Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A company wants to use a third-party foundation model from Amazon Bedrock but is concerned about data privacy because the model provider might store prompts and responses. How should they address this concern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the third-party model provider's data handling policy and choose a model that does not retain data

Each third-party model provider in Bedrock has its own data handling policies. Customers should review those policies and can choose models that do not store data or use Bedrock features like Guardrails to redact sensitive data. However, the direct action is to review the provider's policy and select a model that meets privacy requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Amazon Bedrock model invocation logging to capture all interactions

    Why it's wrong here

    Invocation logging writes prompts and responses to CloudWatch or S3, increasing exposure rather than preventing the provider from storing them. It is tempting for auditing, but the scenario requires disabling logging and confirming the model provider does not retain data.

  • ✓

    Review the third-party model provider's data handling policy and choose a model that does not retain data

    Why this is correct

    Data retention is governed by each third-party provider's own terms, not by Amazon Bedrock itself. Reviewing the provider's data handling policy and selecting a model whose terms guarantee no retention directly addresses the privacy concern.

  • ✗

    Use Amazon Macie to scan prompts before they are sent

    Why it's wrong here

    Macie discovers and classifies sensitive data in S3; it does not intercept or redact Bedrock prompts in transit. It is tempting as a data-privacy control, but the correct approach is disabling model invocation logging and using a Bedrock guardrail or private model deployment.

  • ✗

    Use AWS KMS to encrypt the prompts and responses before sending to the model

    Why it's wrong here

    KMS encrypts data at rest in AWS services; the model must decrypt prompts to process them, so ciphertext does not stop provider-side storage. KMS is correct for protecting stored artefacts, not for preventing a third-party model from retaining inference data.

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.