Skip to main content
Your progress
0 of 5 lessons complete0%
T3 / M3.10 / Architect TIER / ~10 min

AI Gateway governance: module quiz

M3.10 module quiz

Ten questions. 80% to pass (8 of 10). Open book, unlimited retakes.

Answers are collapsed under each question. Answer first, then check.


Q1

Does ZopNight store customer LLM prompts?

A. Only for failed requests, so that a bad call can be replayed and diagnosed
B. Yes, in the per-request log alongside cost and latency
C. No; it is not in the content path and does no prompt logging or content inspection
D. Only when the complexity router is enabled for that key

Show answer

Correct: C. The per-request log carries key, model, team, cost, latency and outcome. The metadata-versus-content distinction is the whole answer.

Q2

The AI Gateway’s surfaces are:

A. Folded into Cost Reports, Settings Integrations, Developer Settings and the Budgets page
B. On a dedicated AI Gateway page carrying its own top-level navigation entry in the sidebar
C. In the internal admin console, not on the customer surface
D. Available only through the API, with no UI surface at all

Show answer

Correct: A. A dedicated page would create a second place to look for things that already have homes. The /ai-gateway/* routes that exist are fenced behind a playground flag.

Q3

Connecting a provider verifies the credential against the vendor because:

A. It discovers which models the credential can reach and registers each of them automatically
B. The vendor requires registration before a key may be used against their endpoint
C. A revoked or mistyped key would otherwise turn the tile green and fail on the customer’s first inference
D. It mints the STS credentials the gateway needs for the connected AWS account

Show answer

Correct: C. Re-verified on every credential update. The same discipline as cloud-account connection: a successful connect is itself the proof.

Q4

On a shared LiteLLM fleet, tenant isolation is enforced by:

A. The org stamp on the deployment, checked on every request
B. Each key’s model allow-list, which decides the deployment
C. Team-scoped deployments, invisible outside the owning team
D. Team-scoped deployments

Show answer

Correct: A. The allow-list was measured insufficient: a restricted key had 5 of 14 requests served by another org’s vendor credential, because two deployments under one model name form a load-balancing pool.

Q5

Enabling AWS Bedrock models requires:

A. A separate Bedrock API key, held per organisation and rotated
B. No additional credential; STS is minted from the connected AWS account
C. A per-org LiteLLM fleet with isolated credentials
D. An OpenRouter proxy credential, minted at connect

Show answer

Correct: B. For a security reviewer this is frequently the fastest approval in the module, because enabling a capability without a new standing credential is a materially smaller ask.

Q6

Virtual keys are org-visible rather than personal because:

A. AI spend is a shared budget, so ownership never matters
B. RBAC cannot express per-creator ownership on a key entity
C. A key is a budget-bounded consumption artifact attached to a team’s application
D. The gateway cannot associate a virtual key with any single named user

Show answer

Correct: C. When its creator leaves, the application keeps running and somebody must be able to rotate it. Attribution is preserved by a creator stamp that survives rotation.

Q7

Setting an org ceiling on an org with pre-existing keys:

A. Bounds all existing keys immediately at request time
B. Leaves pre-existing keys spending uncapped until a backfill sweep completes
C. Applies only to keys created afterwards, permanently
D. Revokes every existing key immediately and forces all of them to be re-issued under it

Show answer

Correct: B. The sweep logs it, so the ceiling should be verified as effective rather than assumed. The failure mode is a ceiling you believe is enforcing and is not.

Q8

Rotation is gated on virtual-key:update rather than create because:

A. It modifies an existing record rather than creating one
B. Create is reserved for provisioning a brand new key only
C. The endpoint is nested under the existing key’s own id
D. Rotation revokes the old key, so it destroys something

Show answer

Correct: D. A create-only role must not be able to destroy a key by rotating it. The verb is chosen by consequence rather than by HTTP method.

Q9

Editor gets full CRUD on AI Virtual Key but view-only on AI Model because:

A. Models are more expensive to change than keys are
B. Connecting a credential is Admin, and model registration accepts a provider key
C. Model registration requires a schema migration before the new model can be run at all
D. Keys are personal and models are shared org-wide

Show answer

Correct: B. A virtual key is a consumption artifact over already-connected models and accepts no provider secret, so it sits with resource, schedule and dashboard.

Q10

A role scoped to one provider opens the model list and sees:

A. Only that provider’s models
B. That provider’s models plus any on a key they own
C. No models
D. Every registered model

Show answer

Correct: D. The model list is a shared read and provider scope is a no-op on it: scope narrows model create and delete, not view. The virtual-key list does hide keys outside the caller’s providers.


What’s next

Back to AI Gateway governance.

Start with the bill.

Foundations takes about five hours. The first lesson is nine minutes.

Open curriculum. No login. No paywall. 290 lessons across 7 courses, three publicly verifiable credentials. Read it on the train, take the exam on a Saturday, list the credential on your résumé Monday.

5h median time to finish Foundations
0 logins, paywalls, or marketing forms
open curriculum, public credential verifier
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·