easyMultiple Choice
AIF-C01 Practice Question: Using Amazon Bedrock to build a generative AI…
A company is using Amazon Bedrock to build a generative AI application. The company wants to prevent the model from generating toxic or harmful content while still allowing creative responses. Which feature should the company enable?
⚠ Common exam trap
Candidates often confuse security services (like KMS for encryption or IAM for access control) with content moderation capabilities, assuming any AWS security service can filter model outputs, when in fact only Bedrock Guardrails provides purpose-built content filters for generative AI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Bedrock Guardrails with content filters.
Amazon Bedrock Guardrails with content filters is the correct feature because it allows the company to define and enforce policies that block toxic or harmful content in model inputs and outputs, while still permitting creative responses within safe boundaries. This feature provides configurable thresholds for content categories like hate, insults, and sexual content, enabling precise control over model behavior without restricting overall creativity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon Bedrock Guardrails with content filters.
Why this is correct
Guardrails applies configurable content filters that block toxic categories such as hate, violence and insults on both prompts and responses, while threshold tuning preserves creative output. This satisfies the requirement to prevent harmful generation without suppressing legitimate creative responses.
- ✗
AWS Key Management Service (KMS) to encrypt model responses.
Why it's wrong here
KMS encrypts data at rest and in transit; it cannot inspect or filter generated text, so toxic output still reaches users. It is tempting because KMS is the standard control for protecting model responses and fine-tuning data confidentiality, and would be correct where the requirement is encryption of stored artefacts rather than content moderation.
- ✗
AWS Identity and Access Management (IAM) policies to restrict model output.
Why it's wrong here
IAM policies authorise which principals may invoke models and guardrails; they cannot evaluate or block harmful wording inside a response. IAM is tempting because it governs access to Bedrock actions and resources, and would be right if the goal were limiting who can call the model rather than filtering what it generates.
- ✗
Amazon CloudWatch Logs to monitor and block harmful content.
Why it's wrong here
CloudWatch Logs records and monitors application output; it neither inspects prompts nor blocks model responses. It is tempting because observability is genuinely useful for auditing AI traffic, but content filtering requires Amazon Bedrock Guardrails, which applies configurable harmful-content policies while permitting creative output.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.