AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A financial services firm uses Amazon Bedrock to generate investment summaries. They need to prevent the model from generating content containing personally identifiable information (PII) such as social security numbers. Which feature should they configure in Bedrock Guardrails?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitive information filters with PII redaction
Bedrock Guardrails include a PII redaction filter that can detect and block or mask PII in model inputs and outputs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contextual grounding checks
Why it's wrong here
Contextual grounding checks verify responses against a supplied source and query, detecting hallucination; they do not detect or redact PII patterns. It is tempting because grounding improves factual accuracy, and would be correct when answers must be traceable to reference documents rather than filtered for sensitive data.
- ✗
Content filtering with category-based harmful content filters
Why it's wrong here
Category-based harmful content filters target hate, violence, sexual and insulting content, not PII patterns such as social security numbers. It is tempting because content filters are the headline guardrail feature, and would be correct when blocking toxic or harmful generated text rather than sensitive data.
- ✓
Sensitive information filters with PII redaction
Why this is correct
Sensitive information filters detect and redact personally identifiable information, matching the stem's requirement to block social security numbers in generated summaries. Bedrock Guardrails applies these filters to both prompts and responses, so PII is caught before reaching users. Unlike content filters, which target harmful categories such as hate or violence, this mechanism specifically addresses data privacy.
- ✗
Word filters with a custom list of terms
Why it's wrong here
Word filters match literal custom terms, so they cannot recognise the variable digit patterns of social security numbers. It is tempting because custom lists are simple to configure, and would be correct when blocking specific banned words or competitor names rather than structured PII.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.