Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A company is using Amazon Bedrock to power a chatbot that provides customer support. The security team wants to ensure that the chatbot does not generate responses that include profanity, hate speech, or prompts that attempt to bypass safety filters (jailbreak attempts). They also want to log any blocked interactions for review. Which AWS service or feature should be used to meet these requirements?

⚠ Common exam trap

The trap here is thinking that general-purpose security services like AWS WAF or content analysis services like Comprehend can moderate generative AI outputs, when they lack the specific filters for profanity and jailbreak detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Bedrock Guardrails with content filters and prompt attack detection, and enable model invocation logging to capture blocked interactions.

The requirements are to block harmful content and jailbreak attempts in a Bedrock-powered chatbot, and to log blocked interactions. Amazon Bedrock Guardrails offers content filters for profanity, hate speech, and more, plus prompt attack detection. Enabling model invocation logging captures all interactions, including those blocked by Guardrails, for later review. This is a managed solution that directly addresses the needs without custom development.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon Bedrock Guardrails with content filters and prompt attack detection, and enable model invocation logging to capture blocked interactions.

    Why this is correct

    Amazon Bedrock Guardrails provides configurable content filters to block hate speech, profanity, and other harmful content. It also includes prompt attack detection to identify jailbreak attempts. When model invocation logging is enabled, Bedrock logs the full request and response, including blocked interactions, allowing for review. This native integration meets all requirements without custom code.

  • ✗

    Amazon Comprehend for sentiment analysis and Amazon Macie for detecting sensitive data, with alerts sent to Amazon SNS.

    Why it's wrong here

    Amazon Comprehend analyzes sentiment and entities but does not filter profanity or hate speech in generated text. Macie discovers sensitive data in S3, not in real-time model responses. Neither service provides prompt attack detection or integrates with Bedrock to block harmful content. This combination does not meet the requirements for content moderation.

  • ✗

    Amazon SageMaker Clarify for bias detection and Amazon Augmented AI (A2I) for human review, with results logged to Amazon S3.

    Why it's wrong here

    SageMaker Clarify detects bias in datasets and models, not profanity or hate speech in generated responses. A2I is for human review of predictions, which introduces latency and operational overhead. This solution does not provide automated content filtering or prompt attack detection, and it is not integrated with Bedrock for real-time moderation.

  • ✗

    AWS WAF with managed rules for bot control and a custom Lambda function to inspect responses for profanity, logging to Amazon CloudWatch.

    Why it's wrong here

    AWS WAF operates at the HTTP layer and can block malicious traffic, but it cannot inspect the content of model responses for profanity or hate speech. A custom Lambda function would require significant development and maintenance, and would not natively integrate with Bedrock for prompt attack detection. This approach is not designed for generative AI safety.

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.