Courseiva

Generative AI Leader Google Cloud's Generative AI Offerings Practice Question

A healthcare company wants to use generative AI to summarize patient notes while ensuring compliance with strict data privacy regulations. They plan to use Google Cloud's Vertex AI. Which two features should they implement to protect sensitive data? (Choose two.)

⚠ Common exam trap

The trap here is thinking that default Google encryption is sufficient, but for strict compliance, customer-managed keys and network perimeters are needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Service Controls

Customer-managed encryption keys (CMEK) and VPC Service Controls are both critical for protecting sensitive healthcare data in Vertex AI. CMEK gives the organization control over encryption keys, while VPC Service Controls prevent unauthorized data exfiltration. Together, they help meet regulatory requirements for data privacy and security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPC Service Controls

    Why this is correct

    VPC Service Controls create a security perimeter around Google Cloud services to prevent data exfiltration. For healthcare data, this ensures that Vertex AI resources cannot be accessed from outside the authorized network. It helps comply with regulations by restricting data movement and mitigating insider threats. Implementing VPC Service Controls is a recommended practice for sensitive workloads.

  • ✗

    Storing data in a public Cloud Storage bucket

    Why it's wrong here

    Storing patient data in a public Cloud Storage bucket makes it accessible to anyone on the internet, a severe privacy breach. Healthcare regulations like HIPAA require strict access controls. Data should be stored in private buckets with least privilege access. Public buckets are never appropriate for sensitive information and would fail compliance audits.

  • ✓

    Customer-managed encryption keys (CMEK)

    Why this is correct

    CMEK allows the healthcare company to manage their own encryption keys for data at rest in Vertex AI. This ensures that only authorized parties can decrypt the data, meeting stringent compliance requirements. By using CMEK, they retain control over key rotation and revocation, which is essential for protecting sensitive patient information. It adds a layer of security beyond default encryption.

  • ✗

    Disabling audit logging

    Why it's wrong here

    Disabling audit logs removes the ability to track access and changes to patient data, which is contrary to compliance requirements. Audit logs are essential for detecting and investigating security incidents. Healthcare regulations often mandate detailed logging. Therefore, disabling logging is not a protective measure and should never be done for sensitive data.

  • ✗

    Public IP addressing for Vertex AI endpoints

    Why it's wrong here

    Using public IP addresses for Vertex AI endpoints exposes them to the internet, increasing the risk of unauthorized access. For sensitive healthcare data, this is a security risk and likely violates compliance standards. Private endpoints or VPC peering should be used instead. Public IPs do not protect data and are not a recommended feature for privacy.

About these practice questions

This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.