Courseiva

Generative AI Leader Google Cloud's Generative AI Offerings Practice Question

Which THREE steps are required to secure a generative AI pipeline that uses Vertex AI and involves sensitive customer data?

⚠ Common exam trap

Many exam-takers confuse API key authentication (Option C) as a valid security measure, but for sensitive data, API keys lack identity binding and are considered a weak secret, whereas VPC Service Controls and IAM provide defense-in-depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use VPC Service Controls to create a perimeter around Vertex AI resources

Option A is correct because VPC Service Controls lets you define a service perimeter around Vertex AI resources, preventing data exfiltration of sensitive customer data even if credentials are compromised. Option B is correct because applying IAM roles with least privilege and using dedicated service accounts for the pipeline enforces fine-grained access control and limits the blast radius of any compromised identity. Option D is correct because enabling data encryption at rest with Cloud KMS (customer-managed encryption keys) protects sensitive customer data stored in Vertex AI datasets, models, and related storage from unauthorized access at the storage layer. Option C is incorrect because exposing the prediction endpoint publicly with only an API key removes network-level protections and is not a recommended security control for sensitive data. Option E is incorrect because disabling audit logging reduces visibility and accountability, which weakens security and compliance rather than strengthening them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use VPC Service Controls to create a perimeter around Vertex AI resources

    Why this is correct

    VPC Service Controls establish a service perimeter that blocks data exfiltration from Vertex AI endpoints, directly satisfying the requirement to protect sensitive customer data during pipeline operations. This network-level containment prevents unauthorised projects or identities from reaching the model and its training data, even if IAM permissions are misconfigured.

  • ✓

    Apply IAM roles with least privilege and use service accounts for the pipeline

    Why this is correct

    Least-privilege IAM roles and dedicated service accounts constrain each pipeline component to only the Vertex AI and data resources it needs, satisfying the sensitive-customer-data requirement by preventing over-broad access or credential reuse across training, tuning and serving stages.

  • ✗

    Expose the prediction endpoint publicly with an API key

    Why it's wrong here

    A public endpoint guarded only by an API key exposes the model to unauthenticated abuse and key leakage; Vertex AI requires IAM authentication and private networking for sensitive data. API keys suit low-risk public APIs, not regulated customer data pipelines needing identity-based access control.

  • ✓

    Enable data encryption at rest using Cloud KMS

    Why this is correct

    Cloud KMS encryption at rest protects sensitive customer data stored in Vertex AI datasets, models and pipelines, satisfying the requirement to secure data throughout the generative AI pipeline. It addresses the storage-layer constraint where regulated data must remain encrypted.

  • ✗

    Disable audit logging to reduce data exposure

    Why it's wrong here

    Disabling audit logging removes the Cloud Audit Logs records needed to detect and investigate access to sensitive customer data, directly weakening the pipeline's security posture. It is tempting as a perceived way to limit exposure, but audit logging is the correct control when compliance and forensic traceability are required.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.