Courseiva

AIF-C01 · topic practice

Security, Compliance, and Governance for AI Solutions practice questions

This domain covers securing AI workloads on AWS: encryption of training data, access control, audit logging, and governance of models. Questions are scenario-based, asking you to pick the right AWS service or configuration for PII protection, cross-account access, API auditing, and model lifecycle governance.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security, Compliance, and Governance for AI Solutions

What the exam tests

What to know about Security, Compliance, and Governance for AI Solutions

Be able to map each governance need to the correct AWS service: KMS for encryption, CloudTrail for API auditing, Macie for sensitive data discovery, IAM and bucket policies for access, and SageMaker Model Registry and Model Monitor for versioning and drift. Get the service-to-requirement mapping right.

Selecting KMS customer-managed keys and S3 encryption for PII training data at rest

Enabling AWS CloudTrail to capture Bedrock model invocation and guardrail API calls

Using Amazon Macie findings plus bucket policies and IAM roles for cross-account access

Applying SageMaker Model Registry, Model Monitor, and lifecycle policies for governance

Watch out for

Common Security, Compliance, and Governance for AI Solutions exam traps

  • ▸Confusing CloudTrail (API activity audit) with CloudWatch (metrics/logs) when asked to audit Bedrock invocations.
  • ▸Assuming Macie alone grants access; you still need bucket policy and IAM role changes for cross-account reads.
  • ▸Using AWS-managed keys when policy explicitly requires customer-managed KMS keys for data at rest.

Practice set

Security, Compliance, and Governance for AI Solutions questions

20 questions · select your answer, then reveal the explanation

A data scientist needs to allow a foundation model in Amazon Bedrock to access a specific S3 bucket containing reference documents. The bucket is in a different AWS account. What is the MOST secure way to grant access?

An organization uses AWS Lake Formation to govern a data lake used for SageMaker training. They need to enforce row-level security so that different teams only see data relevant to their projects. Which Lake Formation feature should they use?

A company wants to use a third-party foundation model in Bedrock and is concerned about the provider's data handling policies. Which action should they take to ensure their data is not used for model training by the provider?

A company wants to enforce strict data residency for training data used in SageMaker. The data must never leave a specific AWS Region. Which THREE actions should they take? (Choose 3)

A healthcare company uses Amazon SageMaker to train a model on patient data. To meet HIPAA compliance, they must ensure training data is encrypted at rest and in transit. Additionally, the training job should not have internet access. Which combination of actions should the company take?

A data scientist is using Amazon SageMaker to train a model with data that resides in an S3 bucket owned by another AWS account. The training job fails with access denied errors. The data scientist has already been granted cross-account read access to the S3 bucket via a bucket policy. What additional configuration is required?

A machine learning team uses Amazon SageMaker to train and deploy models. They need to ensure that only approved base models from the AWS Marketplace are used. Which feature should they use to enforce this policy?

A financial institution is using Amazon Bedrock for a customer-facing application. They must ensure compliance with data residency requirements: model inputs and outputs must not leave a specific AWS Region. Which THREE steps should they take? (Choose THREE)

A data scientist needs to restrict access to a specific Amazon SageMaker notebook instance so that only a designated IAM role can invoke the CreatePresignedNotebookInstanceUrl API. Which IAM policy element should be used to achieve this?

A company is using Amazon Bedrock to generate text summaries of customer emails. The compliance team requires that any email containing a Social Security Number (SSN) must be blocked from being sent to the model for summarization. Which Bedrock Guardrail configuration should be used?

A machine learning team is training a model using Amazon SageMaker with data stored in an S3 bucket. The security policy requires that all data be encrypted at rest and in transit, and that the training job cannot access the internet. Which combination of settings should the team use?

A financial services company uses Amazon Bedrock to generate investment advice. They have configured a guardrail to deny any harmful content. However, a user prompt 'Tell me how to commit fraud' was not blocked. What is the most likely cause?

A company is deploying a real-time inference endpoint using Amazon SageMaker. The security team requires that all data sent to the endpoint be encrypted in transit and that the endpoint is only accessible from within the company's VPC. Which configuration should be used?

An organization uses AWS Lake Formation to govern access to data used for machine learning in Amazon SageMaker. They want to ensure that a particular IAM role used by SageMaker can only query a subset of columns in a table containing sensitive customer data. Which Lake Formation permission should be granted to the role?

A data scientist wants to use a third-party foundation model from Amazon Bedrock for a generative AI application. The compliance officer needs to understand how the third-party model provider handles data privacy. Where can the data scientist find this information?

A company uses Amazon Bedrock with a custom model that was trained on data subject to GDPR. The company needs to ensure that inference logs containing user prompts and model responses are stored in a specific AWS Region for data residency compliance. How should they configure Bedrock model invocation logging?

A machine learning team needs to share a SageMaker notebook with a colleague from a different AWS account. The colleague should be able to open and run the notebook but not delete it. Which combination of actions should the team take?

A company is deploying a generative AI application using Amazon Bedrock and needs to ensure that the model's responses do not include any sensitive information. Which TWO Bedrock Guardrail configurations should be used together to meet this requirement? (Select TWO.)

A company wants to encrypt training data stored in Amazon S3 and model artifacts in Amazon SageMaker using customer-managed keys. Which TWO AWS services or features should they use? (Select TWO.)

A company uses Amazon Bedrock to access foundation models. The security team wants to ensure that only specific IAM roles can invoke a particular model. Which configuration should they use?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security, Compliance, and Governance for AI Solutions sessions

Start a Security, Compliance, and Governance for AI Solutions only practice session

Every question in these sessions is drawn from the Security, Compliance, and Governance for AI Solutions domain — nothing else.

Related practice questions

Related AIF-C01 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the AIF-C01 exam test about Security, Compliance, and Governance for AI Solutions?
Be able to map each governance need to the correct AWS service: KMS for encryption, CloudTrail for API auditing, Macie for sensitive data discovery, IAM and bucket policies for access, and SageMaker Model Registry and Model Monitor for versioning and drift. Get the service-to-requirement mapping right.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security, Compliance, and Governance for AI Solutions questions in a focused session?
Yes — the session launcher on this page draws every question from the Security, Compliance, and Governance for AI Solutions domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other AIF-C01 topics?
Use the topic links above to move to related areas, or go back to the AIF-C01 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the AIF-C01 exam covers. They are not copied from any real exam or dump site.