Courseiva
easyMultiple Choice

AIF-C01 Practice Question: Using Amazon Bedrock to generate responses for…

A company is using Amazon Bedrock to generate responses for customer support. They want to ensure that the model does not expose personally identifiable information (PII) in its outputs. Which AWS feature can be configured to automatically redact PII from model responses?

⚠ Common exam trap

Many exam-takers confuse Amazon Macie (a data discovery service for S3) with a real-time content filtering capability, or assume that SageMaker Model Monitor can be applied to Bedrock, when in fact only Bedrock Guardrails provides native PII redaction for model responses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Bedrock Guardrails

Amazon Bedrock Guardrails is the correct choice because it provides configurable policies that can automatically detect and redact personally identifiable information (PII) from model inputs and outputs. This feature is specifically designed for Amazon Bedrock to enforce content safety and compliance requirements, including PII redaction, without requiring custom code or external services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Macie

    Why it's wrong here

    Macie discovers and classifies sensitive data stored in S3, producing findings rather than intercepting model responses. It is tempting because it identifies PII, but it operates on data at rest, not on Bedrock output. Guardrails for Amazon Bedrock applies sensitive-information filters that redact PII inline.

  • ✗

    Amazon SageMaker Model Monitor

    Why it's wrong here

    Model Monitor detects data drift and quality deviations in SageMaker endpoints; it does not sit in the Bedrock response path to redact PII. It is tempting for ongoing output oversight, but masking sensitive entities in generated text is performed by Guardrails for Amazon Bedrock, which applies content filters and sensitive-information policies.

  • ✓

    Amazon Bedrock Guardrails

    Why this is correct

    Amazon Bedrock Guardrails applies configurable sensitive-information filters that detect and automatically redact PII such as names, addresses and card numbers from model responses. This satisfies the requirement to prevent PII exposure in outputs without altering the underlying foundation model itself.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity and management events for auditing, and cannot inspect or alter model output content. It is tempting because it provides visibility into Bedrock invocations, but redaction of PII in responses requires Guardrails for Amazon Bedrock, which filters and masks sensitive content inline.

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.