Courseiva

NCP-GENL Safety, Ethics, and Compliance Practice Question

A hospital network runs an on-premises NVIDIA NIM microservice hosting a clinical-summarization LLM. Compliance requires that every generated summary be attributable to source records and that no protected health information leave the subnet. Which deployment practice best satisfies both requirements at once?

⚠ Common exam trap

The trap here is treating output redaction or hashing as equivalent to preventing data egress, when the residency violation already occurs the moment the prompt is transmitted off-subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Keep inference inside the on-premises NIM endpoint and log retrieval-augmented-generation citations that map each summary sentence back to the source record IDs.

On-premises NVIDIA NIM inference keeps protected health information inside the controlled network boundary, and RAG citation logging provides the source-record traceability an auditor needs. Redaction, hashing, and de-identified fine-tuning each address only part of the problem and none of them stops live PHI from crossing the trust boundary. Only a local endpoint combined with grounded citations satisfies residency and attribution together.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fine-tune the clinical LLM on de-identified records, then deploy the tuned checkpoint to the public cloud region closest to the hospital.

    Why it's wrong here

    Fine-tuning on de-identified data addresses training-data hygiene, not the residency of live patient prompts at inference time. Deploying to any public cloud region still moves PHI outside the hospital subnet, which the compliance rule forbids. This option solves a different problem than the one the scenario states and leaves both attribution and egress unaddressed.

  • ✗

    Route prompts to a hosted public LLM API for higher quality, then hash the returned summaries before writing them to the clinical record.

    Why it's wrong here

    Hashing the output does not prevent the original PHI-bearing prompt from leaving the subnet, so the residency requirement is already violated at transmission time. A hash also destroys the link between summary text and source record, defeating attribution. Higher generation quality is irrelevant when the compliance constraint is explicit about no egress of protected health information.

  • ✗

    Enable NVIDIA NeMo Guardrails output rails to redact names and dates, and continue calling the external model endpoint from the clinical application.

    Why it's wrong here

    Output rails reduce but do not eliminate residual identifiability, and re-identification from clinical context is well documented. More fundamentally, redaction happens after the prompt has already been transmitted off-subnet, so the data-residency rule is breached regardless of how aggressive the rail is. Guardrails are a defense-in-depth layer, not a substitute for local inference.

  • ✓

    Keep inference inside the on-premises NIM endpoint and log retrieval-augmented-generation citations that map each summary sentence back to the source record IDs.

    Why this is correct

    Running the NIM microservice on-premises keeps PHI inside the controlled subnet, and citation-based RAG grounding ties every generated sentence to a retrievable source record, satisfying auditability and data-residency simultaneously. Because the retriever and the NIM endpoint are both local, no prompt or completion crosses the trust boundary, so the attributable-evidence trail never depends on an external service.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This NCP-GENL question is part of Courseiva's 352-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCP-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-GENL exam.