Skip to content
BytePatterns

AIF-C01 · Domain 5: Security, Compliance, and Governance for AI Solutions · 14% of the exam

Task 5.2: Recognize governance and compliance regulations for AI systems.

The AWS services that record, assess and report on an AI workload, data governance across the lifecycle, and the review processes and frameworks, such as the Generative AI Security Scoping Matrix, that keep it compliant.

Study it

  • Governance services: Config, Inspector, Artifact, CloudTrail, Trusted Advisor

    Lesson coming

  • Data governance and review processes; the Generative AI Security Scoping Matrix

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

For an audit, a company must keep the full text of every prompt sent to Amazon Bedrock and every response returned, stored in Amazon S3. Which Amazon Bedrock feature provides this?

  1. AAWS CloudTrail management events for Amazon Bedrock
  2. BModel invocation logging
  3. CAmazon Bedrock Guardrails sensitive information filters
  4. DAWS Artifact
Show the answer and why
  • AAWS CloudTrail management events for Amazon Bedrock

    Incorrect

    CloudTrail records API calls to Amazon Bedrock as events, showing who took which action. Collecting the full request and response data is the job of model invocation logging.

  • BModel invocation logging

    Correct

    Model invocation logging collects the full request data, response data and metadata for invocations and publishes them to Amazon CloudWatch Logs or Amazon S3. It is disabled by default.

  • CAmazon Bedrock Guardrails sensitive information filters

    Incorrect

    Sensitive information filters detect and mask PII in prompts and responses. They do not keep a record of every interaction.

  • DAWS Artifact

    Incorrect

    AWS Artifact provides AWS security and compliance reports, not logs of your own model interactions.

CloudTrail tells you who called Bedrock; model invocation logging tells you what was asked and answered. Audit trails for AI interactions often need both.

Question 2 · choose 2

A company's AI governance policy requires two things for its Amazon SageMaker AI endpoints: a record of who changed an endpoint and when, and continuous evaluation of the endpoints' configurations against the company's rules, with noncompliant resources flagged. Which AWS services meet these requirements? (Choose TWO.)

  1. AAmazon Inspector
  2. BAWS CloudTrail
  3. CAWS Artifact
  4. DAmazon Macie
  5. EAWS Config
Show the answer and why
  • AAmazon Inspector

    Incorrect

    Inspector scans workloads for software vulnerabilities and unintended network exposure. It does not track who changed a configuration.

  • BAWS CloudTrail

    Correct

    CloudTrail records actions taken by a user, role or AWS service as events, which shows who changed a resource and when.

  • CAWS Artifact

    Incorrect

    AWS Artifact provides AWS compliance reports such as ISO and SOC reports. It does not evaluate your resources.

  • DAmazon Macie

    Incorrect

    Macie discovers sensitive data in Amazon S3. It does not audit changes to SageMaker AI endpoints.

  • EAWS Config

    Correct

    AWS Config rules evaluate resource configuration settings, and Config flags resources that do not comply and continuously evaluates them as they are created or changed.

CloudTrail answers who did what and when; Config answers what a resource looks like and whether it complies with your rules.

Question 3 · choose 1

A European company's data residency rules require that its Amazon Bedrock inference requests are processed only within the EU. It also wants Bedrock to route requests across several Regions to handle traffic peaks. Which option meets both needs?

  1. AA global cross-Region inference profile
  2. BProvisioned Throughput attached to a cross-Region inference profile
  3. CA geographic cross-Region inference profile for the EU
  4. DCalls to whichever Region outside the EU responds fastest
Show the answer and why
  • AA global cross-Region inference profile

    Incorrect

    Global profiles can route requests to any supported commercial Region worldwide. AWS recommends them for cost savings without geographic restrictions, not for data residency.

  • BProvisioned Throughput attached to a cross-Region inference profile

    Incorrect

    Inference profiles currently do not support Provisioned Throughput, so this combination is not available.

  • CA geographic cross-Region inference profile for the EU

    Correct

    Geographic profiles route requests only to Regions within the chosen geography, such as the EU, and AWS recommends them when there are data residency requirements.

  • DCalls to whichever Region outside the EU responds fastest

    Incorrect

    Processing outside the EU breaks the company's residency rule, whatever the latency benefit.

Data residency is a governance requirement that shapes architecture: geographic cross-Region inference spreads load while keeping processing inside the chosen geography.

Question 4 · choose 1

A company builds its own customer support chatbot. It retrieves company data with Retrieval Augmented Generation and calls an existing third-party foundation model through Amazon Bedrock APIs, without changing the model. In the Generative AI Security Scoping Matrix, which scope is this?

  1. AScope 2, enterprise app
  2. BScope 4, fine-tuned models
  3. CScope 5, self-trained models
  4. DScope 3, pre-trained models
Show the answer and why
  • AScope 2, enterprise app

    Incorrect

    Scope 2 is using a third-party enterprise application that has generative AI features built in. This company builds its own application.

  • BScope 4, fine-tuned models

    Incorrect

    Scope 4 means refining a third-party model with your own data to create a new model. Here the model is used unchanged.

  • CScope 5, self-trained models

    Incorrect

    Scope 5 means training a model from scratch on data you own or acquire.

  • DScope 3, pre-trained models

    Correct

    Scope 3 covers building your own application on an existing third-party foundation model through an API; AWS gives a RAG chatbot on Amazon Bedrock as its example.

The scopes run from 1 (consumer app) to 5 (self-trained model) by how much of the model and data you own, and the security work grows with each step.

Question 5 · choose 1

A compliance officer needs AWS's own ISO certifications and SOC reports to include in an audit package for an AI workload hosted on AWS. Where can the officer download them?

  1. AAWS CloudTrail
  2. BAWS Artifact
  3. CAWS Config
  4. DAmazon Inspector
Show the answer and why
  • AAWS CloudTrail

    Incorrect

    CloudTrail records actions taken in your account; it does not provide AWS's compliance reports.

  • BAWS Artifact

    Correct

    AWS Artifact provides on-demand downloads of AWS security and compliance documents, such as ISO reports and SOC reports.

  • CAWS Config

    Incorrect

    AWS Config records and evaluates your resource configurations; it is not a library of AWS's reports.

  • DAmazon Inspector

    Incorrect

    Inspector scans your workloads for vulnerabilities; it does not provide AWS's certifications.

Artifact holds AWS's evidence for the "of the cloud" side; your own records come from services such as CloudTrail and Config.

Question 6 · choose 1

A company fine-tunes a model on a mix of public product data and data classified as confidential. According to the Generative AI Security Scoping Matrix, how should the resulting model be treated?

  1. AAs public, because most of the training data was public
  2. BAs unclassified, because a model is not data
  3. CAt the confidential level, with inference limited to authorized users
  4. DAt whatever sensitivity level the model provider assigned to the original base model
Show the answer and why
  • AAs public, because most of the training data was public

    Incorrect

    The guidance is to classify the model at the highest sensitivity level used in training, not the most common one.

  • BAs unclassified, because a model is not data

    Incorrect

    The matrix treats the trained model as carrying the classification of its training data.

  • CAt the confidential level, with inference limited to authorized users

    Correct

    For Scopes 4 and 5, the resulting model should be classified at the highest level of data sensitivity used during training, and inference access restricted to users authorized for that classification.

  • DAt whatever sensitivity level the model provider assigned to the original base model

    Incorrect

    Once the company fine-tunes with its own data, the classification of that data drives how the new model must be handled.

A model trained on confidential data can reveal it, so the model inherits the highest classification of its training data.

Question 7 · choose 1

An operations team wants to watch Amazon Bedrock usage metrics for its application on a dashboard and be alerted automatically when invocation errors or latency rise above a threshold. Which AWS service fits?

  1. AAmazon CloudWatch
  2. BAWS Artifact
  3. CAWS Glue Data Catalog
  4. DAmazon Bedrock Prompt Management
Show the answer and why
  • AAmazon CloudWatch

    Correct

    Amazon Bedrock publishes metrics to CloudWatch, which provides operational visibility with metrics, alarms and dashboards.

  • BAWS Artifact

    Incorrect

    AWS Artifact provides AWS compliance reports; it does not monitor your application.

  • CAWS Glue Data Catalog

    Incorrect

    The Data Catalog stores metadata about data sources; it does not raise alarms on metrics.

  • DAmazon Bedrock Prompt Management

    Incorrect

    Prompt Management stores and versions prompts; it does not monitor invocations.

Monitoring and observation are part of AI governance: metrics and alarms in CloudWatch, API records in CloudTrail, full interactions in invocation logs.

Question 8 · choose 2

A company stores model invocation logs and training datasets in Amazon S3. Its data governance policy requires a fixed retention period and an audit record of who accessed or changed the data. Which actions support this policy? (Choose TWO.)

  1. AMake the bucket public so auditors can browse the data
  2. BDisable logging to reduce storage costs
  3. CCopy all data to every team's account by default
  4. DConfigure S3 Lifecycle rules that expire objects after the retention period
  5. ERecord actions on the data and its resources with AWS CloudTrail
Show the answer and why
  • AMake the bucket public so auditors can browse the data

    Incorrect

    Public access widens exposure; access should follow least privilege.

  • BDisable logging to reduce storage costs

    Incorrect

    Turning off logging removes the audit record that the policy requires.

  • CCopy all data to every team's account by default

    Incorrect

    Too much access lets data become unregulated across applications and data stores, which increases the risk of unauthorized access.

  • DConfigure S3 Lifecycle rules that expire objects after the retention period

    Correct

    S3 Lifecycle expiration actions delete objects when they reach a defined age, which enforces a retention period.

  • ERecord actions on the data and its resources with AWS CloudTrail

    Correct

    CloudTrail records actions taken by users, roles and AWS services as events, which supports operational and risk auditing, governance and compliance.

Data governance spans the whole lifecycle: retention and deletion rules, access control, and logs that show who did what.

Question 9 · choose 1

A company wants a service that inspects its AWS environment and recommends where it can save money, improve availability and performance, or close security gaps across the accounts that host its AI workloads. Which service fits?

  1. AAmazon Macie
  2. BAWS Artifact
  3. CAmazon Bedrock Guardrails
  4. DAWS Trusted Advisor
Show the answer and why
  • AAmazon Macie

    Incorrect

    Macie discovers sensitive data in Amazon S3; it does not review the whole environment for cost or performance.

  • BAWS Artifact

    Incorrect

    AWS Artifact provides AWS compliance documents, not recommendations for your environment.

  • CAmazon Bedrock Guardrails

    Incorrect

    Guardrails filter model inputs and outputs; they do not inspect the AWS environment.

  • DAWS Trusted Advisor

    Correct

    Trusted Advisor inspects your AWS environment and makes recommendations when opportunities exist to save money, improve system availability and performance, or help close security gaps.

Trusted Advisor gives account-wide best-practice checks; it complements AI-specific controls rather than replacing them.

Practise domain 5 →Practise all domains →