Generative AI Leader Google Cloud's Generative AI Offerings Practice Question
A healthcare organization is using Vertex AI to build a generative AI application that summarizes patient notes. They need to ensure that the model does not inadvertently generate or expose protected health information (PHI) in its outputs. Which Google Cloud feature should they implement to detect and redact sensitive data in the model's responses?
⚠ Common exam trap
Watch out — candidates often confuse access control or monitoring services with data inspection and redaction; only DLP is built to detect and redact sensitive data in text.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Data Loss Prevention (DLP) API
Cloud DLP API is designed to discover, classify, and protect sensitive data such as PHI. By integrating it into the output pipeline of the generative AI application, the healthcare organization can automatically detect and redact PHI from model responses, ensuring compliance and preventing data leaks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vertex AI Model Monitoring
Why it's wrong here
Vertex AI Model Monitoring tracks model performance and data drift over time, such as prediction accuracy and feature distributions. It does not inspect or redact sensitive information in text outputs. While it can alert on anomalies, it is not designed for PHI detection or redaction, so it does not meet the requirement.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls create a security perimeter around Google Cloud resources to prevent data exfiltration. They control network access but do not inspect the content of model outputs for sensitive data. They cannot redact PHI, so they are not the right tool for this scenario.
- ✗
Cloud Identity-Aware Proxy (IAP)
Why it's wrong here
IAP controls access to applications based on user identity and context. It ensures only authorized users can reach the application, but it does not analyze or redact the content of model responses. It is an access control layer, not a data inspection or redaction service.
- ✓
Cloud Data Loss Prevention (DLP) API
Why this is correct
Cloud DLP API can inspect text for sensitive data like PHI and redact or mask it before it is stored or displayed. By integrating DLP into the application's output pipeline, the organization can automatically detect and redact PHI from model responses, ensuring compliance with regulations like HIPAA. This is the appropriate service for data loss prevention and sensitive data redaction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.