GCP Professional Cloud Security Engineer Practice Question

Your team is releasing a customer-facing chat assistant that uses Vertex AI's generative text model. To answer questions the application sometimes includes internal documents in the system prompt. Security testing shows that a skilled user can craft prompts that make the model echo confidential data from those documents. Which Google Cloud control most directly reduces this adversarial prompt-injection risk without changing the model weights or retraining?

  • Place the Vertex AI endpoint inside a VPC Service Controls service perimeter.

  • Encrypt all training data with customer-managed encryption keys (CMEK) before fine-tuning the model.

  • Call Sensitive Data Protection to inspect and redact the model's response before it is sent back to the user.

  • Enable CMEK on the Vertex AI model to ensure its checkpoints are stored with customer-managed keys.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot