Courseiva

AIF-C01 Applications of Foundation Models Practice Question

A healthcare company needs to use a foundation model for analyzing medical records while complying with HIPAA. They plan to use Amazon Bedrock. What should they do to meet HIPAA requirements?

⚠ Common exam trap

The trap here is that candidates often pick a single security control (like encryption or logging) thinking it alone ensures HIPAA compliance, but the exam tests that HIPAA requires a combination of administrative, physical, and technical safeguards, all of which must be addressed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All of the above

HIPAA compliance in Amazon Bedrock requires a combination of controls: using a HIPAA-eligible model in a region where AWS offers a Business Associate Addendum (BAA), enabling access logging for auditability, and encrypting data at rest and in transit. None of the individual options alone satisfy all HIPAA requirements; only the full set of controls ensures compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a model that is HIPAA eligible in a region that supports BAA

    Why it's wrong here

    Amazon Bedrock does not itself confer HIPAA compliance; the BAA must be executed with AWS, and only specific models are covered. Choosing a HIPAA-eligible model in a BAA-supported region is necessary but insufficient alone — the customer must also request the BAA and configure logging, encryption and access controls. It is tempting because region and model eligibility are genuine prerequisites, but they do not by themselves satisfy the requirement.

  • ✗

    Implement access logging for all API calls

    Why it's wrong here

    Access logging records who called which API, but HIPAA compliance for Bedrock rests on signing a Business Associate Addendum and using HIPAA-eligible models in supported regions. Logging alone leaves the BAA gap. It is tempting because CloudTrail auditing is a real security control, yet it addresses traceability, not the contractual eligibility requirement.

  • ✗

    Encrypt data at rest and in transit

    Why it's wrong here

    Encryption at rest and in transit is already applied by Bedrock by default, so it adds nothing toward the HIPAA requirement. It is tempting because encryption is a familiar compliance checkbox, but the scenario's unmet need is a signed BAA plus a HIPAA-eligible model in a supported region.

  • ✓

    All of the above

    Why this is correct

    Bedrock's HIPAA eligibility requires a signed AWS Business Associate Addendum, use of HIPAA-eligible models, and no PHI in non-eligible services. Selecting all of the above satisfies the stem's compliance requirement, since each measure is mandatory rather than optional.

About these practice questions

Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.