AIF-C01 Guidelines for Responsible AI Practice Question
A startup uses Amazon Lex to build a chatbot for mental health support. They must ensure user conversations are private and not used for model improvement. Which AWS service can help anonymize text data before storage?
⚠ Common exam trap
Candidates often confuse data anonymization with data encryption (KMS) or data discovery (Macie), overlooking that Amazon Comprehend provides direct text-level redaction via its PII detection API.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon Comprehend
Amazon Comprehend offers a built-in feature called PII (Personally Identifiable Information) detection and redaction, which can automatically identify and mask sensitive data such as names, addresses, and health information in text. By using the `DetectPIIEntities` API with redaction, the startup can anonymize user conversations before storing them, ensuring compliance with privacy requirements and preventing data from being used for model improvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Textract
Why it's wrong here
Textract extracts text and form data from scanned documents; it neither detects nor removes personal identifiers from chat transcripts. It is tempting because it processes unstructured text, and would be correct for digitising uploaded documents rather than anonymising conversation data before it is stored.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
KMS manages encryption keys and envelope encryption; it does not detect or redact personally identifiable information within text. It is tempting because KMS protects data at rest, which supports privacy, but anonymisation requires a service such as Amazon Comprehend's PII detection before storage.
- ✓
Amazon Comprehend
Why this is correct
Amazon Comprehend provides detect-PII and entity-redaction capabilities that identify and mask personal information in text before it is persisted, satisfying the requirement that conversations remain private and unavailable for model improvement. Lex itself does not anonymise stored utterances.
- ✗
Amazon Macie
Why it's wrong here
Macie discovers and classifies sensitive data in S3, alerting on exposure; it does not redact or anonymise text before storage. It is tempting because it identifies personally identifiable information, and would be correct for auditing where sensitive data resides rather than scrubbing it in transit.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.