Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A company runs a Retrieval Augmented Generation (RAG) application on Amazon Bedrock. The application uses an Amazon OpenSearch Serverless vector index to store internal HR documents. The security team must ensure that the vector index is encrypted at rest with a customer-managed AWS KMS key so that they can control key rotation and revoke access independently. Which configuration should they implement?

⚠ Common exam trap

The trap here is assuming that encrypting the source documents in Amazon S3 also encrypts the derived vector index or that the encryption key can be swapped after the collection exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a customer managed KMS key and associate it with the OpenSearch Serverless collection at creation time using the encryption policy.

A customer managed KMS key must be specified in the OpenSearch Serverless encryption policy when the collection is created, because the encryption key cannot be changed after creation. This gives the security team control over rotation and the ability to revoke access by disabling the key. Encrypting source documents or using private connectivity does not encrypt the vector index at rest with a customer managed key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the OpenSearch Serverless collection with an AWS owned key and enable automatic key rotation in AWS KMS.

    Why it's wrong here

    AWS owned keys are managed entirely by AWS and cannot be viewed, rotated, or revoked by the customer. Automatic key rotation is only available for customer managed keys. This option would not give the security team the required control over rotation or the ability to revoke access to the vector index data independently, so it does not meet the scenario's requirement for a customer managed key.

  • ✗

    Enable Amazon S3 default encryption with SSE-KMS on the bucket that stores the source documents, then rebuild the vector index.

    Why it's wrong here

    Encrypting the source documents in Amazon S3 does not encrypt the OpenSearch Serverless vector index that stores the embeddings. The vector index is a separate data store and requires its own encryption configuration. Rebuilding the index from encrypted documents would still leave the index itself encrypted with an AWS owned key by default, so the security team would not gain the required customer managed key control.

  • ✗

    Use AWS PrivateLink to connect to the OpenSearch Serverless collection and rely on TLS in transit for data protection.

    Why it's wrong here

    AWS PrivateLink and TLS provide protection for data in transit, not data at rest. The scenario explicitly requires encryption at rest with a customer managed KMS key. While private connectivity is a good security practice, it does not address the key management and revocation requirements described. Therefore, this option does not fulfill the encryption-at-rest control that the security team needs.

  • ✓

    Create a customer managed KMS key and associate it with the OpenSearch Serverless collection at creation time using the encryption policy.

    Why this is correct

    OpenSearch Serverless supports specifying a customer managed AWS KMS key in the collection's encryption policy at creation. This key encrypts the vector index at rest and allows the security team to manage rotation and revoke access by disabling or deleting the key. This directly satisfies the requirement for customer-controlled encryption of the vector store used by the RAG application.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.