Using the Generative AI Security Scoping Matrix, a company identifies four solution scopes. Which scope gives the company the greatest responsibility for security?
Choose an answer
Tap an option to check your answer.
Correct answer: Designing and training a generative AI model from scratch using customer-owned data..
Why this is the answer
Designing and training a generative AI model from scratch using customer-owned data places the greatest security responsibility on the company. This approach requires the company to manage all aspects of the model lifecycle, including data security, model integrity, infrastructure security, and compliance, without relying on a third party for any core generative AI component. Building an application that relies on a third-party generative AI foundation model (FM) involves shared responsibility, where the third party secures the FM itself, but the company is responsible for the application layer. Fine-tuning an existing third-party generative AI FM with the company’s specific data also involves shared responsibility, with the third party securing the base FM and the company responsible for the fine-tuning data and its security. Using a third-party enterprise application with built-in generative AI features delegates most security responsibilities to the third-party vendor, as the company primarily consumes a pre-built service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed