundary. By placing Vertex AI inside a perimeter with approved projects, the bank ensures prompts and responses cannot leave the controlled network, meeting the security team's requirement.
- ✗
Cloud Armor
Why it's wrong here
Cloud Armor protects applications from web attacks such as DDoS and SQL injection at the edge. It does not govern API-level access to Vertex AI or enforce data residency boundaries. The bank's concern is data exfiltration and project-level access, which Cloud Armor does not address.
- ✗
Cloud CDN
Why it's wrong here
Cloud CDN caches content close to users to reduce latency for web applications. It does not enforce data boundaries for API calls to Vertex AI or prevent data exfiltration. Using Cloud CDN would not address the requirement that prompts and responses stay within the bank's controlled perimeter.
- ✗
Cloud Interconnect
Why it's wrong here
Cloud Interconnect provides private network connectivity between on-premises networks and Google Cloud. While it improves network performance and security for data transfer, it does not restrict which projects or services can access Vertex AI, nor does it prevent data from leaving the perimeter. It is not the control needed here.
Go deeper
Related to this question
About these practice questions
One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.