Courseiva

Generative AI Leader Practice Question: Techniques to Improve Generative AI Model Output

A software development team builds an internal code assistant using a generative model. The assistant writes Python functions that often contain security vulnerabilities such as SQL injection or command injection. The team wants to mitigate these vulnerabilities without adding a manual review step for every code snippet, as that would slow development. They have access to a static analysis security scanner API. Which approach best addresses the vulnerabilities while maintaining developer velocity?

⚠ Common exam trap

This exam often tests the misconception that a simple prompt or fine-tuning alone can guarantee safety, when in reality, a closed-loop validation with a dedicated security tool is required for reliable mitigation of injection vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

After each generation, automatically run the code through the static analysis scanner, and if vulnerabilities are found, send the output back to the model for revision with the scanner's feedback.

It creates an automated feedback loop: the static analysis scanner detects vulnerabilities in the generated code, and the model revises the output based on that feedback. This approach directly mitigates security flaws without requiring manual review, preserving developer velocity. It leverages the scanner's precise, rule-based detection to iteratively improve the model's output, which is more reliable than relying on the model's inherent safety.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase top-k sampling to generate a wider variety of code tokens.

    Why it's wrong here

    Raising top-k widens token sampling, increasing output diversity and the likelihood of insecure code rather than removing injection flaws. It is tempting because sampling parameters tune generation behaviour, and higher top-k is the correct choice when a model produces repetitive or overly narrow completions.

  • ✓

    After each generation, automatically run the code through the static analysis scanner, and if vulnerabilities are found, send the output back to the model for revision with the scanner's feedback.

    Why this is correct

    Feeding scanner findings back into the model creates an automated generate-scan-revise loop, so vulnerable patterns are corrected before the developer sees the snippet. This satisfies the no-manual-review constraint while preserving velocity, unlike prompt-only hardening, which cannot verify the emitted code.

  • ✗

    Fine-tune the model on a corpus of secure code examples.

    Why it's wrong here

    Fine-tuning shifts the model's output distribution toward secure patterns but cannot guarantee that generated code is free of injection flaws, since the model still samples probabilistically. It is tempting because fine-tuning is the standard way to specialise a model's style or domain, and would suit teams wanting consistent secure coding conventions rather than deterministic vulnerability detection.

  • ✗

    Add a system prompt: 'Do not generate code with security vulnerabilities.'

    Why it's wrong here

    A system prompt is probabilistic guidance the model can ignore, so it cannot reliably prevent SQL or command injection patterns. It is tempting because prompt instructions are the cheapest control to add, and would suffice for stylistic constraints such as output formatting rather than security guarantees.

About these practice questions

This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.