Skip to content
BytePatterns

AIB-C01 · Domain 3: AI Governance and Responsible AI Leadership · 24% of the exam

Task 3.3: Identify enterprise AI risks and direct mitigation strategies.

Controls and monitoring for AI in production, bias that enters at every lifecycle stage, harmful content and intellectual property exposure, and reliability risks such as hallucinations, degrading data and model drift.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

A hiring platform balanced its training data across demographic groups before launch. Its risk team now proposes to close the bias workstream because "bias was handled in the data". Which facts argue against closing it? (Choose TWO.)

  1. AContent filters in a guardrail remove bias from any model's decisions
  2. BBias can enter through how examples were labeled and who labeled them
  3. CBias can emerge after launch as inputs and users drift from the baseline
  4. DBias exists only in model architectures, never in data
  5. ELarger models are trained on so much data that they cannot be biased
Show the answer and why
  • AContent filters in a guardrail remove bias from any model's decisions

    Incorrect

    Content filters detect categories such as hate or insults. They do not correct unequal outcomes in a screening model.

  • BBias can enter through how examples were labeled and who labeled them

    Correct

    AWS guidance asks teams to document the characteristics of data contributors and annotators, including potential sources of unwanted bias that could affect system behavior.

  • CBias can emerge after launch as inputs and users drift from the baseline

    Correct

    Production performance must be baselined and monitored with drift detection, because behavior can deviate from what was measured at release.

  • DBias exists only in model architectures, never in data

    Incorrect

    Data is a major source of unwanted bias, which is why AWS asks teams to assess datasets for representation across groups.

  • ELarger models are trained on so much data that they cannot be biased

    Incorrect

    Scale does not guarantee fairness; any model must be evaluated for unwanted bias across the stakeholder groups it affects.

Bias can enter at several stages: data collection, labeling, design and operation. Balancing the training data is one control, not the end of the work; fairness needs measuring before release and monitoring for drift after it.

Question 2 · choose 1

A video game publisher is launching a public chat character powered by generative AI. Players will try to make it produce insulting, violent or sexual content, and some will attempt prompt attacks. Which control addresses this most directly?

  1. AA word filter that blocks the names of competing games and their characters
  2. BContent filters on inputs and responses, tuned per harm category
  3. CA contextual grounding check on the character's replies
  4. DA system prompt asking the character to always be polite
Show the answer and why
  • AA word filter that blocks the names of competing games and their characters

    Incorrect

    Word filters block specific words or phrases, such as competitor names. A fixed list cannot cover the open range of harmful content players will attempt.

  • BContent filters on inputs and responses, tuned per harm category

    Correct

    Amazon Bedrock Guardrails content filters detect and filter harmful content in prompts and responses across categories such as hate, insults, sexual, violence, misconduct and prompt attack, with configurable strength.

  • CA contextual grounding check on the character's replies

    Incorrect

    Grounding checks detect responses not supported by a reference source. They address hallucinations, not harmful content.

  • DA system prompt asking the character to always be polite

    Incorrect

    Instructions in the prompt help shape behavior but can be circumvented by prompt attacks; they are not a filter on inputs and outputs.

Harmful content risk is managed with filters that check both what users send and what the model returns, tuned to the use case. A game for a broad audience needs those filters across categories, including attempts to override the system's instructions.

Question 3 · choose 1

A home-goods retailer will use generative AI to write about 20,000 product descriptions a month for its websites. Its general counsel's main concern is third-party claims that the published text infringes copyright. There is no budget for lawyers to review each description, and marketing wants to start this quarter. Which approach best reduces the company's exposure to these claims?

  1. ASelf-host an open-weight model on the retailer's own instances, so that no outside provider handles the text
  2. BAdd a notice to each product page stating that the description was written with AI
  3. CHave the copy team spot-check a small sample of descriptions each week for copied passages
  4. DUse a generally available Amazon model that AWS indemnifies, with its filtering features left enabled
Show the answer and why
  • ASelf-host an open-weight model on the retailer's own instances, so that no outside provider handles the text

    Incorrect

    Self-hosting controls where the text is processed, not what the output contains. A model the retailer runs itself is not among the services AWS indemnifies, so the retailer alone bears any copyright claim.

  • BAdd a notice to each product page stating that the description was written with AI

    Incorrect

    Saying how the text was made does not change whether it copies protected work, and a notice gives the retailer no defense or cover if a rights holder brings a claim.

  • CHave the copy team spot-check a small sample of descriptions each week for copied passages

    Incorrect

    Sampling may catch some copied passages, but most of the 20,000 texts go unchecked each month and the retailer still carries the full cost of any claim on its own.

  • DUse a generally available Amazon model that AWS indemnifies, with its filtering features left enabled

    Correct

    AWS offers an uncapped IP indemnity against third-party copyright claims for output of the generative AI services it lists, such as Amazon models, provided customers use them responsibly, for example by not disabling filtering features.

Intellectual property exposure from generated content is a business risk that leaders can reduce through vendor and model choices. At this volume, a contractual indemnity that covers the output shifts the cost of copyright claims in a way that hosting choices, notices and sampling cannot, as long as the company meets its conditions, such as keeping filters enabled.

Question 4 · choose 1

After a content migration, a manufacturer's AI assistant for field technicians began giving outdated and contradictory repair steps. The model and prompts have not changed; investigators found duplicated and superseded manuals in the source library. What should the service owner put in place to catch this kind of problem early?

  1. AData observability over the source content's lineage and quality
  2. BA switch to a newer foundation model with a larger context window
  3. CA lower temperature so that answers are more consistent
  4. DA monthly survey asking technicians whether they like the assistant
Show the answer and why
  • AData observability over the source content's lineage and quality

    Correct

    AWS guidance is to establish data observability, tracking data lineage, provenance and quality metrics to identify gaps, and to evaluate datasets periodically as requirements change.

  • BA switch to a newer foundation model with a larger context window

    Incorrect

    The model was not the cause. A newer model would read the same duplicated and superseded manuals.

  • CA lower temperature so that answers are more consistent

    Incorrect

    Lower temperature makes outputs more deterministic, but it would consistently repeat whatever the outdated sources say.

  • DA monthly survey asking technicians whether they like the assistant

    Incorrect

    User feedback is useful, but a monthly satisfaction survey detects problems late and does not show which source data degraded.

The reliability of an AI system depends on the quality of the data it draws on. When source content degrades, answers degrade with it, so the data itself needs monitoring: where it came from, how fresh it is and whether it meets quality standards.

Question 5 · choose 1

A bank's customer assistant has run with Amazon Bedrock Guardrails in production for two months. Complaint data shows that about one in ten legitimate questions about debt hardship is blocked, because the misconduct content filter, set to high strength, treats them as harmful. The product team wants these questions answered. The risk committee will accept a change only if it is shown, before it reaches customers, not to let requests about fraud or other crimes through. What should the risk owner require?

  1. ATurn off the misconduct filter and rely on the guardrail's remaining filters for hate, insults and violence
  2. BLower the misconduct filter to low strength in production now and watch the complaint data afterward
  3. CKeep the current settings and change the blocked message to suggest that customers call the bank
  4. DTest candidate settings in detect mode, review false blocks and misses, then deploy the best one
Show the answer and why
  • ATurn off the misconduct filter and rely on the guardrail's remaining filters for hate, insults and violence

    Incorrect

    The misconduct category covers requests about criminal activity and defrauding people, which the other categories do not, so removing it lets exactly those requests through.

  • BLower the misconduct filter to low strength in production now and watch the complaint data afterward

    Incorrect

    A lower strength may be the right setting, but changing it live leaves its effect on fraud-related requests untested until customers are exposed, which the committee will not accept.

  • CKeep the current settings and change the blocked message to suggest that customers call the bank

    Incorrect

    A clearer blocked message softens the experience, but one in ten legitimate hardship questions would still go unanswered by the assistant.

  • DTest candidate settings in detect mode, review false blocks and misses, then deploy the best one

    Correct

    Detect mode records what a guardrail would block without acting on it, so the team can compare strengths, analyze false positives and negatives and deploy only after confirming the setting works as expected.

A risk control in production needs evidence on how well it works, not only whether it is switched on. When a control blocks too much, the answer is to measure both its false blocks and its misses, adjust it and prove the new setting before customers see it, rather than removing the control or loosening it blind.

Question 6 · choose 1

A publisher drafts articles with a generally available Amazon model on Amazon Bedrock, which AWS lists among the generative AI services covered by its IP indemnity, and it keeps the available filters enabled. To save storage, the content team keeps only the final edited articles and deletes the prompts, source material and raw model output after each session. The general counsel wants the company to be able to rely on the indemnity if a copyright claim about an article arrives years from now. Which change should the general counsel ask for?

  1. AArchive the final published version of each article for the long term
  2. BRely on AWS to supply the prompts and outputs if a claim ever arrives
  3. CLog each article's prompts, inputs and model output and keep them
  4. DFlag in the content system which articles were drafted with AI help
Show the answer and why
  • AArchive the final published version of each article for the long term

    Incorrect

    The published text alone does not show what went into the model or what it returned, and AWS's terms make the indemnity depend on records sufficient to evaluate eligibility, including whether the inputs themselves infringed.

  • BRely on AWS to supply the prompts and outputs if a claim ever arrives

    Incorrect

    AWS's terms require the customer to retain and provide the records, and model invocation logging, which collects model input and output data, is disabled by default.

  • CLog each article's prompts, inputs and model output and keep them

    Correct

    The indemnity applies only if the customer retains and provides records sufficient to evaluate eligibility; model invocation logging collects the full request and response data and keeps it until the logging configuration is deleted.

  • DFlag in the content system which articles were drafted with AI help

    Incorrect

    A flag shows that AI was used, but not what went into the model or what came out, which is what eligibility can turn on, such as whether the inputs infringed.

An indemnity shifts IP risk only while its conditions are met. AWS's terms ask the customer to keep records that let eligibility be evaluated, and eligibility can depend on what went into the model and what came out. Keeping the prompts, inputs and outputs behind each published piece keeps that protection usable when a claim arrives years later.

Question 7 · choose 1

A logistics company's AI route planner occasionally produces impossible routes, and one faulty component recently took down the whole planning system. Which design principles address these reliability risks?

  1. AA single larger component that handles every planning step itself
  2. BModular design that isolates faults, plus output checks
  3. CRemoving validation to make responses faster
  4. DRetraining the model every week regardless of errors
Show the answer and why
  • AA single larger component that handles every planning step itself

    Incorrect

    A monolith makes one failure stop everything, the opposite of fault isolation.

  • BModular design that isolates faults, plus output checks

    Correct

    AWS recommends a modular architecture that decouples critical components to isolate failures, and multiple validation layers that check outputs for plausibility and consistency before they reach users.

  • CRemoving validation to make responses faster

    Incorrect

    Removing checks lets impossible routes reach drivers.

  • DRetraining the model every week regardless of errors

    Incorrect

    Retraining on a schedule does not isolate failures or catch bad outputs before use.

Reliability is designed in. Decoupled components contain failures, and validation layers catch implausible outputs, so a single error does not become an operational incident.

Question 8 · choose 2

A bank is threat modeling a new generative AI assistant that will take actions in customer accounts. According to AWS's security guidance, which steps belong at the start of the threat model? (Choose TWO.)

  1. ARely on the existing perimeter firewalls as the main protection
  2. BSkip logging decisions until after launch
  3. CDefine how much agency the model and agents will have
  4. DTreat the assistant like any static marketing website
  5. EDefine where authentication and authorization will be performed
Show the answer and why
  • ARely on the existing perimeter firewalls as the main protection

    Incorrect

    AWS notes that traditional controls such as perimeter protection do not cover many new AI threat vectors.

  • BSkip logging decisions until after launch

    Incorrect

    Logging levels should be decided up front because they determine the ability to monitor, audit and respond to incidents.

  • CDefine how much agency the model and agents will have

    Correct

    AWS recommends beginning threat modeling by defining the level of agency provided to the model and any agents, including their autonomy and decision-making power.

  • DTreat the assistant like any static marketing website

    Incorrect

    Generative AI applications bring threats that ordinary web applications do not, such as prompt injection.

  • EDefine where authentication and authorization will be performed

    Correct

    AWS's next step is to clearly define where authentication and authorization should be performed.

Threat modeling for generative AI starts with what the system is allowed to do and who is allowed to make it do it. Those decisions shape every control that follows.

Question 9 · choose 1

Data scientists at an insurer download claim data to their laptops to prepare training sets for AI models. The security team has data loss prevention tools on the laptops. What risk control does AWS guidance favor?

  1. AKeep the data in a governed cloud environment
  2. BRely on the laptop data loss prevention tools
  3. CEmail the data to team members who need it
  4. DBan AI work on claim data entirely
Show the answer and why
  • AKeep the data in a governed cloud environment

    Correct

    AWS notes that keeping data contained in the cloud environment that security maintains protects against leaks, because once data reaches a local workstation, controlling access becomes almost impossible, even with data loss prevention tools.

  • BRely on the laptop data loss prevention tools

    Incorrect

    AWS points out that controlling data on local workstations is very hard even with data loss prevention tools.

  • CEmail the data to team members who need it

    Incorrect

    Email spreads copies further and removes control.

  • DBan AI work on claim data entirely

    Incorrect

    A ban stops valuable work; containment allows it to continue safely.

Data spread is a risk that grows with every copy. Keeping AI work on sensitive data inside a governed environment lets organizations enable data science without losing control.

Question 10 · choose 1

Employees use an AI assistant that answers policy questions from internal documents. Some answers are wrong, and staff cannot tell which ones because they cannot see where an answer came from. Compliance wants staff to be able to check each answer against its source before acting on it. Which feature addresses this?

  1. ACitations in each answer pointing to source documents
  2. BA disclaimer on every answer that it may contain errors
  3. CA model fine-tuned on the policy documents
  4. DA lower temperature so answers are more consistent
Show the answer and why
  • ACitations in each answer pointing to source documents

    Correct

    Amazon Bedrock Knowledge Bases can include citations in generated responses so the original data source can be referenced and accuracy can be checked.

  • BA disclaimer on every answer that it may contain errors

    Incorrect

    A warning tells staff that errors are possible but not which answers are wrong or where to check them; citations let users look up the sources themselves.

  • CA model fine-tuned on the policy documents

    Incorrect

    A fine-tuned model answers from what it learned, with no source to show; retrieval augmented generation can present answers with source attribution and citations.

  • DA lower temperature so answers are more consistent

    Incorrect

    Temperature only shifts the model toward more probable words; consistent answers can still be wrong, and they still show no source.

Hallucination risk is easier to manage when users can check answers. Citations connect each response to its source so errors can be spotted and corrected before anyone acts on them.

Practise domain 3 →Practise all domains →