AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company uses Amazon Bedrock to generate content and wants to prevent the model from producing harmful or biased responses. Which AWS service should they configure to enforce content safety policies?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Bedrock Guardrails
Amazon Bedrock Guardrails provides content filtering, PII redaction, topic restrictions, and other safety controls. It is purpose-built for content safety in Bedrock.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Comprehend for toxicity detection
Why it's wrong here
Comprehend performs post-hoc text analytics such as sentiment and toxicity scoring; it cannot intercept or block Bedrock generations. Guardrails for Amazon Bedrock applies configurable content filters and denied topics directly to model input and output. Comprehend suits analysing stored documents or transcripts, not enforcing runtime safety policies.
- ✗
Amazon SageMaker Clarify
Why it's wrong here
SageMaker Clarify detects bias and explains model predictions during development; it does not intercept Bedrock inference to enforce runtime content safety. It is tempting because it addresses bias, but Guardrails for Amazon Bedrock is the service that filters harmful content at generation time.
- ✗
AWS WAF to filter model responses
Why it's wrong here
AWS WAF inspects HTTP requests at the web application layer, filtering traffic by IP, headers and URI patterns; it cannot parse generated text for harmful content. Bedrock Guardrails evaluates prompts and completions against content filters and denied topics. WAF is correct for shielding a public web application from exploits such as SQL injection.
- ✓
Amazon Bedrock Guardrails
Why this is correct
Guardrails applies configurable content filters and denied-topic policies directly to Bedrock model invocations, blocking harmful or biased output before it reaches the application. This satisfies the requirement to enforce content safety policies at inference time, which prompt engineering alone cannot guarantee.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.