AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company is implementing an AI governance framework for their machine learning models deployed on Amazon SageMaker. Which THREE actions should they include to manage the model lifecycle effectively? (Select THREE.)
⚠ Common exam trap
AIF-C01 often tests the misconception that CloudTrail provides model performance monitoring — candidates confuse API activity logging with model behavior observability, when CloudWatch (with Model Monitor) is the correct service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Amazon CloudWatch alarms for model accuracy metrics
Option A is correct because Amazon CloudWatch alarms on model accuracy metrics (e.g., via SageMaker Model Monitor's ModelQuality metrics) provide automated detection of drift or degradation, which is essential for governing model performance across the lifecycle. Option C is correct because a formal decommissioning policy ensures old models are retired in a controlled, auditable way, preventing stale or non-compliant models from continuing to serve predictions. Option E is correct because SageMaker Model Registry provides model versioning, approval workflows, and metadata tracking, which are foundational for managing the model lifecycle and governance. Option B is not appropriate because automatically deleting all previous model versions destroys the audit trail and rollback capability that governance frameworks require. Option D is not the right tool because CloudTrail records AWS API activity (control-plane events), not individual model inference requests; inference logging is handled by SageMaker endpoint data capture or CloudWatch Logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Amazon CloudWatch alarms for model accuracy metrics
Why this is correct
CloudWatch alarms on accuracy metrics detect drift and degradation during live inference, satisfying the governance requirement to monitor deployed models continuously. This provides the observability needed to trigger retraining or rollback decisions across the model lifecycle.
- ✗
Automatically delete all previous model versions after deployment
Why it's wrong here
Deleting prior versions destroys the lineage and rollback capability that lifecycle governance requires, and SageMaker model registry exists to retain them. It is tempting because removing stale artefacts controls storage and confusion, and would be correct for disposable experimental models with no audit or rollback obligation.
- ✓
Create a decommissioning policy that retires old models
Why this is correct
A decommissioning policy directly addresses the lifecycle's end stage, ensuring obsolete models are retired rather than left serving stale predictions. This satisfies the stem's requirement to manage the full model lifecycle on SageMaker, covering governance beyond training and deployment through to controlled, auditable retirement.
- ✗
Use AWS CloudTrail to track model inference requests
Why it's wrong here
CloudTrail records control-plane API activity such as model creation and endpoint changes, not individual inference requests, which InvokeEndpoint data events or model monitor logs capture. It is tempting because CloudTrail genuinely supports governance auditing, and would be correct for tracking who modified SageMaker resources.
- ✓
Use SageMaker Model Registry to version models
Why this is correct
SageMaker Model Registry provides versioned model packages with approval statuses, satisfying the lifecycle governance constraint by tracking lineage from training artefact to deployment endpoint. Each registered version records metadata, metrics and approval state, enabling audit trails and controlled promotion across environments.
Go deeper
Related to this question
About these practice questions
One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.