Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A financial services company is using Amazon Bedrock to generate personalized investment advice. The compliance team requires that the model's responses do not contain any personally identifiable information (PII) such as account numbers or social security numbers, and that all PII is automatically masked. Which AWS service or feature should the company use to meet this requirement?

⚠ Common exam trap

Watch out — candidates often confuse data discovery services like Amazon Macie with runtime content filtering features like Bedrock Guardrails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Bedrock Guardrails

Amazon Bedrock Guardrails provides configurable safeguards that can detect and mask sensitive information like PII in both prompts and responses. By defining a sensitive information filter, the company can ensure that account numbers and social security numbers are automatically redacted from the model's output. This is the only option that directly addresses real-time content filtering and masking within the generative AI application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Macie

    Why it's wrong here

    Amazon Macie is a data security service that discovers and protects sensitive data stored in Amazon S3. It can identify PII in S3 buckets but does not provide real-time masking of model responses. Macie is used for data discovery and classification, not for inline content filtering of generative AI outputs. Therefore, it cannot enforce the requirement to mask PII in Bedrock responses.

  • ✓

    Amazon Bedrock Guardrails

    Why this is correct

    Amazon Bedrock Guardrails allows you to define policies that filter and mask sensitive information in model inputs and outputs. You can configure sensitive information filters to detect and redact PII such as account numbers and social security numbers. This directly meets the compliance requirement by preventing PII from appearing in responses and automatically masking it in real time.

  • ✗

    AWS Identity and Access Management (IAM) policies

    Why it's wrong here

    IAM policies control access to AWS resources and actions, such as who can invoke a Bedrock model. They do not inspect or modify the content of model responses. While IAM is essential for security, it cannot detect or mask PII within the generated text. Thus, it does not satisfy the requirement to automatically mask PII in responses.

  • ✗

    Amazon SageMaker Model Monitor

    Why it's wrong here

    SageMaker Model Monitor is used to monitor the quality of machine learning models in production, detecting data drift and anomalies. It does not provide content filtering or PII masking for generative AI outputs. It operates on model predictions and data distributions, not on the textual content of responses from Bedrock. Therefore, it is not suitable for this scenario.

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.