AIF-C01 Fundamentals of Generative AI Practice Question
A company is deploying a generative AI model on Amazon Bedrock and needs to monitor for potential misuse. Which THREE measures should they implement? (Choose 3)
⚠ Common exam trap
The AIF-C01 exam often tests the distinction between security controls that prevent access (like MFA or VPC isolation) versus monitoring controls that detect or block misuse at the content level, leading candidates to confuse network security with content safety.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Amazon Bedrock Guardrails to block harmful content.
Option B is correct because Amazon Bedrock Guardrails are purpose-built to detect and block harmful or inappropriate content (e.g., hate, violence, prompt injection) in both prompts and model responses, directly addressing misuse monitoring and prevention. Option C is correct because AWS CloudTrail records all Bedrock API activity and management events, providing an auditable trail of who invoked which model, when, and from where, which is essential for detecting misuse. Option E is correct because enabling model invocation logging sends full request/response data to Amazon CloudWatch Logs, allowing continuous monitoring, alerting, and forensic analysis of model inputs and outputs. Option A is not appropriate because MFA applies to human console sign-ins, not programmatic API calls, and Bedrock APIs use IAM credentials/signatures rather than MFA tokens. Option D is not required for misuse monitoring; a private VPC endpoint improves network isolation but does not detect or log misuse, and Bedrock endpoints are AWS-managed services accessed via VPC endpoints rather than being 'placed' in a VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require multi-factor authentication (MFA) for all API calls.
Why it's wrong here
MFA strengthens caller authentication but does not observe model inputs or outputs, so misuse by a legitimate authenticated user goes undetected. It tempts because MFA is a standard access control, and it would be correct if the requirement were preventing credential compromise rather than monitoring misuse.
- ✓
Configure Amazon Bedrock Guardrails to block harmful content.
Why this is correct
Amazon Bedrock Guardrails apply content filters that intercept harmful inputs and outputs at inference time, directly satisfying the requirement to monitor for potential misuse. By defining denied topics and filtering categories, the company enforces safety controls on the generative model itself, rather than relying on post-hoc logging or external review.
- ✓
Use AWS CloudTrail to log API calls and Amazon Bedrock actions.
Why this is correct
CloudTrail records every Bedrock API call as an auditable event, capturing identity, timestamp, source IP and action. This provides the forensic trail needed to detect and investigate misuse, satisfying the monitoring requirement across accounts and regions.
- ✗
Place the Bedrock endpoint in a private VPC with no internet access.
Why it's wrong here
VPC is about network security, not monitoring.
- ✓
Enable model invocation logging in Amazon CloudWatch.
Why this is correct
Model invocation logging captures full request and response payloads plus metadata to CloudWatch Logs, enabling inspection of actual prompts and outputs. This satisfies the misuse-monitoring constraint by exposing content-level activity that CloudTrail's control-plane events alone cannot show.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.