Security, Compliance, and Governance for AI Solutions

Domain 5: Security, Compliance, and Governance for AI Solutions

25 practice questions for Domain 5 of the AWS Certified AI Practitioner (AIF-C01) exam, which makes up 14% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 5: Security, Compliance, and Governance for AI Solutions

14% of scored content · 25 practice questions

210. A company must ensure that prompts submitted to a foundation model are not used to train the provider's base models, and that data stays within a chosen AWS Region. Which statement is correct for Amazon Bedrock?

Answer and explanation

Answer: C. Bedrock's documented behaviour is that customer inputs and outputs are not used to train the underlying base models and are not shared with model providers, and requests are served in the Region the customer calls. The claim that prompts train base models by default contradicts that. Region selection is precisely how data residency is controlled. The in-Region guarantee applies to base model inference as well as customized models.

211. An application built on a foundation model must block prompts requesting disallowed content and filter harmful responses before they reach users. Which capability addresses this?

Answer and explanation

Answer: B. Bedrock Guardrails applies configurable content filters, denied topics, word filters, and sensitive information handling to both the prompt and the model response, which is exactly the two-sided control described. WAF inspects HTTP requests for web exploits and cannot evaluate model semantics. Macie discovers and classifies sensitive data in S3. Shield Advanced provides DDoS protection. WAF, Macie, and Shield Advanced each operate at a different layer, and none of them inspects generative model content.

212. Which service should be used to discover personally identifiable information sitting in Amazon S3 before it is used to train or ground a model?

Answer and explanation

Answer: D. Macie applies managed and custom data identifiers to classify sensitive data such as PII in S3 buckets. GuardDuty detects threat activity from account and network telemetry. Config records resource configuration and evaluates compliance rules. Trusted Advisor gives best-practice recommendations across cost, performance, and security.

213. Which mechanism restricts which IAM principals in an account may invoke a specific Amazon Bedrock model?

Answer and explanation

Answer: C. Access to Bedrock models is governed by IAM, and a policy naming the invoke action and the specific model ARN grants exactly the intended access. Security groups filter network traffic and do not attach to managed model APIs. A bucket policy governs S3 objects. Guardrails filter content within a request and do not decide who may call the model.

214. An auditor asks for a record of every Amazon Bedrock model invocation, including which principal made each call. Which service provides this?

Answer and explanation

Answer: C. CloudTrail records API activity including the calling identity, time, and source address, which is the audit record described. CloudWatch metrics show invocation counts and latency without identifying callers. Cost Explorer reports spend. Macie classifies sensitive data at rest.

215. Under the shared responsibility model, which task belongs to the customer when using a managed generative AI service?

Answer and explanation

Answer: A. Customers control their data, their prompts, and the identity and access model of their application, which is security in the cloud. Host patching, physical facility security, and serving infrastructure maintenance are all AWS responsibilities for security of the cloud.

216. A regulated company must ensure that traffic between its VPC and Amazon Bedrock does not traverse the public internet. What should be configured?

Answer and explanation

Answer: D. An interface endpoint places a PrivateLink-backed network interface in the VPC so calls to Bedrock stay on the AWS network. A NAT gateway routes traffic to the internet, which is what the requirement excludes. An internet gateway does the same regardless of routing rules. Gateway endpoints are available only for S3 and DynamoDB.

217. Where should a company look for AWS compliance attestations such as SOC 2 and ISO 27001 reports covering AI services?

Answer and explanation

Answer: C. Artifact is the self-service portal for downloading AWS audit artifacts, including SOC and ISO reports. Trusted Advisor makes best-practice recommendations rather than distributing attestations. Inspector performs vulnerability assessment of workloads. Audit Manager collects evidence against control frameworks but relies on Artifact for the underlying AWS attestations.

218. Which practice reduces the risk that sensitive data entered by users is exposed in a generative AI application's outputs?

Answer and explanation

Answer: C. Removing sensitive data before it reaches the model, and filtering the response as a second layer, addresses the exposure at both ends of the request. Encrypting logs protects stored records but the data still passes through the model and back to users. A larger context window and fewer users do not affect what the model may disclose.

219. Which practice reduces the risk that a user manipulates a generative application's instructions through crafted input?

Answer and explanation

Answer: C. Prompt manipulation is mitigated by treating input as untrusted, filtering it, and scoping permissions so a successful attempt achieves little. A longer instruction is itself part of the context an attack targets. Temperature and output length do not constrain what the model can be induced to do.

220. Which principle should govern the permissions granted to an application that calls a foundation model and internal APIs?

Answer and explanation

Answer: A. Least privilege limits the damage from a defect or a successful manipulation of the application. Administrator access maximises the blast radius. Copying a senior colleague's permissions propagates over-provisioning. Broad read access still exposes data the application has no need to see.

221. A company must retain evidence of how its generative AI application behaved for a compliance review. Which combination is appropriate?

Answer and explanation

Answer: B. A reviewer must be able to reconstruct what was asked, what was returned, and under which model and guardrail configuration, which requires invocation logging with those identifiers. Usage metrics describe volume. Source code shows intent rather than behaviour. An access list documents who could use the system, not what it did.

222. Which control keeps data used by a generative AI application encrypted at rest with a key the company manages?

Answer and explanation

Answer: A. A customer managed KMS key gives the company an author-controlled key policy, controllable rotation, and an audit trail of key usage. AWS managed keys expose no key policy. TLS protects data in transit rather than at rest. An IAM policy controls access without encrypting.

223. Which statement about compliance responsibilities for a generative AI application is correct?

Answer and explanation

Answer: A. Under the shared responsibility model AWS attests to its own controls while the customer remains accountable for its application, its data handling, and its regulatory obligations. Provider certification does not confer compliance on a customer application. Obligations cannot be transferred to a provider. Outputs can carry regulatory implications as much as stored data.

224. Which technique reduces hallucinations by grounding a model's response in retrieved source material?

Answer and explanation

Answer: A. RAG supplies retrieved passages so the response is grounded in source material the answer can be checked against. Higher temperature increases variability and hallucination. More output tokens produce longer responses. A shorter prompt removes context.

225. What does confidence scoring contribute to hallucination detection in a generative AI application?

Answer and explanation

Answer: B. A confidence score identifies responses warranting verification, which is a triage signal rather than a guarantee. A high score does not establish factual correctness, since confidence is often poorly calibrated. Scoring does not change generation length or prevent unsupported content on its own.

226. Which service controls which principals may invoke a foundation model?

Answer and explanation

Answer: D. IAM policies control who may call the model. Macie classifies data. Config records configuration. CloudWatch monitors.

227. Which practice protects training data from unauthorized access?

Answer and explanation

Answer: A. Encryption with least-privilege access protects the data. Public storage and broad sharing expose it. Removing metadata does not control access.

228. What is data lineage in the context of an AI system?

Answer and explanation

Answer: C. Lineage records origin and transformation. Storage location, size, and encryption are separate attributes.

229. Which risk does supplying personal data to a foundation model introduce?

Answer and explanation

Answer: C. Personal data may surface in responses or persist in logs. Refusal, accuracy gains, and licence revocation are not the principal risks.

230. Which regulation concept requires that individuals can request the deletion of their personal data?

Answer and explanation

Answer: B. Data subject rights include deletion requests, which an AI system must honour across training data, logs, and retrieval indexes. Licensing terms, service level agreements, and quotas are unrelated to individual data rights.

231. Why does an organization define a data retention policy for AI system logs?

Answer and explanation

Answer: C. Retention policies address regulatory obligation and limit exposure. They do not affect accuracy, latency, or training data volume.

232. Which practice supports governance of an AI system throughout its lifecycle?

Answer and explanation

Answer: B. Lifecycle governance reviews at defined checkpoints throughout. Launch-only, incident-only, and replacement-only reviews all leave long ungoverned periods.

233. Which practice protects against sensitive data being exposed through a generative AI application's responses?

Answer and explanation

Answer: C. Removing sensitive data from the sources and filtering responses addresses both entry and exit. Encryption protects storage, deployment restrictions control who builds, and shorter responses do not filter content.

234. Which practice reduces the risk of sensitive data reaching a foundation model in the first place?

Answer and explanation

Answer: B. Removing sensitive values before sending prevents the exposure. Response filtering acts after processing, encryption protects transit, and logging records.