Skip to content
BytePatterns

AIF-C01 · Domain 5: Security, Compliance, and Governance for AI Solutions · 14% of the exam

Task 5.1: Explain methods to secure AI systems.

IAM, encryption, private connectivity, guardrails and agent identity for AI workloads, data lineage, prompt injection and data leakage, and the grounding techniques that reduce hallucinations.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An application runs on Amazon EC2 instances in private subnets with no internet access. Security policy says its calls to Amazon Bedrock must not travel over the internet and the instances must not get public IP addresses. What should the team set up?

  1. AA NAT gateway in a public subnet for the private subnets to use
  2. BAn interface VPC endpoint for Amazon Bedrock, powered by AWS PrivateLink
  3. CAn Elastic IP address attached to each instance
  4. DAn Amazon CloudFront distribution placed in front of the Amazon Bedrock API endpoint
Show the answer and why
  • AA NAT gateway in a public subnet for the private subnets to use

    Incorrect

    A public NAT gateway lets private instances connect to services outside the VPC through an internet gateway. The Bedrock interface endpoint is reached without an internet gateway or NAT device.

  • BAn interface VPC endpoint for Amazon Bedrock, powered by AWS PrivateLink

    Correct

    An interface endpoint creates a private connection between the VPC and Amazon Bedrock, without an internet gateway, NAT device or VPN, and instances need no public IP addresses.

  • CAn Elastic IP address attached to each instance

    Incorrect

    Public addresses are exactly what the policy rules out, and with an interface endpoint, instances do not need public IP addresses to reach Amazon Bedrock.

  • DAn Amazon CloudFront distribution placed in front of the Amazon Bedrock API endpoint

    Incorrect

    CloudFront speeds up the distribution of web content to users. It does not provide private connectivity from a VPC to an AWS service.

Private access to an AWS service from a VPC is the job of an interface VPC endpoint (AWS PrivateLink); traffic then stays off the internet.

Question 2 · choose 1

A company's customer service agent can call an issue_refund tool. The company requires that refunds above $500 are always blocked, that the rule is enforced deterministically outside the agent's code, and that a cleverly worded prompt cannot talk the agent past it. Which capability fits best?

  1. AAmazon Bedrock AgentCore Identity
  2. BA rule in the agent's system prompt that forbids large refunds
  3. CPolicy in Amazon Bedrock AgentCore
  4. DAn Amazon Bedrock Guardrails content filter
Show the answer and why
  • AAmazon Bedrock AgentCore Identity

    Incorrect

    AgentCore Identity manages agent identities and credentials so agents can access AWS resources and third-party services on behalf of users. It does not evaluate the input values of each tool call.

  • BA rule in the agent's system prompt that forbids large refunds

    Incorrect

    Instructions inside the agent can be argued with or bypassed through manipulation; Policy in AgentCore moves security controls outside the agent code to reduce that risk.

  • CPolicy in Amazon Bedrock AgentCore

    Correct

    Policy in AgentCore intercepts agent traffic through AgentCore Gateway and evaluates each tool call against deterministic policies, including conditions on the call's input parameters, before allowing it.

  • DAn Amazon Bedrock Guardrails content filter

    Incorrect

    Content filters detect harmful content categories in prompts and responses. They do not authorize tool calls by parameter values such as a refund amount.

Identity answers who the agent acts for; Policy answers what it may do with each tool. Business limits on tool calls belong in Policy, outside the model's reach.

Question 3 · choose 1

Before a company uses data from its Amazon S3 data lake to customize a model, the security team wants an automated inventory of its S3 buckets and a scan that discovers objects containing sensitive data such as personally identifiable information (PII). Which AWS service fits best?

  1. AAWS Config
  2. BAmazon Inspector
  3. CAWS Trusted Advisor
  4. DAmazon Macie
Show the answer and why
  • AAWS Config

    Incorrect

    AWS Config records and evaluates resource configurations. It does not inspect the contents of objects for sensitive data.

  • BAmazon Inspector

    Incorrect

    Inspector scans EC2 instances, container images and Lambda functions for software vulnerabilities and network exposure, not data contents.

  • CAWS Trusted Advisor

    Incorrect

    Trusted Advisor recommends ways to save money, improve performance and close security gaps in your environment; it does not classify data.

  • DAmazon Macie

    Correct

    Macie is a data security service that discovers sensitive data with machine learning and pattern matching, and it inventories and evaluates your S3 general purpose buckets.

Secure data engineering starts with knowing what is in the training data. Macie finds sensitive data in S3 so it can be protected or removed first.

Question 4 · choose 2

A company's question-answering feature answers employees from HR documents stored in Amazon Bedrock Knowledge Bases. Testers find that some answers add facts that are not in the documents. Which measures help reduce or catch these hallucinations? (Choose TWO.)

  1. AGround every answer in passages retrieved from the HR documents (RAG)
  2. BRaise the temperature so the model explores more possible answers
  3. CRemove the retrieved passages from the prompt to save input tokens
  4. DIncrease the maximum response length so answers can be complete
  5. EApply the Amazon Bedrock Guardrails contextual grounding check
Show the answer and why
  • AGround every answer in passages retrieved from the HR documents (RAG)

    Correct

    Retrieval Augmented Generation has the model draw on relevant information from an authoritative source instead of filling gaps with false information.

  • BRaise the temperature so the model explores more possible answers

    Incorrect

    A higher temperature makes lower-probability tokens more likely and the output more random, which does not make it more faithful to the documents.

  • CRemove the retrieved passages from the prompt to save input tokens

    Incorrect

    Without the passages, the model has no source to ground its answer in, which is the gap RAG exists to fill.

  • DIncrease the maximum response length so answers can be complete

    Incorrect

    Response length only limits how many tokens are returned; it does not check answers against the source.

  • EApply the Amazon Bedrock Guardrails contextual grounding check

    Correct

    The contextual grounding check detects and filters hallucinations in responses when a reference source and a user query are provided, and it supports question answering.

Grounding reduces hallucinations at generation time; output validation, such as the contextual grounding check, catches the ones that remain.

Question 5 · choose 1

A company builds a customer-facing application on Amazon Bedrock. Under the AWS shared responsibility model, who is responsible for preventing prompt injection in that application?

  1. AThe company, because prompt injection is an application-level concern
  2. BAWS, because Amazon Bedrock is a fully managed service
  3. CThe model provider, because the attack targets its model
  4. DNobody, because foundation models cannot be manipulated through their prompts at all
Show the answer and why
  • AThe company, because prompt injection is an application-level concern

    Correct

    AWS secures the underlying infrastructure and the Bedrock service, but secure application development and preventing vulnerabilities such as prompt injection lie with the customer.

  • BAWS, because Amazon Bedrock is a fully managed service

    Incorrect

    AWS is responsible for the infrastructure and the Amazon Bedrock service itself, not for the customer's application code and prompts.

  • CThe model provider, because the attack targets its model

    Incorrect

    Prompt injection is compared to SQL injection: the customer prevents it in their own application, just as with a secure database engine.

  • DNobody, because foundation models cannot be manipulated through their prompts at all

    Incorrect

    Prompt injection is a real, documented vulnerability, and customers must take measures to prevent it in their code.

As with SQL injection on a managed database, the service is secured by AWS but the application that builds prompts is secured by the customer.

Question 6 · choose 1

An analytics team should be able to invoke one approved foundation model in Amazon Bedrock and nothing else in the service. How should an administrator grant this access?

  1. AAttach the AdministratorAccess managed policy to the team's role
  2. BShare one IAM user's access keys with the whole team
  3. CAdd the approved model's name to the application's system prompt
  4. DUse an IAM policy that allows invoking only that model's ARN
Show the answer and why
  • AAttach the AdministratorAccess managed policy to the team's role

    Incorrect

    Administrator access grants far more than one model; IAM best practice is to apply least-privilege permissions.

  • BShare one IAM user's access keys with the whole team

    Incorrect

    Shared long-term credentials defeat accountability; IAM best practice is to use roles and temporary credentials, scoped to what each identity needs.

  • CAdd the approved model's name to the application's system prompt

    Incorrect

    A prompt is not an access control. Permissions to call Amazon Bedrock are managed with IAM.

  • DUse an IAM policy that allows invoking only that model's ARN

    Correct

    IAM controls who can perform which Amazon Bedrock actions on which resources, and least privilege means granting only the permissions required, here invocation of one model.

Access to AI services is controlled like any AWS API: IAM identities, policies scoped to specific actions and resources, and least privilege.

Question 7 · choose 1

A security team requires that the company's custom models in Amazon Bedrock are encrypted with keys the team controls itself and whose use it can audit. Which option meets this requirement?

  1. AEncrypt the custom models with customer managed keys in AWS KMS
  2. BKeep the default encryption with AWS owned keys
  3. CStore the model weights unencrypted in a private S3 bucket with no public access
  4. DUse AWS Secrets Manager to rotate an encryption password
Show the answer and why
  • AEncrypt the custom models with customer managed keys in AWS KMS

    Correct

    Amazon Bedrock lets you encrypt custom models with customer managed keys that you manage yourself in AWS Key Management Service.

  • BKeep the default encryption with AWS owned keys

    Incorrect

    Custom models are encrypted with AWS owned keys by default, but you cannot view, manage or use those keys, or audit their use.

  • CStore the model weights unencrypted in a private S3 bucket with no public access

    Incorrect

    Custom models are managed and stored by AWS and encrypted at rest automatically; the requirement is control of the keys, which this does not give.

  • DUse AWS Secrets Manager to rotate an encryption password

    Incorrect

    Secrets Manager stores and rotates secrets such as credentials; it is not the key management option Amazon Bedrock offers for custom models.

AWS owned keys protect data by default with no effort; customer managed KMS keys add control and an audit trail when policy requires them.

Question 8 · choose 1

An AI agent needs to read and update each user's calendar in a third-party service on that user's behalf, using the user's own OAuth authorization, without credentials hard-coded in the agent. Which AWS capability is designed for this?

  1. APolicy in Amazon Bedrock AgentCore
  2. BAmazon Bedrock AgentCore Identity
  3. CAmazon Bedrock AgentCore Memory
  4. DAmazon Macie
Show the answer and why
  • APolicy in Amazon Bedrock AgentCore

    Incorrect

    Policy decides whether each tool call is allowed under your rules; it does not obtain or manage the user's credentials for a third-party service.

  • BAmazon Bedrock AgentCore Identity

    Correct

    AgentCore Identity is an identity and credential management service for AI agents that lets agents and tools access AWS resources and third-party services on behalf of users.

  • CAmazon Bedrock AgentCore Memory

    Incorrect

    Memory stores conversation context and long-term knowledge for agents, not access credentials.

  • DAmazon Macie

    Incorrect

    Macie discovers sensitive data in Amazon S3; it does not handle authorization for agents.

Agent security splits into who the agent acts for (Identity) and what it is allowed to do (Policy); both live outside the model.

Question 9 · choose 2

Auditors ask a company to show where the training data for each of its models came from and how each model was built. Which AWS capabilities help document data origins and model details? (Choose TWO.)

  1. AAmazon Polly
  2. BAmazon CloudFront
  3. CThe AWS Glue Data Catalog
  4. DAmazon SageMaker Model Cards
  5. EAWS Secrets Manager
Show the answer and why
  • AAmazon Polly

    Incorrect

    Amazon Polly converts text to speech; it keeps no record of data origins.

  • BAmazon CloudFront

    Incorrect

    CloudFront speeds up distribution of web content to users; it does not document data or models.

  • CThe AWS Glue Data Catalog

    Correct

    The Data Catalog is a centralized repository that stores metadata about the organization's data sources, which helps trace where data comes from.

  • DAmazon SageMaker Model Cards

    Correct

    Model Cards document a model's intended use, training details and metrics, and evaluation results in one place for governance.

  • EAWS Secrets Manager

    Incorrect

    Secrets Manager stores and rotates credentials, not data lineage or model documentation.

Cataloged data sources plus documented models give an audit trail from data origin to deployed model.

Question 10 · choose 1

A company plans to fine-tune a model in Amazon Bedrock on support tickets that include some confidential customer details. The resulting assistant must never expose those details in its answers. What should the company do before training?

  1. ANothing, because Amazon Bedrock deletes training data after the job
  2. BRaise the temperature so the model is less likely to repeat details
  3. CFilter the confidential data out of the training dataset
  4. DEncrypt the model with a customer managed key so the details cannot leak
Show the answer and why
  • ANothing, because Amazon Bedrock deletes training data after the job

    Incorrect

    Bedrock does not keep the data after the job, but the fine-tuned model itself can replay some of its fine-tuning data in completions.

  • BRaise the temperature so the model is less likely to repeat details

    Incorrect

    Temperature changes output randomness; it is not a data protection control.

  • CFilter the confidential data out of the training dataset

    Correct

    Fine-tuned models can replay some of the fine-tuning data while generating completions, so confidential data should be filtered out of the training data first.

  • DEncrypt the model with a customer managed key so the details cannot leak

    Incorrect

    Encryption protects the stored model at rest; it does not stop the model from reproducing training data in its answers.

Data that goes into training can come back out in generation. Prevent leakage at the source by removing sensitive data before fine-tuning.

Practise domain 5 →Practise all domains →