Courseiva

CCNA Security, Compliance, and Governance for AI Solutions Questions

56 questions · Security, Compliance, and Governance for AI Solutions · All types, answers revealed

1
MCQeasy

A machine learning engineer wants to detect if sensitive data, such as personally identifiable information (PII), exists in a training dataset stored in S3 before training a model. Which AWS service should they use?

A.Amazon Inspector
B.Amazon Macie
C.Amazon GuardDuty
D.AWS Config
AnswerB

Macie uses managed data identifiers and pattern matching to scan S3 objects and report PII such as names, addresses and credit card numbers. It satisfies the requirement to detect sensitive data in the training dataset before training begins, without modifying the data.

Why this answer

Amazon Macie uses machine learning to automatically discover, classify, and protect sensitive data in S3 buckets.

2
MCQmedium

A company wants to use Amazon Bedrock to generate responses grounded in their proprietary knowledge base. They need to minimize hallucinations and ensure responses are based on the provided documents. Which feature should they enable?

A.Topic restrictions
B.Word filters
C.Grounding check
D.Content filters
AnswerC

Grounding check measures whether each response is supported by the retrieved source passages, flagging or filtering ungrounded statements. This directly reduces hallucination by tying outputs to the proprietary knowledge base documents rather than model memory.

Why this answer

Grounding check in Bedrock Guardrails verifies that the model's response is supported by the source documents, reducing hallucinations.

3
MCQhard

A company has trained a model using Amazon SageMaker and stored the model artifacts in S3 with SSE-KMS encryption. The development team wants to grant cross-account access to the model artifacts so a partner can deploy the model in their own account. Which steps are required?

A.Create a new IAM role in the partner account with S3 read permissions
B.Create an S3 bucket policy allowing the partner account to read the objects, and ensure the KMS key policy allows the partner account to use the key
C.Use AWS Lake Formation to share the data
D.Copy the model artifacts to a public S3 bucket
AnswerB

Cross-account access requires permissions at both layers: the S3 bucket policy grants the partner account read access to the objects, while the SSE-KMS key policy must separately allow that account to decrypt using the customer managed key. Missing either blocks access.

Why this answer

To share SSE-KMS encrypted objects cross-account, you must grant the partner account access to both the S3 object (via bucket policy) and the KMS key (via key policy). The partner must also have the correct IAM permissions.

4
MCQmedium

A company runs a Retrieval Augmented Generation (RAG) application on Amazon Bedrock. The application uses an Amazon OpenSearch Serverless vector index to store internal HR documents. The security team must ensure that the vector index is encrypted at rest with a customer-managed AWS KMS key so that they can control key rotation and revoke access independently. Which configuration should they implement?

A.Configure the OpenSearch Serverless collection with an AWS owned key and enable automatic key rotation in AWS KMS.
B.Enable Amazon S3 default encryption with SSE-KMS on the bucket that stores the source documents, then rebuild the vector index.
C.Use AWS PrivateLink to connect to the OpenSearch Serverless collection and rely on TLS in transit for data protection.
D.Create a customer managed KMS key and associate it with the OpenSearch Serverless collection at creation time using the encryption policy.
AnswerD

OpenSearch Serverless supports specifying a customer managed AWS KMS key in the collection's encryption policy at creation. This key encrypts the vector index at rest and allows the security team to manage rotation and revoke access by disabling or deleting the key. This directly satisfies the requirement for customer-controlled encryption of the vector store used by the RAG application.

Why this answer

A customer managed KMS key must be specified in the OpenSearch Serverless encryption policy when the collection is created, because the encryption key cannot be changed after creation. This gives the security team control over rotation and the ability to revoke access by disabling the key. Encrypting source documents or using private connectivity does not encrypt the vector index at rest with a customer managed key.

Exam trap

The trap here is assuming that encrypting the source documents in Amazon S3 also encrypts the derived vector index or that the encryption key can be swapped after the collection exists.

5
MCQeasy

An organization wants to control which topics their AI chatbot can discuss. For example, they want to block all conversations about investment advice. Which Amazon Bedrock Guardrails feature should they configure?

A.Contextual grounding check
B.Content filtering with category-based harmful content filters
C.Sensitive information filters
D.Topic restrictions
AnswerD

Topic restrictions define denied subjects, so the guardrail evaluates prompts and responses against them and blocks investment-advice conversations. Content filters target harmful categories such as hate or violence, whereas denied topics are the mechanism for excluding specific subject matter.

Why this answer

Amazon Bedrock Guardrails topic restrictions allow you to define a set of topics that the model should avoid discussing. By configuring topic restrictions, you can block conversations about investment advice by providing a natural language description of the topic and example phrases. This is the specific feature designed to deny-list topics.

Exam trap

AIF-C01 often tests the distinction between content filters (harmful categories) and topic restrictions (custom denied topics), causing candidates to choose content filtering when the requirement is to block a specific subject like investment advice.

How to eliminate wrong answers

Option A is wrong because contextual grounding check is used to detect and filter hallucinations by comparing responses to source information, not to block topics. Option B is wrong because content filtering with category-based harmful content filters targets harmful categories like hate, violence, and sexual content, not specific topics like investment advice. Option C is wrong because sensitive information filters are for detecting and redacting PII or custom regex patterns, not for blocking discussion topics.

6
Multi-Selectmedium

A company uses Amazon Bedrock and wants to ensure that the model outputs are grounded in a set of provided documents to reduce hallucinations. Which TWO actions should they take? (Select TWO.)

Select 2 answers
A.Enable the grounding check in Bedrock Guardrails
B.Configure a word filter to block ungrounded phrases
C.Enable model invocation logging to S3
D.Use Amazon Bedrock Knowledge Bases to store and retrieve document chunks
E.Fine-tune the model on the documents
AnswersA, D

The grounding check compares each model response against the retrieved source chunks and flags or blocks claims unsupported by them, directly reducing hallucination. It satisfies the grounding requirement by validating output against provided documents rather than relying on the model's parametric knowledge.

Why this answer

Option A is correct because Bedrock Guardrails provides a contextual grounding check that evaluates model responses against a provided source (reference) and applies a grounding threshold to filter or flag responses that are not supported by the source, directly reducing hallucinations. Option D is correct because Amazon Bedrock Knowledge Bases ingests the provided documents, chunks them, generates embeddings, and stores them in a vector store so the model can retrieve relevant chunks at inference time via RetrieveAndGenerate, grounding outputs in the actual documents. Option B is wrong because a word filter blocks specific words or phrases and cannot determine whether a statement is factually grounded in the source documents.

Option C is wrong because model invocation logging to S3 only records requests and responses for auditing and monitoring; it does not ground outputs or prevent hallucinations. Option E is wrong because fine-tuning on the documents adapts model weights to style and patterns but does not provide retrieval-based grounding or verifiable citations, and it is not the recommended mechanism for grounding against a document set.

Exam trap

The trap is confusing fine-tuning with RAG. Fine-tuning adjusts model weights but does not provide a mechanism to ground responses in specific documents at runtime. Also, word filters are often mistaken for grounding mechanisms, but they only block specific terms, not verify factual consistency.

7
MCQmedium

A company uses SageMaker Clarify to detect bias in a deployed model. The monitoring must run automatically on a schedule. Which SageMaker feature should they use?

A.SageMaker Pipelines
B.SageMaker Experiments
C.SageMaker Data Wrangler
D.SageMaker Model Monitor
AnswerD

SageMaker Model Monitor runs scheduled bias and drift jobs against a deployed endpoint, integrating Clarify's bias metrics into automated monitoring schedules. This satisfies the stem's requirement for automatic, recurring bias detection, whereas Clarify alone provides analysis without native scheduling.

Why this answer

SageMaker Model Monitor can be configured to run bias detection jobs on a schedule using Clarify's bias metrics.

8
MCQhard

A company uses Amazon SageMaker Clarify to monitor a deployed model for bias. After running an analysis, they find that the model's predictions have a disparate impact on a protected group. What is the MOST appropriate next step?

A.Investigate the root cause of bias, then use techniques such as reweighing training data or applying bias mitigation algorithms before redeploying
B.Modify the SageMaker endpoint to add a random noise to predictions for the protected group
C.Ignore the results because SageMaker Clarify is still in preview
D.Immediately delete the model and retrain from scratch using only data from the protected group
AnswerA

Disparate impact is a measured bias metric, so the remedy is mitigation, not monitoring. Reweighing training data or applying bias mitigation algorithms directly addresses the detected disparity in the protected group before redeployment, satisfying the requirement to correct the bias rather than merely report it.

Why this answer

Discovering bias requires investigation and mitigation. SageMaker Clarify can help identify bias, but mitigation typically involves retraining with balanced data or adjusting model outputs.

9
MCQmedium

A company uses Amazon Bedrock to build an AI assistant. They need to restrict the model from generating responses about competitors. Which Bedrock feature should they configure?

A.Word filters
B.Denied topics
C.PII redaction
D.Content filters
AnswerB

Denied topics let you define a set of undesirable subjects, described in natural language, that Bedrock Guardrails blocks the model from discussing. Configuring a denied topic covering competitors prevents the assistant generating responses about them, meeting the restriction requirement.

Why this answer

Bedrock Guardrails allows you to define topic restrictions that block certain topics from being discussed. Other options are for content filtering, PII redaction, or grounding.

10
MCQhard

A financial services company uses Amazon SageMaker to train models with sensitive customer data. They must ensure that no data leaves a specific AWS Region due to data residency regulations. The training data is in S3. Which architecture meets this requirement while minimizing data transfer?

A.Place SageMaker training job in a private subnet with a NAT gateway and route traffic through the internet
B.Configure S3 Transfer Acceleration and use a public SageMaker training job
C.Use AWS Glue to copy data to an EBS volume attached to the training instance
D.Use S3 VPC endpoints and place SageMaker training job in a private subnet with no internet access
AnswerD

S3 VPC endpoints keep S3 traffic on the AWS private network within the Region, and the private subnet without internet access prevents any egress outside it. This satisfies the data residency constraint while avoiding NAT gateway data transfer costs.

Why this answer

Using a VPC with S3 VPC endpoints ensures data stays within the AWS network and does not traverse the internet. Data remains in the same Region because S3 endpoints are Regional.

11
MCQeasy

A data scientist needs to restrict access to a SageMaker notebook instance to only the corporate network. Which configuration should they use?

A.Enable multi-factor authentication for the notebook
B.Use an IAM policy to allow only corporate users
C.Place the notebook instance in a VPC and configure security groups to allow only corporate IP ranges
D.Use a SageMaker lifecycle configuration to block external IPs
AnswerC

Placing the notebook in a VPC lets security groups act as stateful IP filters, permitting only the corporate CIDR ranges. Direct internet access is removed, so the network-origin constraint is enforced at the elastic network interface.

Why this answer

To restrict access to a SageMaker notebook instance to only the corporate network, the best approach is to place the notebook instance in a VPC and configure security groups to allow inbound traffic only from corporate IP ranges. This network-level control ensures that only traffic from specified IPs can reach the notebook.

Exam trap

The trap is confusing authentication (IAM, MFA) with network-level restrictions. Candidates must remember that to restrict by network, you need VPC and security groups.

How to eliminate wrong answers

Option A is wrong because multi-factor authentication adds an authentication layer but does not restrict network access; users can still connect from any network. Option B is wrong because an IAM policy controls AWS API permissions, not network access to the notebook instance; it does not restrict the source IP. Option D is wrong because lifecycle configurations are scripts that run during notebook instance creation or startup, and they cannot dynamically block external IPs at the network level.

12
MCQeasy

A company wants to detect sensitive data such as PII in their training datasets stored in S3 before using them for model training. Which AWS service should they use?

A.Amazon Macie
B.Amazon Inspector
C.AWS Shield
D.Amazon GuardDuty
AnswerA

Amazon Macie uses machine learning and pattern matching to automatically discover, classify and alert on sensitive data such as PII within S3 buckets, directly satisfying the requirement to scan training datasets before use. It continuously evaluates bucket contents against managed and custom data identifiers, providing the visibility needed prior to model training.

Why this answer

Amazon Macie uses machine learning to discover and protect sensitive data in S3, including PII.

13
MCQeasy

A healthcare startup uses Amazon Bedrock to power a patient-facing chatbot. Compliance officers are concerned that prompts or responses could contain protected health information and want an automated control that detects and blocks such content in real time before it reaches the model or the user. Which Amazon Bedrock feature should the team configure?

A.Amazon Macie sensitive data discovery jobs scoped to the Bedrock service-linked bucket.
B.AWS PrivateLink interface endpoints for the Amazon Bedrock runtime.
C.Amazon Bedrock Guardrails with sensitive information filters enabled.
D.Amazon Bedrock model evaluation jobs configured with an automatic toxicity metric.
AnswerC

Guardrails evaluate prompts and responses against configured policies, and the sensitive information filters detect and block entities such as names, addresses, and other PII patterns. Because Guardrails act inline during InvokeModel and Converse calls, they stop disallowed content before it reaches the model or returns to the user, matching the real-time blocking requirement.

Why this answer

The requirement is inline detection and blocking of sensitive content in both prompts and responses. Amazon Bedrock Guardrails applies configurable policies during inference, and its sensitive information filters identify PII and can mask or block it. Storage scanning, private networking, and offline evaluation each miss the real-time enforcement point where the chatbot interacts with patients.

Exam trap

The trap here is confusing asynchronous data discovery in storage with inline content filtering that can actually block a live prompt or response.

14
Multi-Selectmedium

A retail company is preparing to launch a generative AI assistant built on Amazon Bedrock that will answer customer questions using internal product documents. The governance team wants to reduce the risk of the assistant producing fabricated, misleading, or harmful outputs before launch and during operation. (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail management event logging for all Bedrock API calls in the account.
B.Run Amazon Bedrock model evaluation jobs that score responses for accuracy, toxicity, and robustness against a curated dataset.
C.Store all assistant conversations in Amazon S3 with default encryption and a lifecycle policy.
D.Attach an AWS WAF web ACL with rate-based rules to the application's public endpoint.
E.Configure Amazon Bedrock Guardrails with contextual grounding and relevance checks tied to the retrieved source documents.
AnswersB, E

Model evaluation jobs provide systematic, repeatable measurements before launch, letting the team compare models or configurations on quality and safety metrics. The results create evidence for a go or no-go decision and a baseline for later comparisons. This is a pre-deployment governance control that complements runtime filtering rather than replacing it.

Why this answer

Reducing fabricated and harmful output requires both pre-launch measurement and runtime enforcement. Bedrock model evaluation jobs quantify accuracy, toxicity, and robustness so the team can make an evidence-based launch decision, while Guardrails contextual grounding and relevance checks block or flag responses unsupported by the retrieved documents. Logging, WAF rules, and storage encryption address unrelated risks.

Exam trap

The trap here is selecting logging or network controls as safety mitigations, when only evaluation and guardrail checks actually influence or measure the model's generated content.

15
MCQmedium

A financial services company is using Amazon Bedrock to generate personalized investment advice. The compliance team requires that the model's responses do not contain any personally identifiable information (PII) such as account numbers or social security numbers, and that all PII is automatically masked. Which AWS service or feature should the company use to meet this requirement?

A.Amazon Macie
B.Amazon Bedrock Guardrails
C.AWS Identity and Access Management (IAM) policies
D.Amazon SageMaker Model Monitor
AnswerB

Amazon Bedrock Guardrails allows you to define policies that filter and mask sensitive information in model inputs and outputs. You can configure sensitive information filters to detect and redact PII such as account numbers and social security numbers. This directly meets the compliance requirement by preventing PII from appearing in responses and automatically masking it in real time.

Why this answer

Amazon Bedrock Guardrails provides configurable safeguards that can detect and mask sensitive information like PII in both prompts and responses. By defining a sensitive information filter, the company can ensure that account numbers and social security numbers are automatically redacted from the model's output. This is the only option that directly addresses real-time content filtering and masking within the generative AI application.

Exam trap

The trap here is confusing data discovery services like Amazon Macie with runtime content filtering features like Bedrock Guardrails.

16
Multi-Selectmedium

A company is deploying an AI model on Amazon SageMaker and needs to monitor for model drift over time. Which TWO actions should they take? (Choose TWO)

Select 2 answers
A.Use AWS CloudTrail to log all inference requests and responses
B.Enable data capture on the SageMaker endpoint to store real-time inference data in S3
C.Store model artifacts in Amazon ECR and tag each version
D.Set up Amazon CloudWatch anomaly detection on the endpoint invocation count
E.Configure SageMaker Model Monitor to schedule monitoring jobs that compare new data against a baseline
AnswersB, E

Data capture on a SageMaker endpoint records real-time inference requests and responses to S3, producing the live production dataset that drift detection requires. Without captured data, Model Monitor has nothing to compare against the training baseline.

Why this answer

Option B is correct because enabling data capture on a SageMaker endpoint records the request and response payloads of real-time inference traffic and stores them in Amazon S3, which is the required input for drift analysis. Option E is correct because SageMaker Model Monitor runs scheduled monitoring jobs that compare newly captured data against a baseline (created from training or a baseline job) and can emit CloudWatch metrics and alarms when drift, such as data or model quality drift, is detected. Together, B supplies the live data and E performs the comparison and alerting needed to monitor model drift over time.

Option A is not appropriate because CloudTrail records control-plane API activity, not inference payloads, so it cannot detect data or model drift. Option C is unrelated because storing model artifacts in Amazon ECR and tagging versions addresses artifact versioning, not runtime drift detection. Option D is insufficient because CloudWatch anomaly detection on invocation count only tracks traffic volume, not changes in input data distribution or model prediction quality.

17
MCQhard

A company uses Bedrock Guardrails to filter harmful content in a generative AI application. They need to prevent the model from discussing proprietary internal projects. Which Guardrail component should be configured?

A.Topic restrictions
B.Content filters
C.Grounding check
D.Word filters
AnswerA

Topic restrictions define denied topics using natural-language descriptions and example phrases, blocking discussion of named subjects such as proprietary internal projects. Content filters address harmful categories, not specific business topics, so topic restrictions satisfy this constraint.

Why this answer

Topic restrictions allow administrators to define denied topics; the model will not generate responses related to those topics.

18
MCQmedium

A company uses Amazon Bedrock with a third-party foundation model. They are concerned about the third-party provider accessing their data. What should they review to understand data handling practices?

A.AWS Artifact reports for SOC and PCI compliance
B.AWS CloudTrail logs for model invocation
C.The third-party model provider's data privacy and handling documentation within AWS Bedrock's service description
D.Amazon SageMaker Model Registry metadata
AnswerC

Reviewing the third-party provider's privacy and handling documentation within the AWS Bedrock service description reveals whether prompts, completions, or fine-tuning data are retained, logged, or used for model training. This directly addresses the stem's constraint: understanding the provider's data handling practices and whether they can access company data.

Why this answer

When using a third-party foundation model through Amazon Bedrock, the model provider's own data privacy and handling documentation — surfaced within the Bedrock service description and model details — is the authoritative source for how that provider treats your prompts, completions, and any fine-tuning data. AWS's shared responsibility model means AWS secures the Bedrock infrastructure, but the third-party model provider defines its own data usage terms. Reviewing that documentation tells you whether inputs are used for training, how long they are retained, and what regional or contractual safeguards apply.

Exam trap

AIF-C01 often tests the misconception that AWS Artifact or CloudTrail covers third-party model data practices, when in fact the model provider's own documentation is the correct source under the shared responsibility model.

How to eliminate wrong answers

Option A is wrong because AWS Artifact reports cover AWS's own compliance certifications (SOC, PCI, ISO) for AWS services, not the data-handling practices of a third-party model provider running on Bedrock. Option B is wrong because CloudTrail logs record API activity such as InvokeModel calls for auditing and security, but they do not describe how the provider stores or uses the data. Option D is wrong because SageMaker Model Registry is a catalog for managing model versions and approval workflows in SageMaker, and it is unrelated to Bedrock third-party model data governance.

19
MCQmedium

A data science team is deploying a model using Amazon SageMaker. They need to monitor the model for bias after it is deployed. Which AWS service or feature should they use?

A.Amazon Bedrock Guardrails
B.Amazon SageMaker Clarify
C.Amazon SageMaker Model Monitor
D.AWS CloudTrail
AnswerB

SageMaker Clarify runs bias metrics such as disparate impact against deployed endpoints and emits them to CloudWatch, detecting bias after deployment. This satisfies the post-deployment monitoring requirement, which pre-training Clarify analysis alone would not cover.

Why this answer

Amazon SageMaker Clarify provides bias detection and explainability for machine learning models, including pre-training bias metrics on datasets and post-training bias metrics on deployed model predictions. It integrates with SageMaker Model Monitor to continuously detect bias drift in production.

Exam trap

AIF-C01 often tests the boundary between Clarify (bias and explainability) and Model Monitor (drift detection); candidates pick Model Monitor because it also sounds like a monitoring service, but bias-specific metrics come from Clarify.

How to eliminate wrong answers

Option A is wrong because Amazon Bedrock Guardrails filters harmful content and enforces safety policies for generative AI applications — it does not measure model bias. Option C is wrong because SageMaker Model Monitor detects data drift, model quality drift, and feature attribution drift, but bias detection specifically is a Clarify capability (Model Monitor can consume Clarify bias metrics, but Clarify is the service that computes them). Option D is wrong because AWS CloudTrail records API activity for auditing, not model bias.

20
Multi-Selectmedium

A company needs to govern the lifecycle of ML models, including versioning, monitoring for drift, and decommissioning outdated models. Which TWO services should they use? (Choose 2)

Select 2 answers
A.AWS CloudTrail
B.Amazon SageMaker Model Registry
C.Amazon SageMaker Model Monitor
D.Amazon S3
E.AWS CodePipeline
AnswersB, C

Amazon SageMaker Model Registry provides a centralised catalogue for versioning ML models, tracking approval status, and managing their lifecycle through to decommissioning. It satisfies the stem's governance requirements by recording model metadata and lineage, while drift monitoring is handled by SageMaker Model Monitor alongside it.

Why this answer

Amazon SageMaker Model Registry (B) is correct because it provides a centralized catalog for versioning ML models, tracking approval status, and managing the model lifecycle through metadata such as model packages and model groups, which directly supports versioning and decommissioning outdated models. Amazon SageMaker Model Monitor (C) is correct because it continuously monitors deployed models for data drift, model quality drift, bias drift, and feature attribution drift, alerting when behavior deviates from the baseline, which fulfills the drift-monitoring requirement. AWS CloudTrail (A) only records API activity for auditing and governance of account actions, not ML model versioning or drift detection.

Amazon S3 (D) is object storage for artifacts and data, not a lifecycle governance or monitoring service. AWS CodePipeline (E) is a CI/CD orchestration service for automating build and deployment stages, not for model registry or drift monitoring.

21
MCQeasy

A company wants to automatically discover sensitive data such as credit card numbers in their Amazon S3 training datasets before using them for model training. Which AWS service should they use?

A.Amazon Macie
B.AWS Config
C.Amazon GuardDuty
D.AWS Audit Manager
AnswerA

Amazon Macie uses machine learning and pattern matching to automatically discover, classify and alert on sensitive data such as credit card numbers stored in Amazon S3. It directly satisfies the requirement to scan S3 training datasets before use, providing continuous visibility without manual inspection or custom scripts.

Why this answer

Amazon Macie is a fully managed data security service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in Amazon S3. It is purpose-built to detect PII such as credit card numbers, social security numbers, and API keys in S3 buckets, making it the correct choice for scanning training datasets before use.

Exam trap

AIF-C01 often tests the confusion between data classification services (Macie) and threat detection or compliance services (GuardDuty, Config, Audit Manager), so candidates must map 'sensitive data in S3' directly to Macie.

How to eliminate wrong answers

Option B is wrong because AWS Config is a configuration compliance and resource inventory service that records resource changes and evaluates them against rules; it does not inspect data content for sensitive information. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious activity, not data classification. Option D is wrong because AWS Audit Manager helps collect evidence and automate audit reports for compliance frameworks; it does not scan S3 objects for sensitive data.

22
MCQmedium

A data governance team wants to enforce fine-grained access control on data in an Amazon S3 data lake used by multiple business units for AI training. Which AWS service should they use to define and manage data permissions at the table and column level?

A.AWS Identity and Access Management (IAM)
B.AWS Lake Formation
C.AWS CloudTrail
D.Amazon Macie
AnswerB

Lake Formation provides table- and column-level permission grants over S3 data registered in its Data Catalog, meeting the fine-grained access requirement. IAM policies alone cannot restrict individual columns, so Lake Formation is the only service here that enforces column-level control across business units.

Why this answer

AWS Lake Formation is purpose-built to define and manage fine-grained access control (table, column, row, and cell level) on data stored in Amazon S3 data lakes. It provides a centralized permission model that works across analytics and AI/ML services, making it the correct choice for multi-business-unit governance. IAM alone cannot express column-level permissions on S3 data.

Exam trap

The trap is choosing IAM because it is the default AWS access control service — candidates miss that IAM cannot enforce table/column-level permissions on data lake tables, which is the specific requirement Lake Formation exists to solve.

How to eliminate wrong answers

Option A is wrong because IAM policies operate at the AWS resource/API level (e.g., s3:GetObject) and cannot enforce table- or column-level permissions within data lake tables. Option C is wrong because AWS CloudTrail is an auditing/logging service that records API activity, not a permission management service. Option D is wrong because Amazon Macie is a data security service that discovers and classifies sensitive data (like PII) but does not define or manage access permissions.

23
MCQhard

An organization uses a third-party foundation model accessed through Amazon Bedrock. The compliance team requires that all model inputs and outputs be auditable and retained for one year. Which approach should the team implement?

A.Store all prompts and responses in a DynamoDB table via custom code in the application
B.Use VPC Flow Logs to capture network traffic to Bedrock
C.Enable Bedrock model invocation logging and configure destination to S3 with a lifecycle policy to retain logs for one year
D.Enable CloudTrail data events for Bedrock
AnswerC

Bedrock model invocation logging captures full request and response payloads for each foundation model call, and directing output to S3 with a one-year lifecycle retention policy satisfies the compliance requirement for auditable, retained inputs and outputs.

Why this answer

Bedrock model invocation logging captures all requests and responses and can be sent to CloudWatch Logs or S3 for retention. CloudTrail logs only API-level events (e.g., InvokeModel calls) but not the actual payloads. The other options do not provide payload logging.

24
MCQhard

A company has deployed a model on Amazon SageMaker and enabled Model Monitor. They notice that the model's prediction accuracy has declined over time. Which type of drift is this, and what should they do?

A.This is bias drift; they should run SageMaker Clarify
B.This is concept drift; they should retrain the model with new data
C.This is model drift; they should delete and redeploy the model
D.This is data drift; they should update the training data
AnswerB

Concept drift occurs when the statistical relationship between input features and the target variable changes, degrading accuracy even if input distributions remain stable. Retraining with recent data captures the new feature-to-label mapping, directly addressing the declining accuracy described in the stem.

Why this answer

The decline in prediction accuracy over time, despite the model and data pipeline remaining the same, is characteristic of concept drift—the relationship between input features and the target variable has changed. The appropriate action is to retrain the model with new data that reflects the current relationship. SageMaker Model Monitor can detect this via accuracy metrics.

Exam trap

The trap is confusing concept drift with data drift; candidates may pick data drift because both cause accuracy loss, but concept drift specifically refers to the changed relationship between features and target.

How to eliminate wrong answers

Option A is wrong because bias drift refers to unfairness in predictions across groups, not overall accuracy decline, and Clarify is for bias detection, not concept drift. Option C is wrong because model drift is a broad term, and deleting/redeploying the model would not fix the underlying issue of changed data relationships. Option D is wrong because data drift refers to changes in the distribution of input features, not necessarily the input-output relationship; while it can cause accuracy loss, concept drift is the more precise term when accuracy drops due to changed relationships.

25
MCQeasy

A data scientist needs to train a model in Amazon SageMaker using a dataset that contains personally identifiable information (PII). The company policy requires all data at rest to be encrypted with a customer-managed key. Which configuration meets this requirement?

A.Enable default encryption for the S3 bucket using AWS-managed S3 keys (SSE-S3)
B.Specify a KMS customer-managed key when creating the SageMaker training job and enable data encryption for the S3 bucket with the same key
C.Encrypt the data before uploading to S3 using a client-side library
D.Use SageMaker's local mode and store data on the instance's ephemeral storage
AnswerB

Specifying a KMS customer-managed key for the training job and encrypting the source S3 bucket with the same key satisfies the policy that all data at rest uses a customer-managed key. SageMaker's default encryption uses AWS-owned keys, which the policy excludes.

Why this answer

Using a KMS customer-managed key (CMK) for SageMaker's EBS volumes and S3 buckets ensures encryption at rest with a key the customer controls. The other options either use AWS-managed keys, skip encryption, or are not applicable to SageMaker training jobs.

26
MCQeasy

A company uses AWS Lake Formation to manage data lakes for analytics. They want to ensure that only authorized users can access specific columns in a table containing sensitive data used for ML training. Which Lake Formation feature should they use?

A.Row-level security filters
B.Cell-level security
C.S3 bucket policies
D.Column-level permissions
AnswerD

Column-level permissions in Lake Formation grant or deny access to individual columns within a table, so users querying sensitive ML training data see only authorised fields. This satisfies the requirement to restrict access to specific columns rather than the whole table.

Why this answer

Lake Formation column-level permissions allow fine-grained access control to specific columns within a table.

27
MCQmedium

A financial services company runs a fraud-detection model on an Amazon SageMaker endpoint. Auditors require the company to prove that each prediction can be traced back to the specific model artifact, container image, and training data version used, so the company must be able to reproduce and explain any past decision. Which AWS capability should the company implement to meet this requirement?

A.Apply resource tags to the SageMaker endpoint and generate a cost allocation report in AWS Cost Explorer.
B.Enable SageMaker Model Monitor with a data quality baseline on the production endpoint.
C.Configure SageMaker Model Registry with model cards and record lineage metadata in Amazon SageMaker ML Lineage Tracking.
D.Turn on AWS CloudTrail data events for the Amazon S3 bucket that stores the training data.
AnswerC

Model Registry versions approved model artifacts with approval status, while ML Lineage Tracking automatically captures entities and associations such as training datasets, processing jobs, trial components, and endpoints. Together they let the company connect a deployed endpoint back to the exact artifact, image, and data version, which is precisely the traceability an auditor requests.

Why this answer

Auditors need a defensible chain from prediction back to artifact, image, and data version. SageMaker Model Registry stores versioned, approved model packages with metadata, and ML Lineage Tracking records the relationships among datasets, jobs, artifacts, and endpoints. Using them together creates the reproducible evidence trail, whereas monitoring, access logging, or cost tagging each answer a different question.

Exam trap

The trap here is assuming that logging API access to training data or enabling endpoint monitoring creates model lineage, when traceability requires explicit artifact and dataset relationship tracking.

28
MCQmedium

A company is deploying an AI-powered document summarization system using Amazon Bedrock. They must ensure that the model only uses information from provided source documents and does not generate unsupported claims. Which Bedrock Guardrails feature should they enable?

A.Content filtering with category-based harmful content filters
B.Contextual grounding check
C.Word filters
D.Topic restrictions
AnswerB

Contextual grounding check evaluates responses against the supplied source documents and a query, scoring grounding and relevance. It blocks or flags outputs containing unsupported claims, directly enforcing the requirement that the model use only provided source material rather than generating fabricated content.

Why this answer

Contextual grounding checks ensure that model responses are factually supported by the reference sources, reducing hallucinations.

29
MCQmedium

A company uses Amazon Bedrock to generate content and wants to prevent the model from producing harmful or biased responses. Which AWS service should they configure to enforce content safety policies?

A.Amazon Comprehend for toxicity detection
B.Amazon SageMaker Clarify
C.AWS WAF to filter model responses
D.Amazon Bedrock Guardrails
AnswerD

Guardrails applies configurable content filters and denied-topic policies directly to Bedrock model invocations, blocking harmful or biased output before it reaches the application. This satisfies the requirement to enforce content safety policies at inference time, which prompt engineering alone cannot guarantee.

Why this answer

Amazon Bedrock Guardrails provides content filtering, PII redaction, topic restrictions, and other safety controls. It is purpose-built for content safety in Bedrock.

30
MCQmedium

A company wants to use a third-party foundation model from Amazon Bedrock but is concerned about data privacy because the model provider might store prompts and responses. How should they address this concern?

A.Enable Amazon Bedrock model invocation logging to capture all interactions
B.Review the third-party model provider's data handling policy and choose a model that does not retain data
C.Use Amazon Macie to scan prompts before they are sent
D.Use AWS KMS to encrypt the prompts and responses before sending to the model
AnswerB

Data retention is governed by each third-party provider's own terms, not by Amazon Bedrock itself. Reviewing the provider's data handling policy and selecting a model whose terms guarantee no retention directly addresses the privacy concern.

Why this answer

Each third-party model provider in Bedrock has its own data handling policies. Customers should review those policies and can choose models that do not store data or use Bedrock features like Guardrails to redact sensitive data. However, the direct action is to review the provider's policy and select a model that meets privacy requirements.

31
MCQmedium

A company is using Amazon Bedrock to power a customer-facing chatbot. The security team wants to ensure that the chatbot does not respond to prompts that attempt to elicit inappropriate or off-topic responses, such as discussing competitors or providing medical advice. The company also wants to monitor and log all blocked prompts for analysis. Which AWS service or feature should they use to achieve this?

A.AWS WAF with custom rules to block inappropriate prompts
B.Amazon SageMaker Ground Truth to label and filter prompts
C.Amazon Comprehend to analyze and filter prompts
D.Amazon Bedrock Guardrails with denied topics and content filters
AnswerD

Amazon Bedrock Guardrails allows you to define denied topics to block discussions on specific subjects like competitors or medical advice. It also provides content filters to block harmful content. Guardrails can be configured to log blocked prompts to CloudWatch or S3, enabling monitoring and analysis. This directly meets the requirements.

Why this answer

Amazon Bedrock Guardrails provides configurable safeguards, including denied topics and content filters, that can block inappropriate or off-topic responses in real time. It also supports logging of blocked prompts, which allows the security team to monitor and analyze attempts. This is the most direct and effective solution for the chatbot's requirements.

Exam trap

The trap here is thinking that AWS WAF can inspect the semantic content of prompts; WAF operates at the network layer, not the application layer for natural language.

32
Multi-Selecthard

A company is using Amazon SageMaker to manage the lifecycle of their machine learning models. They need to implement a governance framework that includes model versioning, monitoring for drift, and decommissioning of outdated models. Which THREE AWS services or features should they use together to meet these requirements? (Select THREE.)

Select 3 answers
A.AWS CloudTrail
B.SageMaker Pipelines
C.SageMaker Model Registry
D.SageMaker Role Manager
E.SageMaker Model Monitor
AnswersB, C, E

SageMaker Pipelines orchestrates the end-to-end ML workflow as code, automating retraining, evaluation and conditional deployment steps. Within a governance framework it enforces repeatable, auditable lifecycle transitions, complementing Model Registry versioning and Model Monitor drift detection rather than duplicating them.

Why this answer

SageMaker Model Registry (C) is the correct service for model versioning and governance, as it maintains a catalog of model versions with metadata, approval statuses, and lineage, enabling tracking and controlled promotion of models through their lifecycle. SageMaker Model Monitor (E) is correct because it continuously monitors deployed endpoints for data drift, model quality drift, bias drift, and feature attribution drift, alerting when the model deviates from baseline behavior. SageMaker Pipelines (B) is correct because it provides CI/CD orchestration to automate the ML workflow, including training, evaluation, registration to the Model Registry, and deployment, which supports governance and decommissioning through repeatable, versioned pipeline executions.

AWS CloudTrail (A) only records API activity for auditing and does not provide model versioning, drift monitoring, or lifecycle decommissioning, so it does not meet the requirements. SageMaker Role Manager (D) merely helps create and manage IAM roles and permissions for SageMaker personas; it does not provide versioning, drift detection, or model decommissioning capabilities.

33
MCQeasy

A company is deploying a machine learning model on Amazon SageMaker. The compliance team requires that the model's predictions be explainable and that the company can provide documentation on how the model makes decisions. Which SageMaker feature should the company use to meet this requirement?

A.Amazon SageMaker Autopilot
B.Amazon SageMaker Debugger
C.Amazon SageMaker Clarify
D.Amazon SageMaker Model Monitor
AnswerC

SageMaker Clarify provides tools to detect bias and explain model predictions. It generates feature attribution explanations using SHAP values, which show how each input feature contributes to the model's output. This directly meets the requirement for explainability and documentation of model decisions, helping the company comply with regulations that demand transparency.

Why this answer

SageMaker Clarify is specifically designed to provide explainability for machine learning models. It generates feature attribution reports that show the contribution of each input feature to the model's predictions, which can be used to document and explain model decisions. This meets the compliance requirement for explainable AI.

Exam trap

The trap here is confusing model monitoring with model explainability; Model Monitor tracks performance, while Clarify explains predictions.

34
MCQeasy

A company is using Amazon SageMaker to deploy a machine learning model for credit scoring. The compliance team requires that the model's predictions be explainable to customers, and that the company can demonstrate which features contributed most to a decision. Which SageMaker feature should be used to meet this requirement?

A.SageMaker Debugger
B.SageMaker Experiments
C.SageMaker Model Monitor
D.SageMaker Clarify
AnswerD

SageMaker Clarify provides feature attribution explanations using SHAP values, which show the contribution of each feature to a model's prediction. This allows the company to explain individual credit decisions to customers and auditors. Clarify can be integrated with SageMaker endpoints to generate explanations in real time, meeting the compliance requirement.

Why this answer

The requirement is to explain individual predictions by identifying which features contributed most to a credit decision. SageMaker Clarify offers SHAP-based feature attributions that can be generated for real-time predictions. This enables the company to provide explanations to customers and demonstrate compliance.

Other SageMaker features focus on monitoring, debugging, or experiment tracking, not on model explainability.

Exam trap

The trap here is confusing model monitoring or debugging with explainability, when only Clarify provides feature-level attribution for individual predictions.

35
MCQmedium

A financial services firm needs to ensure that all calls to Amazon Bedrock APIs are logged for audit purposes. Which AWS service should they enable to capture API calls?

A.AWS CloudTrail
B.Amazon S3 server access logs
C.Amazon CloudWatch Logs
D.AWS Config
AnswerA

CloudTrail records API activity as management and data events, capturing every Bedrock API call with caller identity, timestamp and source IP. Enabling a trail delivers the audit logging the firm requires, satisfying the compliance constraint without altering application code.

Why this answer

AWS CloudTrail records API activity in AWS accounts, including Bedrock API calls, providing audit logs.

36
MCQmedium

A company is using Amazon Bedrock to power a chatbot that provides customer support. The security team wants to ensure that the chatbot does not generate responses that include profanity, hate speech, or prompts that attempt to bypass safety filters (jailbreak attempts). They also want to log any blocked interactions for review. Which AWS service or feature should be used to meet these requirements?

A.Amazon Bedrock Guardrails with content filters and prompt attack detection, and enable model invocation logging to capture blocked interactions.
B.Amazon Comprehend for sentiment analysis and Amazon Macie for detecting sensitive data, with alerts sent to Amazon SNS.
C.Amazon SageMaker Clarify for bias detection and Amazon Augmented AI (A2I) for human review, with results logged to Amazon S3.
D.AWS WAF with managed rules for bot control and a custom Lambda function to inspect responses for profanity, logging to Amazon CloudWatch.
AnswerA

Amazon Bedrock Guardrails provides configurable content filters to block hate speech, profanity, and other harmful content. It also includes prompt attack detection to identify jailbreak attempts. When model invocation logging is enabled, Bedrock logs the full request and response, including blocked interactions, allowing for review. This native integration meets all requirements without custom code.

Why this answer

The requirements are to block harmful content and jailbreak attempts in a Bedrock-powered chatbot, and to log blocked interactions. Amazon Bedrock Guardrails offers content filters for profanity, hate speech, and more, plus prompt attack detection. Enabling model invocation logging captures all interactions, including those blocked by Guardrails, for later review.

This is a managed solution that directly addresses the needs without custom development.

Exam trap

The trap here is thinking that general-purpose security services like AWS WAF or content analysis services like Comprehend can moderate generative AI outputs, when they lack the specific filters for profanity and jailbreak detection.

37
MCQmedium

A healthcare startup is using Amazon SageMaker to train a model on patient data. They need to ensure that the training data does not contain any personally identifiable information (PII) before being used. Which AWS service can automatically detect and report PII in the data stored in S3?

A.Amazon Rekognition
B.AWS Glue DataBrew
C.Amazon Comprehend Medical
D.Amazon Macie
AnswerD

Amazon Macie uses machine learning and pattern matching to automatically discover, classify and report sensitive data such as PII in S3. It continuously evaluates buckets and raises findings, directly satisfying the requirement to detect and report PII before SageMaker training begins.

Why this answer

Amazon Macie is a fully managed data security and privacy service that uses machine learning to automatically discover, classify, and protect sensitive data stored in Amazon S3. It can detect personally identifiable information (PII) such as names, addresses, and credit card numbers, and provides detailed reports. This directly addresses the requirement to detect and report PII in S3 before using it for training.

Exam trap

AIF-C01 often tests the confusion between Macie and Comprehend Medical — candidates may think Comprehend Medical detects all PII, but Macie is the dedicated service for PII discovery in S3, while Comprehend Medical is for clinical text extraction.

How to eliminate wrong answers

Option A is wrong because Amazon Rekognition is a computer vision service for image and video analysis, not for detecting PII in text data stored in S3. Option B is wrong because AWS Glue DataBrew is a data preparation tool that can profile data but does not automatically detect PII with the same specialized focus as Macie. Option C is wrong because Amazon Comprehend Medical is designed for extracting medical information from unstructured text, not for general PII detection in S3.

38
MCQhard

A company using Amazon Bedrock needs to redact personally identifiable information (PII) from user inputs before sending them to the foundation model. Which Bedrock Guardrails component should be configured?

A.Content filters
B.Topic restrictions
C.Word filters
D.Sensitive information filters
AnswerD

Sensitive information filters detect and redact PII such as names, addresses and credit card numbers in prompts, directly satisfying the requirement to remove personal data before it reaches the foundation model. Configuring these filters with appropriate PII entities and action set to Mask achieves the redaction.

Why this answer

PII redaction in Guardrails automatically detects and redacts PII in user inputs or model responses.

39
MCQeasy

A company needs to audit all API calls made to Amazon Bedrock, including model invocations and guardrail evaluations. Which AWS service should they enable to capture these API calls for compliance?

A.AWS CloudTrail
B.Amazon Macie
C.AWS Config
D.Amazon GuardDuty
AnswerA

AWS CloudTrail records Bedrock control-plane and data-plane API activity, including model invocations and guardrail evaluations, as audit events. It satisfies the compliance requirement to capture every API call by logging requests, identities, timestamps and source IPs to an immutable trail, which can then be queried or exported for auditing.

Why this answer

AWS CloudTrail records API calls for all AWS services, including Bedrock. It captures the caller identity, API, parameters, and response elements, which can be used for auditing and compliance.

40
MCQmedium

A financial services firm uses Amazon Bedrock to generate investment summaries. They need to prevent the model from generating content containing personally identifiable information (PII) such as social security numbers. Which feature should they configure in Bedrock Guardrails?

A.Contextual grounding checks
B.Content filtering with category-based harmful content filters
C.Sensitive information filters with PII redaction
D.Word filters with a custom list of terms
AnswerC

Sensitive information filters detect and redact personally identifiable information, matching the stem's requirement to block social security numbers in generated summaries. Bedrock Guardrails applies these filters to both prompts and responses, so PII is caught before reaching users. Unlike content filters, which target harmful categories such as hate or violence, this mechanism specifically addresses data privacy.

Why this answer

Bedrock Guardrails include a PII redaction filter that can detect and block or mask PII in model inputs and outputs.

41
MCQmedium

A machine learning team wants to detect bias in a deployed model's predictions on new data. They use Amazon SageMaker. Which service should they use to generate bias reports after deployment?

A.Amazon SageMaker Clarify
B.Amazon SageMaker Debugger
C.Amazon SageMaker Model Monitor
D.Amazon SageMaker Role Manager
AnswerA

Amazon SageMaker Clarify generates post-deployment bias reports by monitoring live endpoint traffic and computing metrics such as disparate impact against baseline data. This satisfies the stem's requirement to detect bias in predictions on new data after deployment, which pre-training Clarify analysis alone cannot cover.

Why this answer

Amazon SageMaker Clarify provides bias detection and explainability for ML models, both during training and after deployment. SageMaker Model Monitor detects data drift but not bias. SageMaker Debugger is for training debugging.

SageMaker Role Manager is for managing IAM roles.

42
MCQhard

A security engineer is configuring logging for Amazon Bedrock model invocations. They need to capture both the input and output of all API calls for compliance audits. Which set of steps should they take?

A.Enable Bedrock model invocation logging and specify an S3 bucket and optionally CloudWatch Logs as the destination
B.Enable CloudTrail for the Bedrock API and configure S3 event notifications
C.Use VPC Flow Logs to capture network traffic and reconstruct model inputs from packet data
D.Enable AWS Config rules for Bedrock and stream logs to Amazon Kinesis
AnswerA

Enabling model invocation logging in Bedrock and designating an S3 bucket (with optional CloudWatch Logs) captures both the request input and the model output for every API call, directly meeting the compliance audit requirement to record full invocation content.

Why this answer

Bedrock model invocation logging captures inputs and outputs to S3 and/or CloudWatch Logs. CloudTrail records API calls but not the model inputs/outputs.

43
Multi-Selecteasy

A company wants to log all model invocation requests in Amazon Bedrock for audit and troubleshooting. Which TWO destinations can they configure for invocation logging? (Choose 2)

Select 2 answers
A.Amazon CloudWatch Logs
B.Amazon S3
C.Amazon DynamoDB
D.AWS CloudTrail
E.Amazon Kinesis Data Firehose
AnswersA, B

Amazon CloudWatch Logs is a supported destination for Bedrock model invocation logging, satisfying the audit and troubleshooting requirement. It captures text, image, and embedding invocation data as log events, enabling near-real-time querying and retention policies for compliance reviews.

Why this answer

Amazon Bedrock invocation logging supports two destination types: Amazon CloudWatch Logs (option A) and Amazon S3 (option B). Option A is correct because Bedrock can deliver text and image invocation logs to a CloudWatch Logs log group, enabling real-time monitoring and troubleshooting via CloudWatch. Option B is correct because Bedrock can also deliver invocation logs to an S3 bucket for durable, long-term audit storage and later analysis.

Option C is incorrect because DynamoDB is not a supported invocation logging destination for Bedrock. Option D is incorrect because CloudTrail records API activity/management events, not the model invocation request/response payloads that invocation logging captures. Option E is incorrect because Kinesis Data Firehose is not a configurable destination for Bedrock invocation logging.

44
MCQhard

A media company must give an external analytics vendor temporary, auditable access to a curated S3 dataset used for fine-tuning a model. The vendor works from its own AWS account, and the company's security policy forbids sharing long-term IAM credentials. Which approach best meets the policy while keeping access auditable?

A.Generate a presigned URL for each S3 object and email the URLs to the vendor on a weekly schedule.
B.Configure a cross-account IAM role in the company account that the vendor assumes using AWS Security Token Service, with an external ID condition.
C.Enable S3 Block Public Access and place the dataset behind an Amazon CloudFront signed cookie distribution.
D.Create an IAM user in the company account for the vendor and rotate the access keys every 24 hours with a script.
AnswerB

A cross-account role lets the vendor's own principals call AssumeRole and receive temporary credentials, so no long-term secrets are shared. The external ID condition guards against the confused deputy problem, and because the vendor assumes a distinct role, CloudTrail records its activity separately. This satisfies both the no-shared-credentials policy and the auditability requirement.

Why this answer

Cross-account IAM roles with AWS Security Token Service temporary credentials are the standard way to grant a partner access without exchanging secrets. The external ID prevents the confused deputy problem, and separate role assumption produces clean CloudTrail attribution. Presigned URLs, rotated IAM user keys, and CDN-signed access all either share secrets or obscure who actually accessed the data.

Exam trap

The trap here is treating time-limited presigned URLs or rotated access keys as equivalent to temporary role-based credentials, when only role assumption avoids sharing secrets and preserves clear identity attribution.

45
MCQeasy

A healthcare company is building an AI application on AWS that processes patient records. The security team must ensure that data stored in Amazon S3 is encrypted at rest using a key that the company manages and can rotate independently. Which AWS service should they use to meet these requirements?

A.AWS KMS AWS managed key
B.AWS Secrets Manager
C.Amazon S3 default encryption with Amazon S3 managed keys (SSE-S3)
D.AWS Key Management Service (AWS KMS) customer managed key
AnswerD

AWS KMS customer managed keys give the company full control over key creation, rotation, and access policies. They can enable automatic rotation and define granular permissions. This meets the requirement for a company-managed key that can be rotated independently, and it integrates with S3 server-side encryption to protect data at rest.

Why this answer

AWS KMS customer managed keys allow the company to create, manage, and rotate encryption keys independently. When used with S3 server-side encryption (SSE-KMS), the company retains control over the key lifecycle and access policies, directly meeting the requirement for company-managed encryption keys for patient records.

Exam trap

The trap here is assuming that any KMS key provides independent rotation control, when only customer managed keys offer that level of management.

46
MCQhard

A government agency trains models on highly sensitive data inside Amazon SageMaker. The security policy states that training data and model artifacts must never be accessible over the public internet and that traffic to AWS services must stay within the agency's Amazon VPC. Which combination should the agency implement?

A.Place the training job in a public subnet with a NAT gateway and restrict security group egress to AWS service prefix lists.
B.Attach an S3 bucket policy that denies requests where aws:SourceIp is outside the agency CIDR range and enable default encryption.
C.Use SageMaker Studio in a private subnet and rely on AWS Identity and Access Management policies to deny access to non-approved services.
D.Run training jobs with network isolation enabled and access AWS services through VPC interface endpoints powered by AWS PrivateLink.
AnswerD

Network isolation disables outbound network access from the training container, preventing data exfiltration over the internet. VPC interface endpoints keep calls to services such as Amazon S3 and SageMaker on private IP addresses inside the VPC. Together they satisfy both halves of the policy without exposing data or control traffic to public routes.

Why this answer

The policy has two distinct demands: no public internet access from the training environment and private connectivity to AWS services. Network isolation removes outbound network access entirely, and VPC interface endpoints route service calls over private addresses. IP conditions, NAT-routed public subnets, and IAM-only controls each address authorization or partial routing rather than the complete private-path requirement.

Exam trap

The trap here is assuming that IAM restrictions or IP-based bucket policies provide network isolation, when only disabling container networking and using private endpoints actually remove public internet paths.

47
MCQhard

A company is using Amazon Bedrock to build an AI assistant that accesses internal knowledge bases. The security team wants to ensure that the assistant only retrieves documents that the requesting user is authorized to view, based on their department. Which approach should be used to enforce this fine-grained access control?

A.Implement document-level access control using metadata filtering in Amazon Bedrock Knowledge Bases
B.Use Amazon Bedrock Guardrails to filter responses by department
C.Store all documents in a single S3 bucket with a bucket policy allowing only the assistant's IAM role
D.Configure IAM policies to restrict access to the Bedrock model
AnswerA

Amazon Bedrock Knowledge Bases supports metadata filtering, allowing you to attach metadata to documents and filter retrieval based on user attributes. By passing user department as a filter, the assistant only retrieves authorized documents. This provides fine-grained access control at the document level.

Why this answer

Amazon Bedrock Knowledge Bases supports metadata filtering, which allows documents to be tagged with attributes such as department. When a user queries the knowledge base, the application can pass a filter based on the user's department, ensuring only authorized documents are retrieved. This enforces fine-grained access control at the document level.

Exam trap

The trap here is thinking that IAM or bucket policies can enforce per-user document access, when they operate at the resource level, not the document level.

48
MCQmedium

A company uses Amazon Bedrock and needs to log all model invocations for audit purposes. The logs must be stored in a central S3 bucket and also sent to CloudWatch Logs for real-time monitoring. Which configuration should they use?

A.Enable Amazon Macie to monitor Bedrock responses
B.Enable AWS CloudTrail to capture Bedrock API calls and configure CloudTrail logs to S3 and CloudWatch
C.Use AWS Lambda to capture responses and write to S3 and CloudWatch
D.Configure Amazon Bedrock model invocation logging to send logs to both S3 and CloudWatch Logs
AnswerD

Bedrock's model invocation logging natively supports dual destinations: you enable it once and specify both an S3 bucket for durable audit storage and a CloudWatch Logs group for real-time monitoring. This satisfies the stem's requirement for centralised S3 retention plus live CloudWatch visibility, without custom pipelines or duplicate instrumentation.

Why this answer

Bedrock model invocation logging can be configured to send logs to both S3 and CloudWatch Logs simultaneously. This is a built-in feature of Bedrock logging settings.

49
MCQmedium

A company has deployed a machine learning model using Amazon SageMaker and wants to monitor the model for bias over time. Which SageMaker feature should they use to detect bias in the model's predictions after deployment?

A.SageMaker Debugger
B.SageMaker Model Monitor
C.SageMaker Clarify
D.SageMaker Role Manager
AnswerC

SageMaker Clarify detects bias in deployed models through bias metrics on predictions and features, and integrates with Model Monitor for ongoing post-deployment checks. This satisfies the requirement to monitor bias over time rather than only during training.

Why this answer

SageMaker Clarify is designed to detect bias in ML models both before and after deployment. It can analyze predictions to identify potential bias against certain groups.

50
MCQeasy

A data scientist wants to restrict which IAM roles can invoke a specific Amazon Bedrock base model. Which AWS feature should they use?

A.S3 bucket policy on the model artifacts
B.Bedrock resource-based policy
C.AWS KMS key policy for the encryption key
D.AWS CloudTrail log delivery policy
AnswerB

Bedrock resource-based policies attach directly to a specific base model, letting you define which principals may invoke it and under what conditions. This satisfies the stem's constraint of restricting IAM roles per model, since identity-based policies alone cannot scope permissions to an individual Bedrock model resource.

Why this answer

Option B is correct because Amazon Bedrock supports resource-based policies that can be attached to a specific base model or custom model to control which IAM principals (roles, users, accounts) can invoke it. This is the intended mechanism for restricting invocation of a particular Bedrock model to a defined set of IAM roles.

Exam trap

AIF-C01 often tests the confusion between identity-based IAM policies and resource-based policies — candidates forget that Bedrock models support resource-based policies for fine-grained invocation control.

How to eliminate wrong answers

Option A is wrong because S3 bucket policies apply to S3 objects, not to Bedrock model invocation; Bedrock base models are not stored in customer S3 buckets. Option C is wrong because a KMS key policy controls access to the encryption key used for data at rest, not the ability to invoke a Bedrock model. Option D is wrong because CloudTrail log delivery policies govern how CloudTrail writes logs to S3/CloudWatch, not model invocation permissions.

51
Multi-Selecthard

A company is implementing an AI governance framework for their machine learning models deployed on Amazon SageMaker. Which THREE actions should they include to manage the model lifecycle effectively? (Select THREE.)

Select 3 answers
A.Enable Amazon CloudWatch alarms for model accuracy metrics
B.Automatically delete all previous model versions after deployment
C.Create a decommissioning policy that retires old models
D.Use AWS CloudTrail to track model inference requests
E.Use SageMaker Model Registry to version models
AnswersA, C, E

CloudWatch alarms on accuracy metrics detect drift and degradation during live inference, satisfying the governance requirement to monitor deployed models continuously. This provides the observability needed to trigger retraining or rollback decisions across the model lifecycle.

Why this answer

Option A is correct because Amazon CloudWatch alarms on model accuracy metrics (e.g., via SageMaker Model Monitor's ModelQuality metrics) provide automated detection of drift or degradation, which is essential for governing model performance across the lifecycle. Option C is correct because a formal decommissioning policy ensures old models are retired in a controlled, auditable way, preventing stale or non-compliant models from continuing to serve predictions. Option E is correct because SageMaker Model Registry provides model versioning, approval workflows, and metadata tracking, which are foundational for managing the model lifecycle and governance.

Option B is not appropriate because automatically deleting all previous model versions destroys the audit trail and rollback capability that governance frameworks require. Option D is not the right tool because CloudTrail records AWS API activity (control-plane events), not individual model inference requests; inference logging is handled by SageMaker endpoint data capture or CloudWatch Logs.

Exam trap

AIF-C01 often tests the misconception that CloudTrail provides model performance monitoring — candidates confuse API activity logging with model behavior observability, when CloudWatch (with Model Monitor) is the correct service.

52
MCQmedium

A company needs to ensure that model inference endpoints in SageMaker are only accessible from a private subnet in their VPC, and no traffic goes over the public internet. Which network configuration should they use?

A.Create a public endpoint and restrict access using IAM policies
B.Use AWS PrivateLink for the endpoint, but keep public endpoint enabled
C.Use a VPC interface endpoint for SageMaker and disable public access
D.Deploy the endpoint in a public subnet with a security group blocking all inbound traffic
AnswerC

A VPC interface endpoint (AWS PrivateLink) provisions an elastic network interface with a private IP inside the subnet, letting inference calls reach SageMaker without traversing the public internet. Disabling public access enforces the stem's constraint that endpoints remain reachable only from the private subnet, satisfying the no-internet requirement.

Why this answer

To keep SageMaker inference traffic entirely off the public internet, you create a VPC interface endpoint (powered by AWS PrivateLink) for the SageMaker API and runtime, then disable the public endpoint so the service is reachable only from within the VPC. This forces all inference calls to traverse the private endpoint ENI in the subnet, never leaving the AWS network.

Exam trap

AIF-C01 often tests the misconception that IAM policies or security groups alone can make an endpoint private — candidates must remember that network isolation requires PrivateLink/VPC endpoints, not just authorization controls.

How to eliminate wrong answers

Option A is wrong because IAM policies only control authorization, not network path — a public endpoint still routes traffic over the internet even if only authorized principals can call it. Option B is wrong because keeping the public endpoint enabled leaves an internet-reachable path, defeating the requirement. Option D is wrong because a public subnet with a restrictive security group still exposes the endpoint to the internet and does not provide private-only connectivity.

53
MCQeasy

A company uses Amazon SageMaker to train sensitive ML models. Which AWS service should they use to encrypt the training data and model artifacts at rest?

A.AWS Secrets Manager
B.AWS CloudHSM
C.AWS Key Management Service (KMS)
D.AWS Certificate Manager
AnswerC

AWS KMS provides the customer-managed keys that encrypt SageMaker training data in S3 and model artefacts at rest, satisfying the at-rest encryption requirement. KMS integrates natively with SageMaker and S3, unlike services handling in-transit encryption or access control.

Why this answer

AWS Key Management Service (KMS) allows customers to create and manage encryption keys used to encrypt data at rest in SageMaker, including training data and model artifacts.

54
MCQmedium

A company uses Amazon Bedrock Guardrails to filter harmful content. They want to ensure that the model does not generate responses containing specific keywords related to their internal project names. Which Guardrails component should they configure?

A.Harmful content filters
B.Topic restrictions
C.Word filters
D.Grounding checks
AnswerC

Word filters block or mask prompts and responses containing configured custom terms, so adding internal project names stops the model emitting them. This is distinct from managed word filters, which target profanity, and from denied topics, which cover broader subject areas.

Why this answer

Word filters in Amazon Bedrock Guardrails are specifically designed to block or mask responses containing custom keywords or phrases. By configuring word filters, the company can ensure that internal project names are not generated in model responses. This is the precise component for keyword-based filtering.

Exam trap

The trap is confusing word filters with topic restrictions; candidates may think topic restrictions handle specific keywords, but they are for broader thematic blocking, while word filters are for exact terms.

How to eliminate wrong answers

Option A is wrong because harmful content filters target categories like hate, violence, and sexual content, not specific custom keywords. Option B is wrong because topic restrictions block entire topics based on natural language descriptions, not exact keyword matches. Option D is wrong because grounding checks verify that responses are grounded in source documents, not filter specific words.

55
Multi-Selectmedium

A company uses Amazon Macie to discover sensitive data in an S3 bucket containing training datasets. The bucket policy currently prohibits access from external accounts. Which TWO steps are necessary to allow a cross-account SageMaker training job to access this bucket while maintaining security?

Select 2 answers
A.Configure Macie to automatically grant access to the SageMaker execution role
B.Create a VPC endpoint for S3 and associate it with the SageMaker VPC
C.Add a bucket policy that grants the SageMaker execution role from the other account s3:GetObject and s3:ListBucket permissions
D.Attach an IAM policy to the SageMaker execution role that allows s3:GetObject and s3:ListBucket on the source bucket
E.Remove the bucket policy that prohibits external access
AnswersC, D

The bucket policy is the resource-based control that explicitly overrides the current prohibition on external accounts. Granting the cross-account SageMaker execution role s3:GetObject and s3:ListBucket authorises that principal directly, satisfying the cross-account access requirement while keeping the bucket closed to everyone else.

Why this answer

Option C is correct because the S3 bucket policy is the resource-based policy that must explicitly grant the cross-account SageMaker execution role access; since the bucket currently prohibits external accounts, you must add a statement allowing that role principal s3:GetObject and s3:ListBucket on the bucket and its objects. Option D is correct because the SageMaker execution role in the other account also needs an identity-based IAM policy permitting s3:GetObject and s3:ListBucket on the source bucket, since cross-account access requires both the identity policy and the resource policy to allow the action. Option A is wrong because Macie is a data-discovery and classification service and cannot grant access to a SageMaker execution role.

Option B is wrong because an S3 VPC endpoint only affects private network routing for traffic within a VPC and does not by itself authorize cross-account access. Option E is wrong because removing the bucket policy's external-access prohibition would broadly open the bucket rather than securely scoping access to the SageMaker execution role.

Exam trap

AIF-C01 often tests the misconception that a single policy (either identity-based or resource-based) suffices for cross-account access, when in fact both sides must explicitly grant permission.

56
Multi-Selectmedium

A company wants to use AWS Lake Formation to govern access to data used for AI training. They need to ensure that only approved columns of sensitive tables are visible to data scientists. Which THREE steps should they implement? (Choose THREE)

Select 3 answers
A.Use AWS Glue crawlers to catalog the data and populate the Data Catalog
B.Create a SageMaker notebook instance and attach an IAM role
C.Define column-level permissions in Lake Formation to grant access to specific columns for the data scientist role
D.Enable S3 versioning on the training data bucket
E.Register the S3 bucket containing the training data with Lake Formation
AnswersA, C, E

AWS Glue crawlers scan the underlying data, infer schemas and register tables in the Data Catalog. Lake Formation permissions are granted against those catalogued tables and columns, so cataloguing is the prerequisite step enabling column-level access control.

Why this answer

The scenario requires governing access to AI training data with Lake Formation and restricting visibility to approved columns, so the solution must include cataloging, registering the data location, and applying column-level grants. Option A is correct because AWS Glue crawlers scan the S3 data, infer schemas, and populate the AWS Glue Data Catalog, which Lake Formation relies on to define and enforce permissions on tables and columns. Option C is correct because Lake Formation supports column-level permissions, allowing you to grant SELECT on only specific columns of a table to the data scientist role, which directly satisfies the requirement that only approved columns be visible.

Option E is correct because the S3 bucket containing the training data must be registered with Lake Formation so that Lake Formation manages access to the underlying data and can enforce its table and column permissions. Option B is not required because a SageMaker notebook instance with an IAM role is a compute/access mechanism, not a governance step for restricting column visibility. Option D is not relevant because S3 versioning provides object version retention and recovery, not fine-grained column access control.

Exam trap

AIF-C01 often tests the steps for Lake Formation governance, and candidates may overlook the need to register the S3 bucket or confuse it with other services like SageMaker, leading to incorrect selections.

Ready to test yourself?

Try a timed practice session using only Security, Compliance, and Governance for AI Solutions questions.