hardMultiple Choice
AIF-C01 Practice Question: A financial services company is deploying a…
A financial services company is deploying a generative AI application using Amazon Bedrock. They need to ensure that the model does not generate responses containing personally identifiable information (PII) such as credit card numbers or Social Security numbers. The company also wants to block certain topics like investment advice. Which feature should they configure?
⚠ Common exam trap
The AWS AI Practitioner exam often tests the distinction between security services that protect data at rest (Macie) or at the network layer (WAF) versus those that control content generation at the application layer (Guardrails), leading candidates to confuse data discovery with real-time content filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Bedrock Guardrails
Amazon Bedrock Guardrails is the correct feature because it provides configurable safeguards to filter and block undesirable content in foundation model responses, including PII (e.g., credit card numbers, Social Security numbers) and specific topics like investment advice. It operates at the application layer within Bedrock, allowing you to define denied topics and sensitive information filters that are enforced during inference, without requiring separate infrastructure or manual post-processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF
Why it's wrong here
AWS WAF filters HTTP requests at the edge against IP reputation and web exploit signatures; it cannot parse model completions for PII or investment-advice topics. It is tempting as a content control, but it belongs in front of web traffic, not inside Bedrock's guardrail evaluation.
- ✗
Amazon Macie
Why it's wrong here
Macie discovers and classifies sensitive data held in S3 buckets; it cannot inspect Bedrock prompt or completion traffic, so it never sees generated PII or topics. It is tempting because it does detect credit card and Social Security numbers, but only at rest in storage, not in model responses.
- ✓
Amazon Bedrock Guardrails
Why this is correct
Amazon Bedrock Guardrails applies configurable content filters, including sensitive-information filters that detect and block PII such as credit card and Social Security numbers, plus denied-topics policies that refuse investment advice, satisfying both constraints in one feature.
- ✗
AWS Identity and Access Management (IAM) policies
Why it's wrong here
IAM policies govern which principals may invoke models and resources, not what the model outputs; they cannot detect generated credit card numbers or block investment-advice topics. They are tempting because they enforce access control, which is the right tool for restricting who calls Bedrock, not for content filtering.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.