Generative AI Leader Practice Question: Business Strategies for Generative AI Solutions
A regional insurance company wants to launch a generative AI claims-triage assistant. The CISO requires that no claims data leave the company's existing Google Cloud project boundary and that every model call be attributable to a named employee for audit. Which combination of Google Cloud controls should the architecture team prioritize?
⚠ Common exam trap
The trap here is treating encryption keys or edge security as sufficient for data-boundary compliance, when only a service perimeter actually blocks exfiltration by authorized identities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Service Controls around the project plus Cloud Audit Logs capturing the authenticated principal on each Vertex AI request.
A service perimeter built with VPC Service Controls prevents claims data from being moved outside the approved project even by credentialed users, which is the strongest fit for the boundary mandate. Cloud Audit Logs then capture the authenticated principal behind every Vertex AI call, producing the employee-level attribution auditors demand. Encryption and edge protections are valuable but do not replace these two controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-managed encryption keys in Cloud KMS plus a service account shared by the entire claims department.
Why it's wrong here
Customer-managed keys strengthen encryption control but do not stop an authorized principal from copying data out of the project, so the boundary requirement remains open. A shared service account erases per-employee attribution, which directly contradicts the audit mandate. This pairing looks security-conscious yet fails both stated constraints.
- ✗
Cloud Armor policies on the public load balancer plus Security Command Center premium findings.
Why it's wrong here
Cloud Armor mitigates external attacks such as DDoS and web exploits, and Security Command Center surfaces misconfigurations and threats. Neither mechanism confines data to the project perimeter during legitimate model calls, and neither ties a specific Vertex AI invocation to a named employee, so the audit and boundary requirements stay unresolved.
- ✓
VPC Service Controls around the project plus Cloud Audit Logs capturing the authenticated principal on each Vertex AI request.
Why this is correct
VPC Service Controls create a service perimeter that blocks data exfiltration from the project even if credentials are misused, directly satisfying the boundary requirement. Cloud Audit Logs record the identity of the caller for Vertex AI API activity, giving auditors per-employee attribution. Together they address both the data-residency concern and the traceability requirement without extra infrastructure.
- ✗
Cloud CDN in front of the assistant plus Identity-Aware Proxy on the internal admin console.
Why it's wrong here
Cloud CDN accelerates static content delivery and Identity-Aware Proxy gates access to internal web apps; neither prevents claims data from leaving the project boundary nor records which employee invoked a model. These controls address performance and console access, leaving the CISO's core requirements about data exfiltration and per-call attribution unmet.
Go deeper
Related to this question
About these practice questions
Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.