AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A media company must give an external analytics vendor temporary, auditable access to a curated S3 dataset used for fine-tuning a model. The vendor works from its own AWS account, and the company's security policy forbids sharing long-term IAM credentials. Which approach best meets the policy while keeping access auditable?
⚠ Common exam trap
The trap here is treating time-limited presigned URLs or rotated access keys as equivalent to temporary role-based credentials, when only role assumption avoids sharing secrets and preserves clear identity attribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a cross-account IAM role in the company account that the vendor assumes using AWS Security Token Service, with an external ID condition.
Cross-account IAM roles with AWS Security Token Service temporary credentials are the standard way to grant a partner access without exchanging secrets. The external ID prevents the confused deputy problem, and separate role assumption produces clean CloudTrail attribution. Presigned URLs, rotated IAM user keys, and CDN-signed access all either share secrets or obscure who actually accessed the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Generate a presigned URL for each S3 object and email the URLs to the vendor on a weekly schedule.
Why it's wrong here
Presigned URLs grant time-limited access to individual objects, but distributing them by email spreads bearer tokens that anyone holding the link can use. Auditing becomes difficult because requests appear as the signing identity rather than the vendor, and managing hundreds of objects this way is error prone. The approach also lacks the identity-level control the policy demands.
- ✓
Configure a cross-account IAM role in the company account that the vendor assumes using AWS Security Token Service, with an external ID condition.
Why this is correct
A cross-account role lets the vendor's own principals call AssumeRole and receive temporary credentials, so no long-term secrets are shared. The external ID condition guards against the confused deputy problem, and because the vendor assumes a distinct role, CloudTrail records its activity separately. This satisfies both the no-shared-credentials policy and the auditability requirement.
- ✗
Enable S3 Block Public Access and place the dataset behind an Amazon CloudFront signed cookie distribution.
Why it's wrong here
Block Public Access and CloudFront signed cookies protect content delivery to end users, but CloudFront is designed for HTTP content distribution, not granting a partner programmatic access to an S3 dataset. The vendor would still need underlying credentials or keys, so the policy against shared credentials is not satisfied, and access logs reflect edge requests rather than vendor identity.
- ✗
Create an IAM user in the company account for the vendor and rotate the access keys every 24 hours with a script.
Why it's wrong here
Long-lived IAM users with rotated keys still violate a policy that forbids sharing credentials, because the vendor holds secrets tied to an identity in the company account. Rotation reduces but does not eliminate exposure, and the vendor's actions appear as a company identity, muddying attribution. This approach also scales poorly and is explicitly the pattern the policy rejects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.