Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A media company must give an external analytics vendor temporary, auditable access to a curated S3 dataset used for fine-tuning a model. The vendor works from its own AWS account, and the company's security policy forbids sharing long-term IAM credentials. Which approach best meets the policy while keeping access auditable?

⚠ Common exam trap

The trap here is treating time-limited presigned URLs or rotated access keys as equivalent to temporary role-based credentials, when only role assumption avoids sharing secrets and preserves clear identity attribution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a cross-account IAM role in the company account that the vendor assumes using AWS Security Token Service, with an external ID condition.

Cross-account IAM roles with AWS Security Token Service temporary credentials are the standard way to grant a partner access without exchanging secrets. The external ID prevents the confused deputy problem, and separate role assumption produces clean CloudTrail attribution. Presigned URLs, rotated IAM user keys, and CDN-signed access all either share secrets or obscure who actually accessed the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a presigned URL for each S3 object and email the URLs to the vendor on a weekly schedule.

    Why it's wrong here

    Presigned URLs grant time-limited access to individual objects, but distributing them by email spreads bearer tokens that anyone holding the link can use. Auditing becomes difficult because requests appear as the signing identity rather than the vendor, and managing hundreds of objects this way is error prone. The approach also lacks the identity-level control the policy demands.

  • ✓

    Configure a cross-account IAM role in the company account that the vendor assumes using AWS Security Token Service, with an external ID condition.

    Why this is correct

    A cross-account role lets the vendor's own principals call AssumeRole and receive temporary credentials, so no long-term secrets are shared. The external ID condition guards against the confused deputy problem, and because the vendor assumes a distinct role, CloudTrail records its activity separately. This satisfies both the no-shared-credentials policy and the auditability requirement.

  • ✗

    Enable S3 Block Public Access and place the dataset behind an Amazon CloudFront signed cookie distribution.

    Why it's wrong here

    Block Public Access and CloudFront signed cookies protect content delivery to end users, but CloudFront is designed for HTTP content distribution, not granting a partner programmatic access to an S3 dataset. The vendor would still need underlying credentials or keys, so the policy against shared credentials is not satisfied, and access logs reflect edge requests rather than vendor identity.

  • ✗

    Create an IAM user in the company account for the vendor and rotate the access keys every 24 hours with a script.

    Why it's wrong here

    Long-lived IAM users with rotated keys still violate a policy that forbids sharing credentials, because the vendor holds secrets tied to an identity in the company account. Rotation reduces but does not eliminate exposure, and the vendor's actions appear as a company identity, muddying attribution. This approach also scales poorly and is explicitly the pattern the policy rejects.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.