Courseiva

AIF-C01 Applications of Foundation Models Practice Question

A company is using Amazon Bedrock to generate code snippets. Developers report that the generated code sometimes contains security vulnerabilities. Which action should the team take to mitigate this risk?

⚠ Common exam trap

AWS often tests the misconception that reducing temperature or isolating the environment can fix output quality issues, when in fact only prompt-level guidance directly addresses the model's generation behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities.

Adding a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities directly influences the model's output at inference time. Amazon Bedrock supports system prompts that act as high-level instructions to guide the foundation model's behavior, making this a proactive, scalable mitigation that does not require manual intervention or architectural changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the model in a sandbox environment to limit its access to sensitive systems.

    Why it's wrong here

    Sandboxing constrains where generated code executes; it does not stop Bedrock from emitting vulnerable snippets in the first place. The risk originates in model output, so mitigation must filter or validate that output. Sandboxing suits containing untrusted code during execution testing, not improving generation quality.

  • ✗

    Implement a manual code review process after generation.

    Why it's wrong here

    Manual review catches some flaws but does not scale and leaves the underlying generation unchanged, so vulnerable patterns persist at volume. The stem asks for mitigation of the model's output risk. Manual review suits low-volume, high-stakes code where human judgement is already the control.

  • ✓

    Add a system prompt that instructs the model to follow security best practices and avoid known vulnerabilities.

    Why this is correct

    A system prompt steers the foundation model at inference time, so instructing it to follow security best practices directly reduces vulnerable code output without retraining or infrastructure changes. This satisfies the scenario's constraint of mitigating risk within the existing Amazon Bedrock setup, though prompt-level guidance offers weaker assurance than automated code scanning.

  • ✗

    Reduce the temperature parameter to 0 to make the output deterministic.

    Why it's wrong here

    Temperature 0 makes sampling deterministic, so the same prompt yields the same snippet — a vulnerable pattern would simply recur reliably. Determinism is unrelated to security correctness. Temperature tuning suits tasks needing reproducible, factual answers, such as classification or extraction, not vulnerability removal.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.