Courseiva

NCP-GENL Safety, Ethics, and Compliance Practice Question

A multinational insurer deploys an NVIDIA NIM-based claims triage assistant across the EU and Brazil. The compliance team must demonstrate that the system honors data-subject deletion requests and that personal data is not transferred outside approved regions. Which design decision addresses both obligations most directly?

⚠ Common exam trap

The trap here is assuming that encrypting personal data or anonymizing it early removes the need to keep it in-region and to delete it on request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy regional NIM endpoints and per-region data stores so personal data stays in its jurisdiction, and implement deletion by cascading erasure across the prompt logs, vector index, and cached responses for that subject.

Residency is a placement problem and erasure is a propagation problem, so the design must solve both: region-local NIM endpoints and stores for placement, and cascading deletion across logs, indexes, and caches for propagation. Centralized logging, global replication of encrypted data, and edge anonymization each fail at least one obligation, and none of them produces a defensible deletion trail. Regional architecture with explicit erasure workflows is what an auditor can verify.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anonymize prompts before inference and retain only aggregate statistics, discarding the original records immediately.

    Why it's wrong here

    Aggressive anonymization at the edge reduces data volume but conflicts with the insurer's need to audit individual claim decisions and respond to subject access requests, since the linkage to the individual is destroyed. It also does not by itself guarantee that the inference endpoint is in the correct region. The scenario asks for a design meeting both residency and erasure obligations, and discarding records satisfies neither cleanly.

  • ✓

    Deploy regional NIM endpoints and per-region data stores so personal data stays in its jurisdiction, and implement deletion by cascading erasure across the prompt logs, vector index, and cached responses for that subject.

    Why this is correct

    Regional endpoints and region-scoped data stores keep personal data within its approved jurisdiction, satisfying the transfer restriction by construction. Cascading deletion across every derived store, including prompt logs, retrieval indexes, and caches, is what makes a data-subject erasure request actually complete, since copies in secondary stores are a common audit finding. Together these two design choices map one-to-one onto the two stated obligations.

  • ✗

    Encrypt all personal data with a single key managed by the home-region security team and replicate the encrypted stores globally for resilience.

    Why it's wrong here

    Encryption protects confidentiality but does not change where data is stored or processed, so global replication still constitutes a cross-border transfer under most regimes. A single home-region key also concentrates control in one jurisdiction, which regulators may view as ineffective local governance. Erasure obligations remain unaddressed because encrypted replicas still contain the subject's data until deleted.

  • ✗

    Store all prompts and completions in a single centralized log bucket in the insurer's home region for simplified auditing.

    Why it's wrong here

    Centralizing logs in one region is precisely the cross-border transfer the compliance team must avoid, and it makes regional deletion requests harder to honor because data from multiple jurisdictions is commingled. A single bucket is operationally convenient but directly conflicts with the residency obligation. Auditability does not require geographic centralization; it requires consistent retention and access controls wherever the data legitimately resides.

About these practice questions

This NCP-GENL question is part of Courseiva's 352-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCP-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-GENL exam.