AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company wants to use a third-party foundation model from Amazon Bedrock but is concerned about data privacy because the model provider might store prompts and responses. How should they address this concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the third-party model provider's data handling policy and choose a model that does not retain data
Each third-party model provider in Bedrock has its own data handling policies. Customers should review those policies and can choose models that do not store data or use Bedrock features like Guardrails to redact sensitive data. However, the direct action is to review the provider's policy and select a model that meets privacy requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Amazon Bedrock model invocation logging to capture all interactions
Why it's wrong here
Invocation logging writes prompts and responses to CloudWatch or S3, increasing exposure rather than preventing the provider from storing them. It is tempting for auditing, but the scenario requires disabling logging and confirming the model provider does not retain data.
- ✓
Review the third-party model provider's data handling policy and choose a model that does not retain data
Why this is correct
Data retention is governed by each third-party provider's own terms, not by Amazon Bedrock itself. Reviewing the provider's data handling policy and selecting a model whose terms guarantee no retention directly addresses the privacy concern.
- ✗
Use Amazon Macie to scan prompts before they are sent
Why it's wrong here
Macie discovers and classifies sensitive data in S3; it does not intercept or redact Bedrock prompts in transit. It is tempting as a data-privacy control, but the correct approach is disabling model invocation logging and using a Bedrock guardrail or private model deployment.
- ✗
Use AWS KMS to encrypt the prompts and responses before sending to the model
Why it's wrong here
KMS encrypts data at rest in AWS services; the model must decrypt prompts to process them, so ciphertext does not stop provider-side storage. KMS is correct for protecting stored artefacts, not for preventing a third-party model from retaining inference data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.