Courseiva

Generative AI Leader Google Cloud's Generative AI Offerings Practice Question

A global bank wants to use Gemini models in Vertex AI to summarize sensitive customer emails. The security team requires that prompts and responses never leave the bank's controlled network perimeter and that access is restricted to approved projects. Which Google Cloud capability should they configure?

⚠ Common exam trap

The trap here is assuming that private connectivity or edge security services such as Cloud Interconnect or Cloud Armor prevent data exfiltration from managed AI APIs, when perimeter controls are what actually enforce service boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Service Controls

VPC Service Controls let organizations define a service perimeter around Google Cloud services, including Vertex AI. Resources inside the perimeter can communicate, but access from outside is blocked, which prevents data exfiltration. Combined with IAM policies limiting access to approved projects, this satisfies the bank's requirement that sensitive prompts and responses remain within a controlled boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPC Service Controls

    Why this is correct

    VPC Service Controls create a service perimeter that restricts access to Google Cloud services such as Vertex AI, preventing data exfiltration outside the defined boundary. By placing Vertex AI inside a perimeter with approved projects, the bank ensures prompts and responses cannot leave the controlled network, meeting the security team's requirement.

  • ✗

    Cloud Armor

    Why it's wrong here

    Cloud Armor protects applications from web attacks such as DDoS and SQL injection at the edge. It does not govern API-level access to Vertex AI or enforce data residency boundaries. The bank's concern is data exfiltration and project-level access, which Cloud Armor does not address.

  • ✗

    Cloud CDN

    Why it's wrong here

    Cloud CDN caches content close to users to reduce latency for web applications. It does not enforce data boundaries for API calls to Vertex AI or prevent data exfiltration. Using Cloud CDN would not address the requirement that prompts and responses stay within the bank's controlled perimeter.

  • ✗

    Cloud Interconnect

    Why it's wrong here

    Cloud Interconnect provides private network connectivity between on-premises networks and Google Cloud. While it improves network performance and security for data transfer, it does not restrict which projects or services can access Vertex AI, nor does it prevent data from leaving the perimeter. It is not the control needed here.

About these practice questions

One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.