AIF-C01 Applications of Foundation Models Practice Question
Network Topology
Refer to the exhibit. A developer runs this command but gets an error: 'An error occurred (AccessDeniedException) when calling the ListFoundationModels operation'. What is the most likely cause?
⚠ Common exam trap
AWS often tests the distinction between service availability errors (e.g., region not supported) and IAM permission errors, where candidates mistakenly attribute an AccessDeniedException to regional or model availability issues rather than missing IAM permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role does not have bedrock:ListFoundationModels permission
The error 'AccessDeniedException' when calling ListFoundationModels indicates that the IAM role or user executing the AWS CLI command lacks the required permission to list foundation models in Amazon Bedrock. The specific permission needed is bedrock:ListFoundationModels, which must be attached to the IAM identity via a policy. Without this permission, the API call is denied regardless of other factors like region or CLI version.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM role does not have bedrock:ListFoundationModels permission
Why this is correct
ListFoundationModels is a Bedrock control-plane action, so the caller's identity must hold bedrock:ListFoundationModels in its attached IAM policy. AccessDeniedException is returned by IAM authorisation evaluation, not by model availability or Region configuration, making a missing or explicitly denied permission the direct cause.
- ✗
The AWS CLI version is outdated
Why it's wrong here
An outdated AWS CLI would produce command-not-found or parameter errors, not an AccessDeniedException returned by the service. It is tempting because CLI versions lacking Bedrock support do fail, but the service's explicit authorisation denial points to missing IAM permissions for bedrock:ListFoundationModels.
- ✗
The foundation model is not available in us-west-2
Why it's wrong here
Model availability affects which models ListFoundationModels returns, not whether the call is authorised; an unavailable model yields an empty list, not AccessDeniedException. It is tempting because regional model gaps are common, but the error is an IAM permissions issue on the bedrock:ListFoundationModels action.
- ✗
The region us-west-2 does not support Bedrock
Why it's wrong here
Bedrock is available in us-west-2, so the region itself does not cause an AccessDeniedException; that error signals an IAM policy or credentials problem. It is tempting because unsupported regions do return errors, but those are typically ValidationException or endpoint resolution failures, not authorisation denials.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.