Courseiva

AIF-C01 Fundamentals of Generative AI Practice Question

A team is deploying a generative AI model for medical report generation. They must ensure patient data privacy and comply with HIPAA. Which AWS service feature is essential for de-identifying protected health information (PHI) before sending data to a foundation model?

⚠ Common exam trap

It's easy for candidates to confuse general data protection services like Macie or encryption services like KMS with the specialized PHI de-identification capability of Amazon Comprehend Medical, assuming any security service can handle HIPAA compliance for generative AI workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon Comprehend Medical

Amazon Comprehend Medical is the correct service because it is specifically designed to extract and de-identify protected health information (PHI) from unstructured medical text using natural language processing (NLP). It can detect entities such as patient names, dates, and medical record numbers, and then redact or replace them before the data is sent to a foundation model, ensuring HIPAA compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    CloudHSM provides dedicated hardware security modules for key storage and cryptographic operations, not detection or masking of PHI within text. It is tempting because HIPAA compliance demands strong key custody, and CloudHSM is correct where regulatory mandates single-tenant FIPS 140-2 Level 3 key protection.

  • ✓

    Amazon Comprehend Medical

    Why this is correct

    Amazon Comprehend Medical provides dedicated PHI detection and de-identification through its DetectPHI API, identifying 18 HIPAA-defined identifier categories such as names, dates and medical record numbers. This satisfies the stem's requirement to strip protected health information before the data reaches any foundation model, unlike generic NLP services lacking healthcare-specific entity recognition.

  • ✗

    Amazon Macie

    Why it's wrong here

    Macie discovers and classifies sensitive data such as PHI in S3, alerting on exposure; it does not redact or mask identified elements before inference. It is tempting because Macie is the correct choice when the requirement is to find where PHI resides and flag unsecured buckets, rather than transform it.

  • ✗

    AWS Key Management Service (AWS KMS)

    Why it's wrong here

    KMS manages encryption keys, not de-identification.

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.