Courseiva
hardMultiple Choice

Generative AI Leader Practice Question: A global retailer uses a generative AI model to…

A global retailer uses a generative AI model to personalize product recommendations. They need to ensure that customer prompts and responses are not logged for model improvement to meet GDPR data minimization principles. Which configuration should they apply?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable prompt/response logging in Vertex AI endpoint settings

To comply with GDPR data minimization, the retailer should disable prompt/response logging. Vertex AI offers settings to control whether prompts and responses are stored for model improvement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a third-party logging service with data deletion policies

    Why it's wrong here

    A third-party logging service still records prompts and responses, so data is logged for improvement regardless of the vendor's deletion policy. Outsourcing is tempting because it shifts retention controls to a specialist, and would be correct where logging is allowed and the concern is only deletion enforcement.

  • ✗

    Enable data logging for six months and then automatically delete

    Why it's wrong here

    Retaining prompts and responses for six months still logs them for model improvement, breaching the requirement that they not be logged at all. Time-limited retention is tempting because it limits exposure, and would be correct where logging is permitted but storage duration must be bounded by a retention schedule.

  • ✓

    Disable prompt/response logging in Vertex AI endpoint settings

    Why this is correct

    Disabling prompt and response logging at the Vertex AI endpoint prevents customer data being stored for model improvement, directly satisfying GDPR data minimisation by ensuring personal data in prompts is not retained beyond serving the request.

  • ✗

    Anonymize all customer data before logging

    Why it's wrong here

    Anonymisation still logs prompt and response content, merely stripped of identifiers, so data is retained for model improvement contrary to the no-logging requirement. It is tempting because anonymisation supports data minimisation generally, and would be correct where logging is permitted provided personal data is irreversibly removed.

About these practice questions

One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.