Generative AI Leader Google Cloud's Generative AI Offerings Practice Question
Which THREE steps are required to secure a generative AI pipeline that uses Vertex AI and involves sensitive customer data?
⚠ Common exam trap
Many exam-takers confuse API key authentication (Option C) as a valid security measure, but for sensitive data, API keys lack identity binding and are considered a weak secret, whereas VPC Service Controls and IAM provide defense-in-depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use VPC Service Controls to create a perimeter around Vertex AI resources
Option A is correct because VPC Service Controls lets you define a service perimeter around Vertex AI resources, preventing data exfiltration of sensitive customer data even if credentials are compromised. Option B is correct because applying IAM roles with least privilege and using dedicated service accounts for the pipeline enforces fine-grained access control and limits the blast radius of any compromised identity. Option D is correct because enabling data encryption at rest with Cloud KMS (customer-managed encryption keys) protects sensitive customer data stored in Vertex AI datasets, models, and related storage from unauthorized access at the storage layer. Option C is incorrect because exposing the prediction endpoint publicly with only an API key removes network-level protections and is not a recommended security control for sensitive data. Option E is incorrect because disabling audit logging reduces visibility and accountability, which weakens security and compliance rather than strengthening them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use VPC Service Controls to create a perimeter around Vertex AI resources
Why this is correct
VPC Service Controls establish a service perimeter that blocks data exfiltration from Vertex AI endpoints, directly satisfying the requirement to protect sensitive customer data during pipeline operations. This network-level containment prevents unauthorised projects or identities from reaching the model and its training data, even if IAM permissions are misconfigured.
- ✓
Apply IAM roles with least privilege and use service accounts for the pipeline
Why this is correct
Least-privilege IAM roles and dedicated service accounts constrain each pipeline component to only the Vertex AI and data resources it needs, satisfying the sensitive-customer-data requirement by preventing over-broad access or credential reuse across training, tuning and serving stages.
- ✗
Expose the prediction endpoint publicly with an API key
Why it's wrong here
A public endpoint guarded only by an API key exposes the model to unauthenticated abuse and key leakage; Vertex AI requires IAM authentication and private networking for sensitive data. API keys suit low-risk public APIs, not regulated customer data pipelines needing identity-based access control.
- ✓
Enable data encryption at rest using Cloud KMS
Why this is correct
Cloud KMS encryption at rest protects sensitive customer data stored in Vertex AI datasets, models and pipelines, satisfying the requirement to secure data throughout the generative AI pipeline. It addresses the storage-layer constraint where regulated data must remain encrypted.
- ✗
Disable audit logging to reduce data exposure
Why it's wrong here
Disabling audit logging removes the Cloud Audit Logs records needed to detect and investigate access to sensitive customer data, directly weakening the pipeline's security posture. It is tempting as a perceived way to limit exposure, but audit logging is the correct control when compliance and forensic traceability are required.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.