Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A company uses Amazon Bedrock with a third-party foundation model. They are concerned about the third-party provider accessing their data. What should they review to understand data handling practices?

⚠ Common exam trap

AIF-C01 often tests the misconception that AWS Artifact or CloudTrail covers third-party model data practices, when in fact the model provider's own documentation is the correct source under the shared responsibility model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The third-party model provider's data privacy and handling documentation within AWS Bedrock's service description

When using a third-party foundation model through Amazon Bedrock, the model provider's own data privacy and handling documentation — surfaced within the Bedrock service description and model details — is the authoritative source for how that provider treats your prompts, completions, and any fine-tuning data. AWS's shared responsibility model means AWS secures the Bedrock infrastructure, but the third-party model provider defines its own data usage terms. Reviewing that documentation tells you whether inputs are used for training, how long they are retained, and what regional or contractual safeguards apply.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Artifact reports for SOC and PCI compliance

    Why it's wrong here

    AWS Artifact supplies AWS's own compliance reports, covering AWS infrastructure controls rather than the third-party foundation model provider's data handling terms. It is tempting because Artifact is the standard source for SOC and PCI evidence, and would be correct when auditing AWS's shared-responsibility security posture rather than a model provider's practices.

  • ✗

    AWS CloudTrail logs for model invocation

    Why it's wrong here

    CloudTrail records API calls made against Bedrock, capturing who invoked which model and when, but it does not document the third-party provider's data handling, retention or training-use terms. It is tempting because CloudTrail is the standard tool for auditing access to AWS resources, and would be correct for investigating suspicious invocations or tracking usage.

  • ✓

    The third-party model provider's data privacy and handling documentation within AWS Bedrock's service description

    Why this is correct

    Reviewing the third-party provider's privacy and handling documentation within the AWS Bedrock service description reveals whether prompts, completions, or fine-tuning data are retained, logged, or used for model training. This directly addresses the stem's constraint: understanding the provider's data handling practices and whether they can access company data.

  • ✗

    Amazon SageMaker Model Registry metadata

    Why it's wrong here

    SageMaker Model Registry stores model versions, approval status and lineage metadata; it holds no information about a third-party Bedrock provider's handling of prompts or outputs. It is tempting because registries are the go-to place for model governance artefacts, and would be correct when tracking model approval workflows or deployment lineage across a SageMaker estate.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.