hardMultiple Choice
Generative AI Leader Practice Question: A research team is fine-tuning a large language…
A research team is fine-tuning a large language model on a dataset containing personal data of EU citizens. They must comply with GDPR. Which measure is ESSENTIAL?
⚠ Common exam trap
The Generative AI Leader exam often tests the distinction between legally required measures (like consent) versus best-practice technical controls (like Model Cards or safety filters), leading candidates to pick a technically sound but legally insufficient option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Obtain explicit consent from individuals for using their data in fine-tuning
Under GDPR, processing personal data requires a lawful basis; explicit consent is essential when no other basis (e.g., legitimate interest) clearly applies, especially for fine-tuning where data is used to train a model that may memorize and regenerate personal information. Without consent, the processing is unlawful, exposing the team to significant fines and regulatory action. This is a foundational requirement that overrides technical measures like storage location or documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the training data is stored in a specific geographic region
Why it's wrong here
Residency alone does not satisfy GDPR's lawful-basis, consent and erasure duties for training on personal data; storing data in one region still permits unlawful processing. It is tempting because data-residency controls are the standard answer for sovereignty requirements, and would be correct if the stem asked only where data must physically reside.
- ✓
Obtain explicit consent from individuals for using their data in fine-tuning
Why this is correct
Explicit consent supplies the lawful basis GDPR requires before processing personal data, satisfying the stem's compliance constraint. Because fine-tuning embeds that data into model weights, purpose limitation and transparency obligations attach directly to this processing, so consent must cover the fine-tuning purpose specifically. Technical safeguards alone cannot substitute for a lawful basis.
- ✗
Use a Model Card to document the training data
Why it's wrong here
A Model Card documents a model's intended use, limitations and evaluation results; it does not establish a lawful basis or honour data-subject rights, so it cannot make personal-data training GDPR-compliant. It is tempting because transparency documentation is genuinely required under GDPR, and would be correct if the question asked how to disclose model characteristics.
- ✗
Apply safety filters to the model outputs
Why it's wrong here
Output safety filters mitigate harmful or toxic generations; they do not address the lawfulness of processing EU citizens' personal data during fine-tuning, which is the GDPR obligation at issue. They are tempting because filtering is a common AI-governance control, and would be correct if the scenario concerned preventing unsafe model responses.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.