Courseiva

NCP-GENL Safety, Ethics, and Compliance Practice Question

A retail company wants to let its customer-support LLM answer questions about order status. The security team insists the model must never be able to invoke a refund or account-modification function, even if a user crafts a clever prompt. Which approach enforces that constraint most reliably?

⚠ Common exam trap

The trap here is treating a strong system prompt or refusal fine-tune as a security boundary when the sensitive function remains callable in the execution layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Expose only a read-only order-status tool to the model and keep refund and account-modification functions outside the tool registry entirely.

Authorization in tool-using LLM applications must be enforced by what the model can reach, not by what it is told. Keeping refund and account-modification functions out of the tool registry makes them structurally unreachable, so no prompt-injection technique can trigger them. Read-only status access still works. Prompts, fine-tuning, and post-hoc alerting all leave a live execution path that an adversary could exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a system prompt instructing the model to refuse any request that would modify an account or issue a refund.

    Why it's wrong here

    System prompts are soft constraints that can be overridden by sufficiently creative user input, including indirect phrasing or role-play framing. Relying on instruction-following alone places the entire security boundary inside the model's judgment, which is exactly what the security team wants to avoid. Prompt-level refusal is useful for tone and policy but is not a reliable authorization mechanism.

  • ✓

    Expose only a read-only order-status tool to the model and keep refund and account-modification functions outside the tool registry entirely.

    Why this is correct

    If the sensitive functions are never registered as callable tools, no prompt can invoke them, because the model's action space is defined by the registry rather than by its instructions. This is an architectural control that holds even against adversarial input. Read-only status queries remain fully supported, so the customer experience is preserved while the constraint is enforced at the system boundary.

  • ✗

    Log every tool invocation and alert the security team whenever a refund or account-modification call is detected.

    Why it's wrong here

    Detection after the fact does not prevent the unauthorized action; the refund has already been issued by the time an alert fires. Logging is a valuable audit and incident-response control, but the requirement is that the model must never be able to perform the action. Monitoring complements prevention rather than substituting for it.

  • ✗

    Fine-tune the model on examples of refund and account-modification refusals so it learns to decline those requests.

    Why it's wrong here

    Fine-tuning shifts behavior probabilistically but provides no guarantee, and adversarial prompts routinely elicit behavior that safety tuning was meant to suppress. A model that has seen refund tooling during training may still emit plausible calls. More importantly, if the function remains reachable in the execution layer, a single successful jailbreak produces a real transaction, so the control must live outside the model.

About these practice questions

This NCP-GENL question is part of Courseiva's 352-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official NVIDIA exam blueprint

This NCP-GENL practice question is part of Courseiva's free NVIDIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NCP-GENL exam.