GCP Professional Cloud Architect Practice Question
Your company is launching a Vertex AI-based chat assistant that will be exposed publicly over HTTP. Security testing shows that attackers can coerce the underlying foundation model into revealing sensitive training data and producing extremist content. Compliance also requires that personal identifiers in both prompts and responses be redacted before they are stored for analytics. You need to design a control plane solution that mitigates these risks while adding the least possible runtime latency to online predictions. What should you do?
Enable Model Armor on the endpoint with both prompt and response policies in enforcement mode, and attach a Sensitive Data Protection rule set for PII redaction.
Place Cloud Armor in front of the endpoint with custom WAF rules and enable Sensitive Data Protection inspection on Cloud Armor.
Enable Model Armor only in monitoring mode and perform daily review of violation logs to update allow-lists.
Store all prompts and responses unmodified in BigQuery and run Cloud DLP jobs hourly to detect and redact sensitive data retroactively.
Model Armor runs inside the Vertex AI prediction service, so no additional network hop is added. By turning on both promptā and responseālevel policies in enforcement (block) mode, the service automatically detects prompt-injection attempts, disallowed content, and sensitive data. Attaching a Sensitive Data Protection (DLP) rule set to the same Model Armor policy allows PII to be redacted inline, satisfying compliance. Relying solely on Cloud Armor or an external proxy would require an extra network hop and cannot introspect the model's generated tokens. Using Cloud DLP after the response is stored violates the requirement to redact before persistence, and disabling enforcement turns Model Armor into monitoring-only, leaving the app unprotected.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Model Armor in Vertex AI?
Open an interactive chat with Bash
What does Sensitive Data Protection (DLP) in Model Armor do?
Open an interactive chat with Bash
Why is Model Armor preferred over Cloud Armor for Vertex AI security?
Open an interactive chat with Bash
What is Model Armor in Vertex AI?
Open an interactive chat with Bash
What is Sensitive Data Protection (DLP) in GCP, and how does it help with PII redaction?
Open an interactive chat with Bash
Why does using Cloud Armor instead of Model Armor add runtime latency to predictions?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .