hardMultiple Choice
AIF-C01 Practice Question: Deploying a generative AI application that…
A company is deploying a generative AI application that creates marketing copy. They want to ensure the outputs do not include harmful or inappropriate content. Which AWS service can enforce content policies and filter undesirable outputs?
⚠ Common exam trap
AIF-C01 often tests the confusion between general-purpose AWS security services (WAF, Shield) and AI-specific responsible AI tooling — candidates must recognize that content moderation for generative AI requires Bedrock Guardrails, not traditional network security services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Bedrock Guardrails
Amazon Bedrock Guardrails lets you define content filters, denied topics, word filters, and sensitive information filters that are applied to both inputs and outputs of foundation models. It is purpose-built to enforce responsible AI policies and block harmful or inappropriate content in generative AI applications. This directly addresses the requirement to filter undesirable outputs from a marketing copy generator.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF
Why it's wrong here
AWS WAF filters inbound HTTP requests at the edge against web exploit rules; it inspects traffic, not model-generated text, so it cannot evaluate marketing copy for harmful content. It is tempting because WAF is the correct choice for blocking malicious inbound requests to a public application.
- ✗
Amazon Comprehend
Why it's wrong here
Amazon Comprehend performs NLP tasks such as sentiment, entity and PII detection; it does not enforce configurable content policies or block undesirable generative output. It is tempting because Comprehend is the correct choice when the requirement is extracting insight or detecting PII within text rather than filtering harmful content.
- ✓
Amazon Bedrock Guardrails
Why this is correct
Amazon Bedrock Guardrails applies configurable content filters and denied-topic policies to model inputs and outputs, blocking harmful or inappropriate marketing copy. This directly satisfies the stem's requirement to enforce content policies and filter undesirable generative AI outputs.
- ✗
AWS Shield
Why it's wrong here
AWS Shield provides DDoS protection at the network and transport layers; it has no visibility into generated text and cannot apply content policies. It is tempting because Shield is the correct choice when the requirement is defending an internet-facing application against volumetric or protocol-layer denial-of-service attacks.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.