Courseiva
Trustworthy AI →hardMultiple Choice

NCA-GENL Trustworthy AI Practice Question

An AI team is deploying an LLM-based coding assistant. They observe that the model sometimes generates insecure code snippets, such as hardcoded credentials or SQL injection vulnerabilities. To mitigate this without retraining the model, which approach aligns with NVIDIA's Trustworthy AI recommendations?

⚠ Common exam trap

The trap here is thinking that adjusting model parameters like temperature or context length can improve security, when what is needed is an external validation layer on the generated output.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a post-processing output rail that scans generated code for known vulnerability patterns and blocks or flags them.

A post-processing output rail is the most direct mitigation because it inspects the generated code before it reaches the user, using static analysis or pattern matching to catch vulnerabilities. It does not require retraining and can be updated as new vulnerability patterns emerge. The other options either increase risk, require retraining, or do not target the security of the output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restrict the model's context window to limit the amount of code it can generate, reducing the chance of vulnerabilities.

    Why it's wrong here

    Limiting the context window affects how much input the model can consider, not the security of its output. Insecure code can be generated in very short snippets. This approach does not address the root cause and may degrade the assistant's usefulness by truncating necessary context for complex coding tasks.

  • ✓

    Implement a post-processing output rail that scans generated code for known vulnerability patterns and blocks or flags them.

    Why this is correct

    A post-processing output rail can analyze the model's generated code against a rule set or static analysis tool to detect insecure patterns like hardcoded credentials or SQL injection. Blocking or flagging such outputs prevents the insecure code from reaching the developer, directly mitigating the risk without retraining the model.

  • ✗

    Fine-tune the model on a dataset of secure code snippets to teach it to avoid vulnerabilities.

    Why it's wrong here

    Fine-tuning could help in the long term, but the scenario explicitly asks for a mitigation without retraining the model. Fine-tuning is a form of retraining and requires significant compute and data curation. It also does not guarantee elimination of all insecure patterns, especially novel ones not present in the fine-tuning set.

  • ✗

    Increase the model's temperature to encourage more diverse code suggestions, reducing the chance of insecure patterns.

    Why it's wrong here

    Higher temperature increases randomness and creativity, which is more likely to produce insecure or nonsensical code rather than safer code. It does not systematically filter out vulnerabilities. The model's underlying knowledge of secure coding is unchanged, so this approach does not reliably mitigate the risk.

About these practice questions

Courseiva writes every NCA-GENL question from scratch — 367 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCA-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCA-GENL exam.