AIF-C01 Guidelines for Responsible AI Practice Question
Which THREE practices are recommended for promoting robustness and security in AI systems?
⚠ Common exam trap
Candidates often mistakenly think that immediate deployment or removing monitoring can improve performance, but these actions severely compromise robustness and security by skipping validation and eliminating visibility into model degradation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement strong access controls and encryption for model artifacts
Robustness and security in AI systems require multiple complementary practices. (B) Implementing strong access controls (e.g., IAM policies, role-based access control) and encryption (e.g., AES-256 for data at rest, TLS 1.2+ for data in transit) protects model artifacts from unauthorized access, tampering, and exfiltration, ensuring confidentiality and integrity throughout the lifecycle. (C) Regularly testing the model against adversarial examples surfaces vulnerabilities to evasion, poisoning, and prompt-injection style attacks, allowing defenses to be hardened before real-world exploitation. (D) Monitoring model performance for data drift and concept drift detects when the model's inputs or the underlying relationships change, so degradation, unexpected behavior, or emerging security-relevant anomalies can be caught and remediated early. Together these practices cover artifact protection, adversarial resilience, and ongoing operational vigilance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the model immediately after training without validation
Why it's wrong here
Deploying without validation increases risk of failure.
- ✓
Implement strong access controls and encryption for model artifacts
Why this is correct
Security controls protect models from unauthorized access and tampering.
- ✓
Regularly test the model against adversarial examples
Why this is correct
Adversarial testing helps identify vulnerabilities.
- ✓
Monitor model performance for data drift and concept drift
Why this is correct
Monitoring drift ensures the model remains reliable over time.
- ✗
Remove logging and monitoring to improve performance
Why it's wrong here
Logging is critical for security and troubleshooting.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.