Courseiva
Trustworthy AI →mediumMultiple Select

NCA-GENL Trustworthy AI Practice Question

An enterprise is preparing an LLM-based document assistant for internal use and must demonstrate accountability for Trustworthy AI to its auditors. Which two practices most directly provide verifiable accountability for the assistant's behavior? (Choose two.)

⚠ Common exam trap

The trap here is equating transparency artifacts like published prompts or satisfaction dashboards with accountability, which actually requires traceable records and enforced ownership.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Maintain an immutable audit log that records prompts, retrieved sources, model versions, and generated responses for each interaction.

Verifiable accountability rests on two complementary pillars: a durable record of what the system did, and a governed process that assigns responsibility for what it is allowed to do. Immutable logging supplies the evidentiary trail, while documented roles and approval gates supply the human ownership and change control. Together they let auditors reconstruct decisions and confirm that modifications were reviewed by accountable parties before reaching users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Publish the assistant's system prompt on the company intranet so employees understand how the model is instructed to behave.

    Why it's wrong here

    Transparency about instructions is useful for users, but publishing a prompt does not create accountability for outcomes. It records intent, not behavior, and it does not link any specific response to a reviewable event or responsible owner. Auditors need evidence of what the system actually did and who approved it, which a static prompt disclosure cannot provide on its own.

  • ✓

    Maintain an immutable audit log that records prompts, retrieved sources, model versions, and generated responses for each interaction.

    Why this is correct

    An immutable log linking each response to its prompt, retrieved context, and model version creates a verifiable record that auditors can reconstruct. It enables root-cause analysis and demonstrates that the organization can explain what the system did and why. This is a foundational accountability control because it makes system behavior reviewable after the fact rather than relying on undocumented claims about how the assistant operates.

  • ✗

    Collect user satisfaction ratings after each interaction and display the rolling average on a dashboard for leadership.

    Why it's wrong here

    Satisfaction ratings measure perceived usefulness, not accountability. They do not record model versions, retrieved evidence, or change approvals, and they can be gamed or skewed by unrepresentative users. A dashboard of averages provides no traceable link between a specific decision and a responsible party, so it fails the verifiability standard auditors apply.

  • ✓

    Define documented model risk roles and approval gates so that changes to prompts, models, or data sources require review before deployment.

    Why this is correct

    Documented roles and approval gates assign human ownership and require review before changes take effect, which is the essence of accountability. Auditors can trace who approved a change, what was evaluated, and when it went live. This governance structure ensures that responsibility is not diffuse and that risky modifications are deliberate rather than ad hoc, complementing technical logging with organizational control.

  • ✗

    Run a one-time red teaming exercise before launch and archive the final report in the project repository.

    Why it's wrong here

    A pre-launch red teaming exercise is valuable for finding weaknesses, but a single archived report becomes stale as models, prompts, and data change. It does not provide ongoing traceability of individual interactions or enforce review of future changes. Accountability requires continuous evidence and control, not a snapshot vulnerability assessment filed once at the start of the project.

About these practice questions

This NCA-GENL question is part of Courseiva's 367-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCA-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCA-GENL exam.