Courseiva
hardMultiple Select

Generative AI Leader Practice Question: A multinational corporation deploys a generative…

A multinational corporation deploys a generative AI chatbot across multiple regions. They need to comply with GDPR and local data residency requirements. Which THREE actions are necessary?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store and process data only in approved geographic regions (data residency controls)

Option C is correct because GDPR and local data residency laws require that personal data be stored and processed only within approved jurisdictions, so implementing geographic data residency controls (e.g., region-pinned storage and compute) is necessary to prevent cross-border transfers. Option D is correct because GDPR accountability and data minimization principles require tracking what personal data the chatbot processes and retaining it only as long as necessary, which is achieved through prompt/response logging with configurable retention and deletion policies. Option E is correct because GDPR Article 32 mandates appropriate technical measures including encryption of personal data at rest and in transit, and using customer-managed encryption keys (CMEK) gives the organization control over key lifecycle and revocation to meet stricter local requirements. Option A is not universally required because GDPR consent is only one of several lawful bases (e.g., contract, legitimate interest) and is not needed for every data collection. Option B is not necessary because anonymization is not required for all training data; pseudonymization or other safeguards may suffice, and fully anonymized data falls outside GDPR scope but is not a blanket obligation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Obtain explicit consent from every user before collecting any data

    Why it's wrong here

    GDPR permits several lawful bases, so blanket explicit consent for all data collection is not mandatory and would not by itself satisfy data residency. It is tempting because consent is the most familiar GDPR mechanism, but the stem's residency requirement demands regional storage and processing controls instead.

  • ✗

    Anonymize all training data before fine-tuning

    Why it's wrong here

    Anonymising training data reduces personal-data risk but does not govern where inference requests, prompts or outputs are stored and processed, so it cannot satisfy data residency. It is tempting because anonymisation is a recognised GDPR safeguard, yet residency requires regional deployment and routing controls.

  • ✓

    Store and process data only in approved geographic regions (data residency controls)

    Why this is correct

    Approved geographic regions satisfy data residency by pinning storage and processing to specific locations, preventing cross-border transfers that would breach GDPR or local mandates. Microsoft Entra ID and regional deployments let you enforce these boundaries, so personal data never leaves the jurisdiction the stem requires.

  • ✓

    Implement prompt and response logging with configurable retention policies

    Why this is correct

    Configurable retention policies satisfy GDPR storage-limitation and data-minimisation duties by ensuring prompt and response logs are deleted once their purpose lapses. Logging itself supports auditability and incident investigation, while per-region retention settings let the corporation align each deployment with local data residency rules.

  • ✓

    Encrypt personal data at rest and in transit using customer-managed encryption keys (CMEK)

    Why this is correct

    CMEK encryption at rest and in transit protects personal data against unauthorised access while giving the corporation control over key lifecycle. This satisfies GDPR security obligations and supports residency by keeping keys within approved regions.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.