AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company using Amazon Bedrock needs to redact personally identifiable information (PII) from user inputs before sending them to the foundation model. Which Bedrock Guardrails component should be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitive information filters
PII redaction in Guardrails automatically detects and redacts PII in user inputs or model responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Content filters
Why it's wrong here
Content filters detect and block harmful categories such as hate, violence or sexual content, not PII entities requiring redaction. They are tempting because they are the correct choice when the requirement is to filter toxic or unsafe material from inputs and outputs rather than to mask personal data.
- ✗
Topic restrictions
Why it's wrong here
Topic restrictions deny entire subject areas by classifying prompt intent, so they cannot identify or redact individual PII entities. They are tempting because they are the correct choice when the requirement is to prevent discussion of defined off-limits subjects rather than to remove sensitive data.
- ✗
Word filters
Why it's wrong here
Word filters block exact custom terms and profanity, matching literal strings rather than detecting PII patterns such as names, addresses or account numbers. They are tempting because custom deny lists are the correct choice when blocking specific banned words or phrases in prompts and responses.
- ✓
Sensitive information filters
Why this is correct
Sensitive information filters detect and redact PII such as names, addresses and credit card numbers in prompts, directly satisfying the requirement to remove personal data before it reaches the foundation model. Configuring these filters with appropriate PII entities and action set to Mask achieves the redaction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.