Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A government agency trains models on highly sensitive data inside Amazon SageMaker. The security policy states that training data and model artifacts must never be accessible over the public internet and that traffic to AWS services must stay within the agency's Amazon VPC. Which combination should the agency implement?

⚠ Common exam trap

The trap here is assuming that IAM restrictions or IP-based bucket policies provide network isolation, when only disabling container networking and using private endpoints actually remove public internet paths.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run training jobs with network isolation enabled and access AWS services through VPC interface endpoints powered by AWS PrivateLink.

The policy has two distinct demands: no public internet access from the training environment and private connectivity to AWS services. Network isolation removes outbound network access entirely, and VPC interface endpoints route service calls over private addresses. IP conditions, NAT-routed public subnets, and IAM-only controls each address authorization or partial routing rather than the complete private-path requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the training job in a public subnet with a NAT gateway and restrict security group egress to AWS service prefix lists.

    Why it's wrong here

    A public subnet with a NAT gateway routes traffic through an internet gateway, which contradicts a policy that forbids public internet paths. Prefix list egress rules narrow destinations but do not make the path private. The architecture still depends on public routing, so it fails the requirement even though the security group is restrictive.

  • ✗

    Attach an S3 bucket policy that denies requests where aws:SourceIp is outside the agency CIDR range and enable default encryption.

    Why it's wrong here

    An IP condition can restrict access to agency addresses, but traffic still traverses public AWS endpoints unless private connectivity exists, and the policy does not isolate the training container's outbound network. Encryption at rest protects stored objects but says nothing about network paths. The combination therefore does not guarantee that data never crosses the public internet.

  • ✗

    Use SageMaker Studio in a private subnet and rely on AWS Identity and Access Management policies to deny access to non-approved services.

    Why it's wrong here

    IAM policies control which API actions identities may call, not the network path those calls take. Running Studio in a private subnet is helpful, but without VPC endpoints the traffic still exits to public service endpoints, and training containers remain able to reach the internet. Authorization alone cannot satisfy a network isolation requirement.

  • ✓

    Run training jobs with network isolation enabled and access AWS services through VPC interface endpoints powered by AWS PrivateLink.

    Why this is correct

    Network isolation disables outbound network access from the training container, preventing data exfiltration over the internet. VPC interface endpoints keep calls to services such as Amazon S3 and SageMaker on private IP addresses inside the VPC. Together they satisfy both halves of the policy without exposing data or control traffic to public routes.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.