AIF-C01 Guidelines for Responsible AI Practice Question
A healthcare company must train a model on sensitive patient data while complying with privacy regulations. They want to add noise to the training process to prevent re-identification. Which technique should they implement?
⚠ Common exam trap
AWS often tests the misconception that federated learning alone provides privacy guarantees, but the trap here is that federated learning only addresses data locality, not re-identification resistance, which requires a formal privacy technique like differential privacy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Differential privacy
Differential privacy is the correct technique because it adds calibrated noise to the training process (e.g., via gradient clipping and noise injection in stochastic gradient descent) to ensure that the model's outputs do not reveal whether any individual's data was included in the training set. This provides a formal mathematical guarantee (ε-differential privacy) that limits the risk of re-identification, which is essential for complying with privacy regulations like HIPAA or GDPR when training on sensitive patient data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Differential privacy
Why this is correct
Differential privacy injects calibrated statistical noise into training or query outputs, bounding any single patient's influence on the model. This mathematically limits re-identification risk while preserving aggregate utility, satisfying privacy regulations when training on sensitive patient records.
- ✗
k-anonymity
Why it's wrong here
k-anonymity generalises or suppresses quasi-identifiers so each record matches at least k others; it alters the dataset rather than injecting calibrated noise into training. It is the right choice when releasing tabular data and you must prevent singling out individuals.
- ✗
Federated learning
Why it's wrong here
Federated learning keeps data on local devices and shares only model updates, so raw records never centralise; it adds no noise to the training process itself. It is the right choice when data cannot leave its source but you still need a shared model.
- ✗
Homomorphic encryption
Why it's wrong here
Homomorphic encryption permits computation on ciphertext without decrypting it, so it protects data in use but adds no noise and cannot prevent re-identification. It is tempting because it genuinely enables privacy-preserving analysis, and would be the right choice when a third party must compute on encrypted records without ever seeing plaintext.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.