Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A company using Amazon Bedrock needs to redact personally identifiable information (PII) from user inputs before sending them to the foundation model. Which Bedrock Guardrails component should be configured?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitive information filters

PII redaction in Guardrails automatically detects and redacts PII in user inputs or model responses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Content filters

    Why it's wrong here

    Content filters detect and block harmful categories such as hate, violence or sexual content, not PII entities requiring redaction. They are tempting because they are the correct choice when the requirement is to filter toxic or unsafe material from inputs and outputs rather than to mask personal data.

  • ✗

    Topic restrictions

    Why it's wrong here

    Topic restrictions deny entire subject areas by classifying prompt intent, so they cannot identify or redact individual PII entities. They are tempting because they are the correct choice when the requirement is to prevent discussion of defined off-limits subjects rather than to remove sensitive data.

  • ✗

    Word filters

    Why it's wrong here

    Word filters block exact custom terms and profanity, matching literal strings rather than detecting PII patterns such as names, addresses or account numbers. They are tempting because custom deny lists are the correct choice when blocking specific banned words or phrases in prompts and responses.

  • ✓

    Sensitive information filters

    Why this is correct

    Sensitive information filters detect and redact PII such as names, addresses and credit card numbers in prompts, directly satisfying the requirement to remove personal data before it reaches the foundation model. Configuring these filters with appropriate PII entities and action set to Mask achieves the redaction.

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.