Courseiva

Generative AI Leader Practice Question: Business Strategies for Generative AI Solutions

A startup is building a generative AI tool that helps users write code. They want to launch quickly but need to ensure the generated code is secure and does not introduce vulnerabilities. They have a small team of developers with some ML experience. The tool should be cloud-hosted. Which approach balances speed, security, and cost?

⚠ Common exam trap

The trap is assuming that a pre-trained model alone is secure, or that training from scratch yields better security — in reality, guardrails around a pre-trained model deliver the best speed/security/cost balance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a pre-trained code model (e.g., Codey) and add a security filtering layer

Using a pre-trained code model such as Codey provides immediate capability without the cost and time of training from scratch, while adding a security filtering layer (SAST-style scanning, output sanitization, policy checks) addresses the security requirement. This balances speed, security, and cost for a small team.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the tool without any security checks and rely on manual review

    Why it's wrong here

    Shipping without automated scanning lets vulnerable code reach users, and manual review cannot scale to generative output volume. It tempts because it maximises launch speed, and would suit a throwaway prototype where security is explicitly out of scope.

  • ✗

    Train a custom code generation model from scratch on a large dataset

    Why it's wrong here

    Training from scratch demands large labelled corpora, GPU budget and ML specialists the startup lacks, delaying launch. It tempts because bespoke training can embed domain-specific security rules, and would be right where proprietary codebases and ample resources justify it.

  • ✓

    Use a pre-trained code model (e.g., Codey) and add a security filtering layer

    Why this is correct

    A pre-trained code model removes the cost and delay of training from scratch, letting a small ML team launch quickly, while the added security filtering layer scans generated code for vulnerabilities. This satisfies the need to balance speed, security and cost.

  • ✗

    Use a smaller model and restrict outputs to only simple code patterns

    Why it's wrong here

    Restricting a small model to simple patterns limits functionality and does not guarantee secure code; vulnerabilities can appear in trivial snippets. This is tempting because smaller models cut cost and latency, but security requires validation layers such as scanning or filtering, not output restriction alone.

About these practice questions

This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.