AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company uses Amazon Bedrock with a third-party foundation model. They are concerned about the third-party provider accessing their data. What should they review to understand data handling practices?
⚠ Common exam trap
AIF-C01 often tests the misconception that AWS Artifact or CloudTrail covers third-party model data practices, when in fact the model provider's own documentation is the correct source under the shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The third-party model provider's data privacy and handling documentation within AWS Bedrock's service description
When using a third-party foundation model through Amazon Bedrock, the model provider's own data privacy and handling documentation — surfaced within the Bedrock service description and model details — is the authoritative source for how that provider treats your prompts, completions, and any fine-tuning data. AWS's shared responsibility model means AWS secures the Bedrock infrastructure, but the third-party model provider defines its own data usage terms. Reviewing that documentation tells you whether inputs are used for training, how long they are retained, and what regional or contractual safeguards apply.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Artifact reports for SOC and PCI compliance
Why it's wrong here
AWS Artifact supplies AWS's own compliance reports, covering AWS infrastructure controls rather than the third-party foundation model provider's data handling terms. It is tempting because Artifact is the standard source for SOC and PCI evidence, and would be correct when auditing AWS's shared-responsibility security posture rather than a model provider's practices.
- ✗
AWS CloudTrail logs for model invocation
Why it's wrong here
CloudTrail records API calls made against Bedrock, capturing who invoked which model and when, but it does not document the third-party provider's data handling, retention or training-use terms. It is tempting because CloudTrail is the standard tool for auditing access to AWS resources, and would be correct for investigating suspicious invocations or tracking usage.
- ✓
The third-party model provider's data privacy and handling documentation within AWS Bedrock's service description
Why this is correct
Reviewing the third-party provider's privacy and handling documentation within the AWS Bedrock service description reveals whether prompts, completions, or fine-tuning data are retained, logged, or used for model training. This directly addresses the stem's constraint: understanding the provider's data handling practices and whether they can access company data.
- ✗
Amazon SageMaker Model Registry metadata
Why it's wrong here
SageMaker Model Registry stores model versions, approval status and lineage metadata; it holds no information about a third-party Bedrock provider's handling of prompts or outputs. It is tempting because registries are the go-to place for model governance artefacts, and would be correct when tracking model approval workflows or deployment lineage across a SageMaker estate.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.