45 practice questions for Domain 3 of the AWS Certified Generative AI Developer - Professional (AIP-C01) exam, which makes up 20% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 3: AI Safety, Security, and Governance
160. A user-facing assistant must block harmful content in both the user's input and the model's response. Which solution meets these requirements?
Answer and explanation
Answer: C. A guardrail evaluating both directions blocks a harmful request before it reaches the model and a harmful response before it reaches the user. Filtering only the output allows the request through. A prompt instruction is advisory. Weekly sampling detects after users have seen the content.
161. A generated answer cites a policy clause that does not appear in the retrieved passages. Which solution meets these requirements?
Answer and explanation
Answer: C. Contextual grounding evaluates whether the response is entailed by the supplied context, which is exactly the hallucinated-citation case. More passages does not prevent fabrication. Lower temperature makes a fabrication more consistent rather than absent. A prompt instruction is advisory.
162. A defence-in-depth approach must protect a GenAI application rather than relying on one control. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, E. Layering input filtering, a model-layer guardrail, and output validation means a bypass of one control still meets another. Temperature and output length are generation parameters rather than controls. A published policy informs without enforcing.
163. An application must detect attempts to override its instructions through crafted user input. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: C, D. Detection catches known manipulation patterns and least-privilege scoping limits what any successful attempt can achieve. A longer instruction is itself part of the context an injection targets. Temperature adds randomness rather than a control. Removing the system prompt discards the instruction that shapes safe behaviour.
164. A GenAI application in a VPC must reach the model service without its traffic traversing the internet. Which solution meets these requirements?
Answer and explanation
Answer: D. An interface endpoint backed by PrivateLink keeps the traffic on the AWS network and an endpoint policy narrows what may be invoked. Gateway endpoints exist only for Amazon S3 and DynamoDB. A NAT gateway routes to the internet. Public addresses create the exposure being avoided.
165. Personal information must not appear in model responses, and it may be present in the retrieval corpus. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, C. Redacting before indexing means the data cannot be retrieved, and a sensitive information policy catches anything that remains. A prompt instruction is advisory. Retrieving fewer passages reduces but does not remove exposure. Restricting who may query does not stop authorised users receiving the data.
166. An auditor must establish which data sources contributed to a specific generated response. Which solution meets these requirements?
Answer and explanation
Answer: D. Recording the specific source identifiers and returning them as citations makes the contributing sources reconstructable for any response. A passage count says nothing about which sources. A timestamp and index version narrow the search without identifying the sources. The model identifier describes how rather than from what.
167. A compliance framework requires documented limitations and intended use for each deployed model configuration. Which solution meets these requirements?
Answer and explanation
Answer: C. Model cards capture intended use, limitations, and evaluation results as a governance artifact tied to the configuration. A model identifier names the model without describing its use or limits. Provider documentation describes the base model rather than this deployment. Pipeline metrics record performance without the surrounding context.
168. Users must be able to see why the assistant produced a particular answer. Which solution meets these requirements?
Answer and explanation
Answer: A. Showing the sources and the reasoning trace lets a user check what the answer rests on. A confidence score is often poorly calibrated and explains nothing. Model and prompt identifiers are provenance rather than reasoning. Elapsed time is operational.
169. An application's outputs must be assessed for systematic differences in quality across user groups. Which solution meets these requirements?
Answer and explanation
Answer: D. Detecting a systematic difference requires measuring each group separately and comparing. An aggregate mean hides the difference. Removing references prevents the measurement. Self-assessment by the model is not evidence.
170. A guardrail blocks a request that a legitimate user needed to make. Which response is appropriate?
Answer and explanation
Answer: B. A guardrail has both false positive and false negative rates, and both are tuned from reviewed examples. Disabling it removes the protection. Asking users to rephrase shifts the cost onto them and teaches evasion. Accepting all false positives ignores half the trade-off.
171. An application must verify that a generated answer is supported by the retrieved passages before returning it. Which approach is appropriate?
Answer and explanation
Answer: A. A grounding check evaluates whether the context entails the response, which is what detects an unsupported claim. Consistency with previous answers detects variation rather than truth. A citation can be present while the claim it supports is fabricated. Length is unrelated.
172. An adversarial testing programme must be established for a GenAI application. Which approach is appropriate?
Answer and explanation
Answer: D. A maintained suite run on every change catches regressions as the application and attack techniques evolve. One-off testing goes stale immediately. Vendor testing covers their product rather than this application. A model generating and evaluating its own attacks is not an independent test.
173. An application must ensure that a user can only retrieve documents their role permits. Which approach is appropriate?
Answer and explanation
Answer: C. Filtering at retrieval from a verified role means unauthorised content never enters the context. Filtering the response happens after that content has influenced generation. A role stated in the prompt is an instruction the model may not follow. A per-user index is unmanageable and unnecessary.
174. Prompts and responses logged for troubleshooting may contain personal information. Which approach is appropriate?
Answer and explanation
Answer: B. Masking makes the values unreadable to ordinary log readers while retaining the log's diagnostic value, with unmasked access held narrowly. Encryption protects against outside readers while authorised principals still see the values. Shorter retention reduces the window. Disabling logging removes troubleshooting capability entirely.
175. An organization must demonstrate which data sources contributed to a GenAI system's outputs over a reporting period. Which approach is appropriate?
Answer and explanation
Answer: D. Per-invocation source identifiers are what allow contribution to be demonstrated for any output in the period. Document counts, model version, and request volume describe the system rather than the provenance of its answers.
176. A governance framework must detect when a deployed GenAI system begins violating a policy it previously satisfied. Which approach is appropriate?
Answer and explanation
Answer: D. Continuous monitoring detects drift into violation between deployments, which point-in-time assessment cannot. Pre-deployment assessment, quarterly configuration review, and annual audit all leave gaps during which a violation goes undetected.
177. A user must be able to judge how much to rely on a generated answer. Which approach is most useful?
Answer and explanation
Answer: A. Showing the sources lets a user verify the answer themselves, which is the most actionable form of transparency. A confidence score is often poorly calibrated and cannot be checked. Model identity and generation time describe the system rather than the answer's basis.
178. An A/B test must establish whether a prompt change affects outputs differently across user groups. Which design is appropriate?
Answer and explanation
Answer: C. Differential effects only appear when outcomes are compared within each group, since an aggregate can improve while one group worsens. Testing on the largest group assumes the others behave identically. Aggregate significance says nothing about distribution across groups.
179. A custom moderation workflow must handle content categories a managed guardrail does not cover. Which approach is appropriate?
Answer and explanation
Answer: C. A custom classifier extends coverage where the managed guardrail stops. Relying on it alone leaves gaps. User instructions and manual review do not scale.
180. A text-to-SQL feature must guarantee that generated queries cannot modify data. Which control is appropriate?
Answer and explanation
Answer: B. A read-only execution role enforces the guarantee at the database. A prompt instruction is advisory. Manual review does not scale. Trust is not a control.
181. A structured output must be enforced so a downstream parser never receives malformed data. Which approach is appropriate?
Answer and explanation
Answer: D. Schema validation guarantees the parser's input. An instruction is advisory. Try-catch handles failure rather than preventing malformed input. Temperature reduces variation without guaranteeing structure.
182. A GenAI application's data access must be auditable so a reviewer can see which data each request touched. Which approach is appropriate?
Answer and explanation
Answer: D. Per-request data access logs with correlation give a reviewable trail. Counts and failure-only logs omit what was accessed. Uncorrelated store logs cannot tie access to a request.
183. A retention policy must ensure that logged prompts containing personal data are deleted after 90 days. Which approach is appropriate?
Answer and explanation
Answer: B. Lifecycle rules and log group retention delete automatically on schedule. Manual deletion is unreliable. Indefinite retention violates the policy. Encryption does not delete.
184. A regulatory framework requires a decision log for every automated decision a GenAI system makes. Which implementation is appropriate?
Answer and explanation
Answer: A. A complete per-decision record with provenance satisfies a decision log requirement. Outcome-only, dispute-only, and summary records omit required detail.
185. A GenAI system's compliance posture must be monitored for policy violations that emerge after deployment. Which approach is appropriate?
Answer and explanation
Answer: D. Continuous automated detection catches emerging violations. Annual and deployment-time assessment leave gaps. Complaints are reactive.
186. An agent's reasoning must be surfaced to users so they can understand how it reached a recommendation. Which capability provides this?
Answer and explanation
Answer: C. A reasoning trace explains the path. Confidence, time, and tool count do not explain reasoning.
187. A policy-compliant system must document each foundation model's known limitations for reviewers. Which artifact is appropriate?
Answer and explanation
Answer: A. A model card is the governance artifact for limitations and intended use. API documentation describes the interface. A user guide addresses users. Parameter lists describe architecture.
188. A guardrail must block a category of content the managed filters do not cover. Which approach is appropriate?
Answer and explanation
Answer: C. A custom filter with measured error rates addresses the specific gap. Maximum strictness blocks legitimate content, instructions are advisory, and manual review does not scale.
189. A GenAI application must prevent a user from extracting content they are not entitled to see through careful prompting. Which approach is appropriate?
Answer and explanation
Answer: C. Enforcement before retrieval means the content is never available to disclose. Instructions and response filtering both act after the content entered the context, and logging detects rather than prevents.
190. A safety control must be tested against inputs designed to bypass it. Which approach is appropriate?
Answer and explanation
Answer: A. A maintained suite run on every change catches regressions as techniques evolve. One-off testing goes stale, vendor testing covers their product, and production monitoring detects after the fact.
191. A GenAI application must handle content that is legitimate in one context and inappropriate in another. Which approach is appropriate?
Answer and explanation
Answer: C. Context-aware evaluation handles the distinction. Blanket blocking or allowing ignores it, and asking the user shifts the judgement onto them.
192. A GenAI system's safety controls must not be bypassed by calling the model directly. Which approach is appropriate?
Answer and explanation
Answer: C. Boundary enforcement with restricted direct access covers every path. Documentation is advisory, client-side controls are bypassable, and monitoring detects afterwards.
193. Data sent to a foundation model must not be used to train the provider's models. Which approach is appropriate?
Answer and explanation
Answer: B. Verifying the terms and configuring opt-outs addresses training use directly. Encryption would make the data unusable to the model, de-identification reduces but does not address the term, and network path is unrelated.
194. A GenAI application must isolate one tenant's data from another's in its vector store. Which approach is appropriate?
Answer and explanation
Answer: B. Enforced separation from verified identity, with separate indexes where required, prevents cross-tenant exposure. Prompt identifiers are manipulable, post-retrieval filtering acts too late, and similarity offers no guarantee.
195. Prompts containing sensitive data must be retained for troubleshooting without exposing the data. Which approach is appropriate?
Answer and explanation
Answer: D. Masking before logging with restricted unmasked access preserves diagnostic value without broad exposure. Encryption protects against outside readers only, shorter retention narrows the window, and disabling logging removes troubleshooting.
196. A GenAI system must satisfy an audit requirement to show what influenced each decision. Which approach is appropriate?
Answer and explanation
Answer: A. Full per-decision provenance satisfies the requirement. Responses alone, summaries, and partial records omit what influenced the decision.
197. An organization must demonstrate that its GenAI system complies with an internal policy over time. Which approach is appropriate?
Answer and explanation
Answer: C. Continuous evaluation with retained results demonstrates sustained compliance. Deployment-time assessment, annual review, and documentation cover a point or intent.
198. A GenAI system's governance must define who may change its prompts and guardrails. Which approach is appropriate?
Answer and explanation
Answer: D. Named roles with review and recorded changes give controlled, auditable governance. Unrestricted change removes control, a single individual is a bottleneck and a risk, and monthly review is retrospective.
199. A GenAI system processing data from several jurisdictions must meet each one's requirements. Which approach is appropriate?
Answer and explanation
Answer: A. Per-flow analysis applies the right controls to each. A uniform strictest standard may be unnecessarily costly and may still miss a specific obligation, a home standard may not satisfy others, and single-jurisdiction processing may violate residency.
200. A GenAI system must support a request to delete an individual's personal data. Which approach is appropriate?
Answer and explanation
Answer: A. Deletion must reach every store including derived indexes and logs. Primary-database-only deletion, soft deletion, and waiting all leave the data present.
201. A GenAI system's risk classification must determine how much oversight it receives. Which approach is appropriate?
Answer and explanation
Answer: D. Consequence, sensitivity, and autonomy determine risk and therefore oversight. Uniform oversight is disproportionate, and user counts and cost do not indicate risk.
202. A GenAI application must disclose its limitations to users appropriately. Which approach is appropriate?
Answer and explanation
Answer: B. Stating limitations at the point of reliance is what reaches the user. Terms of service, technical documentation, and inference all fail to inform at the moment of use.
203. A GenAI system's fairness must be assessed across user groups. Which approach is appropriate?
Answer and explanation
Answer: D. Group-level comparison reveals disparities an aggregate hides. Aggregates, single-group evaluation, and assumptions about training data do not.
204. A GenAI system's decisions must be explainable to an affected individual. Which approach is appropriate?
Answer and explanation
Answer: D. Inputs and reasoning path let an individual evaluate the decision. Confidence scores, model identity, and aggregate accuracy do not explain their case.