Courseiva
Trustworthy AI →hardMultiple Select

NCA-GENL Trustworthy AI Practice Question

An enterprise is deploying an NVIDIA NIM-hosted LLM for internal knowledge management. The security team wants to harden the deployment against prompt injection and jailbreak attempts before go-live. Which two measures should be implemented? (Choose two.)

⚠ Common exam trap

The trap here is treating randomness or log suppression as security controls, when effective defense combines input filtering with disciplined prompt structure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy NeMo Guardrails with input rails that detect and block known jailbreak patterns and instruction-override attempts.

Defending against prompt injection and jailbreaks requires both a runtime detection layer and sound prompt construction. NeMo Guardrails input rails catch known malicious patterns before generation, while strict separation of system instructions from user content prevents injected text from being interpreted as authoritative. The remaining options either weaken security posture, harm reliability, or remove the observability needed to improve defenses over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the model temperature to make outputs less predictable to attackers.

    Why it's wrong here

    Higher temperature increases randomness, which degrades response quality and consistency without providing any real security benefit. Attackers can still craft prompts that succeed under stochastic decoding. This option confuses unpredictability with robustness and would harm the reliability of an internal knowledge management assistant while leaving injection defenses unchanged.

  • ✓

    Deploy NeMo Guardrails with input rails that detect and block known jailbreak patterns and instruction-override attempts.

    Why this is correct

    Input rails evaluate user prompts before they reach the model and can block or rewrite attempts to override system instructions. This directly mitigates prompt injection and jailbreak patterns at the earliest point in the pipeline, reducing the chance that malicious instructions influence generation. It is a core defensive layer for hardening an LLM deployment against adversarial prompting.

  • ✗

    Disable logging of prompts and responses to reduce the attack surface of the logging system.

    Why it's wrong here

    Removing logs eliminates the audit trail needed to detect, investigate, and tune defenses against injection attempts. It reduces observability rather than attack surface in a meaningful way, and it undermines incident response. Security hardening for LLMs depends on visibility into adversarial prompts, so suppressing logs works against the stated goal.

  • ✗

    Store API keys in the client-side application to simplify authentication for internal users.

    Why it's wrong here

    Embedding API keys in client-side code exposes them to extraction and abuse, creating a serious security vulnerability unrelated to prompt injection defense. This practice weakens the overall deployment posture and could allow unauthorized access to the model endpoint. It does nothing to detect or block jailbreak attempts and should be avoided in any enterprise deployment.

  • ✓

    Enforce strict separation between system instructions and user-supplied content in the prompt template.

    Why this is correct

    Keeping trusted system instructions clearly delimited from untrusted user content reduces the model's tendency to treat user text as authoritative directives. It is a foundational prompt-engineering control that complements runtime guardrails. Without this separation, injected instructions can blend with system context and bypass intended behavior, so it is a necessary hardening measure.

About these practice questions

Courseiva writes every NCA-GENL question from scratch — 367 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCA-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCA-GENL exam.