AIF-C01 Applications of Foundation Models Practice Question
A company is using Amazon Bedrock to generate code snippets. Developers report that the generated code sometimes contains security vulnerabilities. Which action should the team take to mitigate this risk?
⚠ Common exam trap
AWS often tests the misconception that reducing temperature or isolating the environment can fix output quality issues, when in fact only prompt-level guidance directly addresses the model's generation behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities.
Adding a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities directly influences the model's output at inference time. Amazon Bedrock supports system prompts that act as high-level instructions to guide the foundation model's behavior, making this a proactive, scalable mitigation that does not require manual intervention or architectural changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the model in a sandbox environment to limit its access to sensitive systems.
Why it's wrong here
Sandboxing constrains where generated code executes; it does not stop Bedrock from emitting vulnerable snippets in the first place. The risk originates in model output, so mitigation must filter or validate that output. Sandboxing suits containing untrusted code during execution testing, not improving generation quality.
- ✗
Implement a manual code review process after generation.
Why it's wrong here
Manual review catches some flaws but does not scale and leaves the underlying generation unchanged, so vulnerable patterns persist at volume. The stem asks for mitigation of the model's output risk. Manual review suits low-volume, high-stakes code where human judgement is already the control.
- ✓
Add a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities.
Why this is correct
A system prompt steers the foundation model at inference time, so instructing it to follow security best practices directly reduces vulnerable code output without retraining or infrastructure changes. This satisfies the scenario's constraint of mitigating risk within the existing Amazon Bedrock setup, though prompt-level guidance offers weaker assurance than automated code scanning.
- ✗
Reduce the temperature parameter to 0 to make the output deterministic.
Why it's wrong here
Temperature 0 makes sampling deterministic, so the same prompt yields the same snippet — a vulnerable pattern would simply recur reliably. Determinism is unrelated to security correctness. Temperature tuning suits tasks needing reproducible, factual answers, such as classification or extraction, not vulnerability removal.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.