Courseiva

AIF-C01 Fundamentals of Generative AI Practice Question

Which THREE are best practices for building a secure and scalable generative AI application using Amazon Bedrock? (Choose 3)

⚠ Common exam trap

Often, candidates mistakenly think that 'more control' (like EC2) is always better for security, when in fact managed services like Bedrock reduce attack surface and operational burden, making them the recommended approach for secure and scalable generative AI applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement guardrails to filter harmful content

Option A is correct because Amazon Bedrock Guardrails let you define denied topics, content filters, word filters, and PII redaction policies that are applied to both prompts and model responses, which is a core best practice for filtering harmful or non-compliant content in a generative AI application. Option D is correct because AWS KMS provides customer-managed keys and envelope encryption for data at rest, including model artifacts, knowledge bases, and logs, satisfying security and compliance requirements for protecting sensitive data. Option E is correct because Bedrock offers a unified, serverless API to access foundation models from multiple providers such as Anthropic, Meta, Mistral, Cohere, and Amazon, enabling model choice, fallback, and cost/performance optimization without managing infrastructure, which supports scalability. Option B is not a Bedrock best practice because deploying models on self-managed EC2 instances moves you away from Bedrock's serverless, managed scaling and shifts patching, scaling, and security responsibilities to you. Option C is incorrect because hardcoding API keys in source code exposes credentials to leakage via repositories and logs; you should use AWS Secrets Manager or IAM roles instead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement guardrails to filter harmful content

    Why this is correct

    Guardrails in Amazon Bedrock apply configurable policies that filter harmful or inappropriate content in prompts and responses, denying unsafe interactions. This directly enforces the security posture the stem requires for a secure generative AI application.

  • ✗

    Deploy models on EC2 instances for better control

    Why it's wrong here

    EC2 deployment replaces Bedrock's managed inference, so you lose its serverless scaling and IAM-integrated guardrails — the very properties the question asks you to preserve. EC2 is the right answer when you need custom model hosting, GPU instance families, or frameworks Bedrock does not offer.

  • ✗

    Store API keys in source code for easy access

    Why it's wrong here

    Hard-coding API keys exposes credentials to anyone with repository access, enabling abuse and cost escalation. It is tempting during prototyping for convenience, but secrets belong in AWS Secrets Manager or IAM roles, which is the correct approach for production Bedrock applications.

  • ✓

    Use AWS KMS to encrypt data and model artifacts

    Why this is correct

    AWS KMS provides customer-managed keys that encrypt data at rest, including model artefacts and stored conversation data. This satisfies the stem's security requirement by ensuring cryptographic protection and controlled key access across the Bedrock workload.

  • ✓

    Use foundation models from multiple providers via Bedrock

    Why this is correct

    Bedrock's unified API exposes foundation models from several providers, so workloads can select the most suitable model per task and switch without re-architecting. This supports the scalability requirement by avoiding lock-in to a single model's capacity or limits.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.