AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company runs a Retrieval Augmented Generation (RAG) application on Amazon Bedrock. The application uses an Amazon OpenSearch Serverless vector index to store internal HR documents. The security team must ensure that the vector index is encrypted at rest with a customer-managed AWS KMS key so that they can control key rotation and revoke access independently. Which configuration should they implement?
⚠ Common exam trap
The trap here is assuming that encrypting the source documents in Amazon S3 also encrypts the derived vector index or that the encryption key can be swapped after the collection exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a customer managed KMS key and associate it with the OpenSearch Serverless collection at creation time using the encryption policy.
A customer managed KMS key must be specified in the OpenSearch Serverless encryption policy when the collection is created, because the encryption key cannot be changed after creation. This gives the security team control over rotation and the ability to revoke access by disabling the key. Encrypting source documents or using private connectivity does not encrypt the vector index at rest with a customer managed key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the OpenSearch Serverless collection with an AWS owned key and enable automatic key rotation in AWS KMS.
Why it's wrong here
AWS owned keys are managed entirely by AWS and cannot be viewed, rotated, or revoked by the customer. Automatic key rotation is only available for customer managed keys. This option would not give the security team the required control over rotation or the ability to revoke access to the vector index data independently, so it does not meet the scenario's requirement for a customer managed key.
- ✗
Enable Amazon S3 default encryption with SSE-KMS on the bucket that stores the source documents, then rebuild the vector index.
Why it's wrong here
Encrypting the source documents in Amazon S3 does not encrypt the OpenSearch Serverless vector index that stores the embeddings. The vector index is a separate data store and requires its own encryption configuration. Rebuilding the index from encrypted documents would still leave the index itself encrypted with an AWS owned key by default, so the security team would not gain the required customer managed key control.
- ✗
Use AWS PrivateLink to connect to the OpenSearch Serverless collection and rely on TLS in transit for data protection.
Why it's wrong here
AWS PrivateLink and TLS provide protection for data in transit, not data at rest. The scenario explicitly requires encryption at rest with a customer managed KMS key. While private connectivity is a good security practice, it does not address the key management and revocation requirements described. Therefore, this option does not fulfill the encryption-at-rest control that the security team needs.
- ✓
Create a customer managed KMS key and associate it with the OpenSearch Serverless collection at creation time using the encryption policy.
Why this is correct
OpenSearch Serverless supports specifying a customer managed AWS KMS key in the collection's encryption policy at creation. This key encrypts the vector index at rest and allows the security team to manage rotation and revoke access by disabling or deleting the key. This directly satisfies the requirement for customer-controlled encryption of the vector store used by the RAG application.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.