AIP-C01 · domain
AI Safety Security And Governance
Practise AWS Certified Generative AI Developer - Professional (AIP-C01) (AIP-C01) AI Safety Security And Governance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice AI Safety Security And Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about AI Safety Security And Governance
AI Safety Security And Governance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common AI Safety Security And Governance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All AI Safety Security And Governance questions (39)
Click any question to see the full explanation, or start a practice session above.
Your organization needs to ensure that only authorized IAM users can access specific foundation models in Bedrock. Which configuration is required?
Medium2A firm wants to audit the specific version of a foundation model used for every inference request. How can they achieve this?
Hard3A company is using RAG with Amazon Bedrock Knowledge Bases. They need to ensure that users can only retrieve documents they are authorized to see. How should this be implemented?
Hard4Which TWO steps are required to properly secure Bedrock Knowledge Bases?
Medium5A researcher wants to ensure the model output does not reference external websites. How can this be enforced?
Hard6A team is storing sensitive documents for RAG. They need to ensure that the document chunks in the vector database are encrypted at rest. How?
Medium7When fine-tuning a model on Amazon Bedrock, which THREE security considerations are critical?
Hard8A developer needs to ensure that an application only uses approved foundation models. How can they govern this centrally?
Medium9Which service should be used to monitor the cost and usage of API requests made to Amazon Bedrock models?
Easy10An enterprise requires that all Generative AI model outputs are logged for compliance, but logs must not contain any PII. How can this be achieved in an AWS environment using Amazon Bedrock?
Hard11You are designing a secure Generative AI architecture on AWS. Which TWO of the following are recommended practices for securing the data ingestion pipeline for RAG?
Medium12To prevent accidental deletion of a Knowledge Base, which feature should be applied?
Easy13You are deploying a Generative AI application using Amazon SageMaker JumpStart. You need to ensure that the model endpoint is protected against prompt injection attacks. Which approach is most effective?
Medium14A developer needs to monitor their Bedrock application for potential abuse. Which TWO features should they utilize?
Medium15Which THREE services/features are essential for establishing a secure perimeter for an Amazon Bedrock deployment?
Hard16Which THREE strategies should be implemented to ensure responsible AI practices in a production workload?
Hard17You need to ensure that all data sent to an Amazon Bedrock model is encrypted in transit using private connectivity. What is the recommended service?
Medium18A company is using a third-party model via Bedrock and needs to ensure that the model provider does not use their data to train their base models. What must they do?
Hard19Which THREE items should be included in an AI application's security documentation for an audit?
Hard20When implementing a RAG-based application, which TWO of the following ensure document security?
Medium21To ensure compliance with data residency requirements, you must restrict which AWS regions your Generative AI application can process data. What is the most effective way to enforce this?
Medium22A developer needs to share a Bedrock prompt template with another team securely. What is the recommended method?
Easy23A business wants to restrict the length of generated outputs to prevent high costs. How can this be done?
Medium24When dealing with PII in Generative AI, which THREE practices are recommended?
Hard25Which AWS tool is used to monitor the performance and latency of an application calling Bedrock?
Easy26What is the role of an AWS Service Control Policy (SCP) in an AI governance framework?
Easy27An organization is concerned about 'Model Hallucinations' and needs a way to ground model outputs in trusted company documents. Which service supports this?
Hard28A company is using Amazon Q Business. How can they restrict access to specific data sources for different groups of users?
Easy29Which TWO of the following actions can help mitigate the risk of 'prompt injection' in a Generative AI application?
Medium30You are building a chat application and notice sensitive internal data is leaking in responses. You have enabled Guardrails. What else should be checked?
Medium31Which service should be used to provide secure identity and access management for an application accessing Bedrock?
Easy32Which TWO features of Amazon Bedrock provide governance capabilities?
Medium33A company requires that every AI-generated document must include a watermark for traceability. How can this be handled in Bedrock?
Hard34A team wants to track who accessed a model and when. Which service provides this audit log?
Easy35Which THREE of the following are components of a robust AI governance framework in an AWS environment?
Hard36A company is using Amazon Bedrock to build a customer support chatbot and needs to ensure that PII is masked before the request reaches the foundation model. Which feature should the developer implement?
Easy37Your organization wants to evaluate the quality and safety of model outputs using a formal testing framework. Which service is designed for this?
Medium38A developer wants to prevent the Generative AI application from producing content related to hate speech or violence. What is the most efficient configuration in Amazon Bedrock?
Easy39A firm needs to ensure that all Generative AI model training data, if used for fine-tuning, is compliant with GDPR. Where should the training data reside?
HardOther domains
All AIP-C01 exam domains
Frequently asked questions
- What does the AI Safety Security And Governance domain cover on the AIP-C01 exam?
- AI Safety Security And Governance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 39 AI Safety Security And Governance questions in the AIP-C01 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only AI Safety Security And Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.