Courseiva

AIF-C01 Applications of Foundation Models Practice Question

A company is using Amazon Bedrock to generate code snippets. They want to ensure the generated code is secure. Which TWO practices should they implement?

⚠ Common exam trap

The AIF-C01 exam often tests the misconception that model parameters like temperature or token limits can substitute for explicit security controls, when in fact only guardrails and human review directly address code security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use guardrails to block insecure code patterns.

Option B is correct because Amazon Bedrock Guardrails let you define denied topics, content filters, and (critically for this scenario) sensitive-information and custom word/regex filters that can detect and block insecure code patterns such as hardcoded credentials or known dangerous constructs before the response is returned. Option D is correct because no generative model guarantees secure output; generated code must be treated as untrusted and go through human review plus SAST/DAST and unit testing in the CI/CD pipeline before deployment, which is the standard secure-SDLC control for AI-generated artifacts. Option A does not belong because raising the max token limit only affects output length, not security posture. Option C does not belong because temperature 0 makes sampling more deterministic but does not make code secure. Option E does not belong because a larger model may improve accuracy or fluency, but accuracy is not a security control and does not prevent insecure code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the max token limit to generate longer code.

    Why it's wrong here

    Raising the max token limit only extends output length; it applies no security scanning, validation or filtering to generated code. It is tempting because larger limits suit generating complete multi-file solutions, but the practice addresses throughput, not the secure-code requirement the stem asks about.

  • ✓

    Use guardrails to block insecure code patterns.

    Why this is correct

    Guardrails apply configurable content filters that intercept prompts and responses, blocking insecure code patterns before they reach developers. This satisfies the stem's security requirement by preventing vulnerable snippets at generation time rather than after deployment.

  • ✗

    Set the temperature to 0 for deterministic output.

    Why it's wrong here

    Temperature controls randomness in token selection, not code security; a low value yields repeatable output but does nothing to prevent vulnerabilities such as injection flaws. It is tempting because deterministic output aids testing, but this setting would be correct when the requirement is consistent, reproducible responses rather than secure code.

  • ✓

    Review and test all generated code before deployment.

    Why this is correct

    Reviewing and testing generated code before deployment satisfies the requirement to ensure security, since Amazon Bedrock cannot guarantee vulnerability-free output. Human validation catches insecure patterns, logic flaws and exposed secrets that the model may produce, acting as the final control before code reaches production.

  • ✗

    Use a larger model for better accuracy.

    Why it's wrong here

    Model size affects capability and reasoning quality, not whether generated code contains security flaws; a larger model can still emit vulnerable patterns. It is tempting because bigger models often perform better on benchmarks, but this choice would be correct when the requirement is higher accuracy on complex tasks rather than secure code generation.

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.