hardMultiple Select
Generative AI Leader Practice Question: A multinational corporation is deploying a…
A multinational corporation is deploying a generative AI chatbot for customer support across Europe, Asia, and North America. The legal team requires compliance with GDPR for EU users, data residency controls, and the ability to audit prompts and responses for safety. Which THREE actions should the company take?
⚠ Common exam trap
A common misconception is that GDPR compliance can be achieved by simply disabling logging or centralizing data, when in fact the regulation requires a combination of data residency, consent-based logging, and content safety controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Vertex AI with data residency controls to keep EU data within the EU.
Option B is correct because Vertex AI supports data residency and regional endpoints, allowing EU user data to be processed and stored within the EU to satisfy GDPR data residency requirements. Option D is correct because Vertex AI content safety filters help block harmful or policy-violating content, supporting the legal team's requirement to audit and enforce safety. Option E is correct because enabling prompt and response logging with user consent provides the audit trail needed for safety review while respecting GDPR consent and transparency obligations. Option A is incorrect because centralizing all user data in a US data center violates EU data residency and GDPR transfer requirements. Option C is incorrect because disabling logging for EU users would prevent the required auditing of prompts and responses and does not by itself resolve GDPR compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store all user data in a central US data center for consistency.
Why it's wrong here
Centralising all user data in the US breaches GDPR transfer rules and the stated data residency controls, since EU personal data would leave its region. Regional storage is chosen when residency obligations apply; here it directly contradicts the legal team's requirement.
- ✓
Use Vertex AI with data residency controls to keep EU data within the EU.
Why this is correct
Vertex AI's data residency controls pin storage and processing of EU prompts and responses to an in-region location, directly satisfying the GDPR-driven residency constraint. This keeps EU customer data within EU boundaries during inference and logging, supporting the audit requirement without exporting regulated data to other regions.
- ✗
Disable all logging for EU users to avoid GDPR complications.
Why it's wrong here
Disabling logging removes the audit trail the legal team explicitly requires for prompts and responses, and GDPR permits lawful processing with safeguards rather than mandating deletion of logs. Logging with retention limits and access controls is the compliant approach, not blanket disablement.
- ✓
Apply content safety filters via Vertex AI to block harmful content.
Why this is correct
Vertex AI content safety filters intercept harmful prompts and responses at inference time, satisfying the audit and safety requirement. However, filters alone do not address GDPR compliance or data residency, so this action must be combined with the other two selections. It directly supports the safety auditing constraint named in the stem.
- ✓
Enable prompt and response logging with user consent for all regions.
Why this is correct
Prompt and response logging with user consent directly satisfies the audit requirement, capturing interactions for safety review. Consent aligns with GDPR's lawful-basis obligations for processing EU users' data, and applying it across all regions maintains a consistent audit trail. This addresses the stem's explicit demand to audit prompts and responses.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.