Courseiva
hardMultiple ChoiceObjective-mapped

AIF-C01 Practice Question: A financial services firm needs an LLM-powered…

A financial services firm needs an LLM-powered application that analyzes customer transaction data and generates compliance reports. The data contains personally identifiable information (PII). The firm must ensure that no training data includes PII, and that the LLM never outputs PII. Which combination of AWS services and practices should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a pre-trained foundation model via Amazon Bedrock with a system prompt that instructs the model not to output PII, and enable Bedrock’s data protection

Using Amazon Bedrock with a pre-trained foundation model (no fine-tuning) ensures PII is not in training data. A system prompt instructing the model to avoid PII, combined with Bedrock’s built-in data protection, prevents PII in outputs. Fine-tuning or RAG with sensitive data would risk exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use RAG to retrieve transaction data from a vector database and include it in the prompt to the LLM

    Why it's wrong here

    RAG would include raw transaction data (containing PII) in the prompt, exposing PII to the model and potentially in outputs.

  • Fine-tune an Amazon Titan model on the transaction data after masking PII, then use the fine-tuned model for inference

    Why it's wrong here

    Even masked PII may be memorized; fine-tuning on sensitive data increases risk of data leakage.

  • Host the model on Amazon SageMaker and apply differential privacy during training

    Why it's wrong here

    Differential privacy can help but is complex; training on PII still poses risk. A pre-trained model avoids training on sensitive data altogether.

  • Use a pre-trained foundation model via Amazon Bedrock with a system prompt that instructs the model not to output PII, and enable Bedrock’s data protection

    Why this is correct

    Pre-trained model avoids PII in training; system prompt and data protection guardrails prevent PII in outputs.

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 619 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.