Skip to content
BytePatterns

AIP-C01 · Domain 3: AI Safety, Security, and Governance · 20% of the exam

Task 3.2: Implement data security and privacy controls.

Protecting data around a model: private connectivity, least-privilege access, PII detection and masking with Comprehend, Macie and guardrails, encryption and retention.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An application in private subnets with no internet gateway or NAT gateway must call Amazon Bedrock models. Security requires that the traffic stay on the AWS network, that calls through this path be allowed only for the two approved models, and that the control sit in the network path rather than only in application roles. What should the developer configure?

  1. AA NAT gateway in a public subnet with a security group that allows only the Bedrock endpoint addresses
  2. BAn interface VPC endpoint for bedrock-agent with an endpoint policy that lists the two models
  3. CA gateway VPC endpoint for Amazon Bedrock with a route table entry in each private subnet
  4. DAn interface VPC endpoint for bedrock-runtime with an endpoint policy that allows only the two approved models
Show the answer and why
  • AA NAT gateway in a public subnet with a security group that allows only the Bedrock endpoint addresses

    Incorrect

    Traffic through a NAT gateway goes to the public service endpoint, and the subnets were designed without internet egress.

  • BAn interface VPC endpoint for bedrock-agent with an endpoint policy that lists the two models

    Incorrect

    The bedrock-agent endpoint serves build-time agent APIs. Model inference calls use the bedrock-runtime endpoint.

  • CA gateway VPC endpoint for Amazon Bedrock with a route table entry in each private subnet

    Incorrect

    Gateway endpoints exist only for Amazon S3 and DynamoDB. Bedrock is reached through interface endpoints.

  • DAn interface VPC endpoint for bedrock-runtime with an endpoint policy that allows only the two approved models

    Correct

    An interface endpoint (AWS PrivateLink) reaches Bedrock without an internet gateway or NAT, and its endpoint policy restricts which actions and resources can be used through it.

Private access to Bedrock uses interface endpoints, one per API family: bedrock (control plane), bedrock-runtime (inference), bedrock-mantle, bedrock-agent and bedrock-agent-runtime. Endpoint policies add a network-path control on top of IAM.

Question 2 · choose 1

Before 6 million documents in 40 Amazon S3 buckets are ingested into a knowledge base, compliance must know exactly which objects contain personal data such as passport numbers and bank account numbers. New objects are added every day, findings must start an automated quarantine step, and the data must not be copied elsewhere for scanning. Which approach meets these requirements?

  1. ASend every document through Amazon Comprehend DetectPiiEntities from a Lambda function triggered by S3 events
  2. BEnable Macie automated sensitive data discovery and treat buckets without findings as free of personal data
  3. CRun recurring Amazon Macie discovery jobs on the buckets and send findings through EventBridge to a quarantine step
  4. DApply a guardrail sensitive information filter to the knowledge base so that any personal data is masked in its answers
Show the answer and why
  • ASend every document through Amazon Comprehend DetectPiiEntities from a Lambda function triggered by S3 events

    Incorrect

    Comprehend detects PII in text it is sent, but this only covers new uploads, needs custom code and conversion of each file to text, and leaves the existing archive unscanned.

  • BEnable Macie automated sensitive data discovery and treat buckets without findings as free of personal data

    Incorrect

    Automated discovery samples representative objects to give broad visibility. It does not inspect every object, so it cannot prove that an object is free of personal data.

  • CRun recurring Amazon Macie discovery jobs on the buckets and send findings through EventBridge to a quarantine step

    Correct

    Discovery jobs analyze the objects in the selected buckets on a schedule and report findings, and Macie publishes findings to EventBridge for automated processing.

  • DApply a guardrail sensitive information filter to the knowledge base so that any personal data is masked in its answers

    Incorrect

    Masking in answers protects output but does not tell compliance which stored objects contain personal data before ingestion.

Finding sensitive data at rest in S3 is Macie's job. Use scheduled discovery jobs when you need every object in scope inspected, and automated discovery when sampled, organization-wide visibility is enough. Findings flow to EventBridge for remediation.

Question 3 · choose 1

A call center generates summaries of transcripts with a model on Amazon Bedrock. Supervisors may read the summaries but must not see customers' names or phone numbers, and a summary that contains a full card number must not be shown at all. The rest of each summary must remain readable. Which guardrail configuration meets these requirements?

  1. AA word filter that lists the customers' names and phone numbers taken from the CRM each night
  2. BA content filter with the Misconduct category set to HIGH on the output of the summarization model
  3. CA sensitive information filter that masks NAME and PHONE and blocks card numbers
  4. DA sensitive information filter that blocks NAME, PHONE and the card number type in the output
Show the answer and why
  • AA word filter that lists the customers' names and phone numbers taken from the CRM each night

    Incorrect

    Word filters match exact words and phrases and would need constant updates, and they do not detect card numbers by pattern.

  • BA content filter with the Misconduct category set to HIGH on the output of the summarization model

    Incorrect

    Content filters detect harmful content categories, not personal data.

  • CA sensitive information filter that masks NAME and PHONE and blocks card numbers

    Correct

    Sensitive information filters can mask entity types, replacing them with tags such as {NAME}, or block the whole response when a type such as a card number is detected.

  • DA sensitive information filter that blocks NAME, PHONE and the card number type in the output

    Incorrect

    Blocking names and phone numbers would suppress nearly every summary instead of keeping the rest readable.

Sensitive information filters offer two actions per entity type: mask (anonymize and keep the response) and block (replace the whole response with the blocked message). Mixing them gives readable but safe output.

Question 4 · choose 2

A company enabled Amazon Bedrock model invocation logging to CloudWatch Logs and Amazon S3 for troubleshooting. The logs contain customers' email addresses and phone numbers in prompts and responses. Analysts must be able to search the logs without seeing that data, a small security team must be able to see it, and the S3 copies must be deleted after 90 days. Which actions meet these requirements? (Choose TWO.)

  1. ATurn off model invocation logging and rely on CloudTrail for troubleshooting
  2. BAdd an S3 Lifecycle rule to the logging bucket that expires the log objects after 90 days
  3. CAttach a CloudWatch Logs data protection policy to the log group and grant logs:Unmask only to the security team
  4. DRun Amazon Macie on the CloudWatch log group to mask personal data in the log events
  5. EEncrypt the log group with a customer managed AWS KMS key so that analysts cannot read personal data
Show the answer and why
  • ATurn off model invocation logging and rely on CloudTrail for troubleshooting

    Incorrect

    CloudTrail records API calls, not prompts and responses, so the team would lose the data it needs for troubleshooting.

  • BAdd an S3 Lifecycle rule to the logging bucket that expires the log objects after 90 days

    Correct

    Lifecycle expiration actions delete objects automatically after the configured age, which enforces the retention period.

  • CAttach a CloudWatch Logs data protection policy to the log group and grant logs:Unmask only to the security team

    Correct

    Data protection policies mask matching data at ingestion for all egress points, including Logs Insights, and only principals with logs:Unmask can see the original values.

  • DRun Amazon Macie on the CloudWatch log group to mask personal data in the log events

    Incorrect

    Macie analyzes data in Amazon S3. It does not mask CloudWatch Logs events.

  • EEncrypt the log group with a customer managed AWS KMS key so that analysts cannot read personal data

    Incorrect

    Encryption protects data at rest, but anyone allowed to read the log group still sees the plaintext values.

Logs that contain prompts are valuable and sensitive. Mask identifiers at ingestion with CloudWatch Logs data protection policies, gate unmasking with IAM, and enforce retention with S3 Lifecycle rules.

Question 5 · choose 1

A bank licenses a document-classification model from a vendor and must host the vendor's container image on a SageMaker AI real-time endpoint. The bank's reviewers cannot inspect the container code, so security requires that the running container cannot send data anywhere: not to the internet, not to other AWS services and not to anything in the bank's network. The model artifacts in Amazon S3 must still load, and the platform team wants to avoid building and maintaining extra network controls for this one endpoint. What should the developer configure?

  1. AAn interface VPC endpoint for the SageMaker runtime with an endpoint policy for the bank's roles
  2. BA customer managed AWS KMS key for the model artifacts and the endpoint's storage volume
  3. CAn execution role that allows only s3:GetObject on the bucket that holds the model artifacts
  4. DNetwork isolation on the model by setting EnableNetworkIsolation when the model is created
Show the answer and why
  • AAn interface VPC endpoint for the SageMaker runtime with an endpoint policy for the bank's roles

    Incorrect

    The endpoint controls the path that callers use to invoke the model. It does not limit where the container itself can send data.

  • BA customer managed AWS KMS key for the model artifacts and the endpoint's storage volume

    Incorrect

    Encryption protects data at rest. A running container can still read what it is given and send it out.

  • CAn execution role that allows only s3:GetObject on the bucket that holds the model artifacts

    Incorrect

    A narrow role limits AWS API calls made with its credentials, but the container could still reach the internet and send data out.

  • DNetwork isolation on the model by setting EnableNetworkIsolation when the model is created

    Correct

    With network isolation, the container cannot make outbound calls to any service and receives no AWS credentials, while SageMaker AI itself still downloads the model artifacts from Amazon S3.

For opaque third-party code, remove the container's ability to talk to the network at all. Network isolation does this without extra network design, and it can also be combined with a VPC when the artifact download must stay on private routes.

Question 6 · choose 1

An HR assistant's knowledge base ingests documents from one Amazon S3 bucket, and only the knowledge base's service role should ever read those objects. Security wants an alert within 15 minutes whenever any other principal reads an object in the bucket, and investigators must then be able to see which principal it was. The organization trail currently records management events only, and data event charges must stay limited to this one bucket. What should the team configure?

  1. AS3 data events for the bucket on a trail sent to CloudWatch Logs, with a metric filter and an alarm on other principals
  2. BS3 server access logging for the bucket delivered to CloudWatch Logs, with a metric filter and an alarm on unexpected requesters
  3. CIAM Access Analyzer for S3 findings on the bucket, sent to the security team through Amazon EventBridge
  4. DAmazon GuardDuty S3 Protection, with its findings for the bucket routed to the security team
Show the answer and why
  • AS3 data events for the bucket on a trail sent to CloudWatch Logs, with a metric filter and an alarm on other principals

    Correct

    Object reads are data events that a trail records only when you select them, and an advanced event selector can scope them to one bucket. CloudTrail delivers data events about every 5 minutes and can send them to CloudWatch Logs, where a metric filter and alarm flag other principals and each logged event shows who made the request.

  • BS3 server access logging for the bucket delivered to CloudWatch Logs, with a metric filter and an alarm on unexpected requesters

    Incorrect

    Server access logs are delivered within a few hours, which misses the 15-minute requirement.

  • CIAM Access Analyzer for S3 findings on the bucket, sent to the security team through Amazon EventBridge

    Incorrect

    Access Analyzer reports bucket policies and grants that allow access from outside the account. It does not record who read individual objects.

  • DAmazon GuardDuty S3 Protection, with its findings for the bucket routed to the security team

    Incorrect

    GuardDuty S3 Protection reports suspicious or anomalous activity patterns. It does not alert on every read by a principal other than the expected role.

"Who read this object" is a data plane question, so it needs CloudTrail data events, which are off by default and can be limited to the resources that matter. Sending them to CloudWatch Logs turns an audit record into a near-real-time alarm.

Question 7 · choose 1

A claims application's IAM role has bedrock:* on all resources. The application calls Converse for document summaries and ConverseStream for its chat window, always with one of two approved models in its own Region, and it never manages Bedrock resources. A security review requires the role to be reduced to exactly what the application uses, and both features must keep working after the change. Which policy should replace the current grant?

  1. AThe AmazonBedrockLimitedAccess managed policy, which AWS keeps up to date
  2. BAllow bedrock:InvokeModel on the ARNs of the two approved models
  3. CAllow bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream on the two model ARNs
  4. DAllow bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream on all foundation models
Show the answer and why
  • AThe AmazonBedrockLimitedAccess managed policy, which AWS keeps up to date

    Incorrect

    This managed policy also allows creating and deleting resources, Marketplace subscriptions and invoking models on all resources, far more than the application needs.

  • BAllow bedrock:InvokeModel on the ARNs of the two approved models

    Incorrect

    Converse is authorized by bedrock:InvokeModel, but ConverseStream needs bedrock:InvokeModelWithResponseStream, so the chat window would fail.

  • CAllow bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream on the two model ARNs

    Correct

    These are the two actions that Converse and ConverseStream require, and scoping them to the two model ARNs grants nothing else.

  • DAllow bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream on all foundation models

    Incorrect

    The actions are right, but the resource scope would let the role call any model, not only the two approved ones.

Least privilege means both the smallest set of actions and the narrowest resources. For the Converse family, check which IAM action each operation needs, because the streaming variant is authorized separately.

Question 8 · choose 2

A fraud team's assistant summarizes live chats between customers and support agents with a model on Amazon Bedrock. Names, email addresses and phone numbers must not reach the model. The summaries must still tell the people in a chat apart, for example "Customer 1 disputed the charge that Agent 2 approved", and authorized fraud analysts must be able to find out who each placeholder refers to. Chats are processed as they happen. Which actions should the developer take? (Choose TWO.)

  1. AApply a guardrail sensitive information filter that masks names, emails and phone numbers in the prompt
  2. BDetect the PII with Amazon Comprehend DetectPiiEntities and swap each distinct value for a consistent placeholder
  3. CEncrypt the chat transcripts with a customer managed AWS KMS key before they are summarized
  4. DKeep the placeholder-to-value mapping in a table that only the fraud analysts' role can read
  5. EInstruct the model in the system prompt never to repeat personal data in its summaries
Show the answer and why
  • AApply a guardrail sensitive information filter that masks names, emails and phone numbers in the prompt

    Incorrect

    Masking replaces each value with its type, such as {NAME}, so two different people become the same placeholder and the summary can no longer tell them apart. The mapping back to real values is also lost.

  • BDetect the PII with Amazon Comprehend DetectPiiEntities and swap each distinct value for a consistent placeholder

    Correct

    DetectPiiEntities returns the type and character offsets of each entity in real time, so the application can give every distinct person its own stable placeholder before the text is sent to the model.

  • CEncrypt the chat transcripts with a customer managed AWS KMS key before they are summarized

    Incorrect

    Encryption at rest protects the stored transcripts, but the model would still receive the readable text, including every name and number.

  • DKeep the placeholder-to-value mapping in a table that only the fraud analysts' role can read

    Correct

    A separate, access-controlled mapping lets authorized analysts re-identify placeholders while the model and everyone else see only pseudonyms.

  • EInstruct the model in the system prompt never to repeat personal data in its summaries

    Incorrect

    The system prompt is sent along with the conversation, so the personal data still reaches the model; the instruction only shapes its output.

Masking by type is enough when the identity of each person does not matter. When the output must keep people distinct and authorized staff must reverse it, use consistent pseudonyms and protect the mapping as sensitive data in its own right.

Question 9 · choose 1

A healthcare company plans to send patient visit summaries to a third-party provider's model on Amazon Bedrock, using in-Region on-demand inference. Before approving the design, legal must decide whether the model provider could ever see prompts or completions, which would require a separate data-processing agreement with that provider. Auditors also require model invocation logging, and legal wants to know whether those logs create any exposure to the provider. Which statement is accurate?

  1. AThe provider can see the prompts sent to its model but not the completions it returns
  2. BThe provider has no access to the Bedrock deployment accounts where its model runs
  3. CEach request is forwarded to the provider's own infrastructure for inference
  4. DTurning on invocation logging also shares copies of the prompts with the provider
Show the answer and why
  • AThe provider can see the prompts sent to its model but not the completions it returns

    Incorrect

    Providers have no access to the accounts where their models run on Amazon Bedrock, so they see neither prompts nor completions.

  • BThe provider has no access to the Bedrock deployment accounts where its model runs

    Correct

    Amazon Bedrock copies the provider's model software into model deployment accounts that the Bedrock service team owns and operates, and providers do not have access to those accounts.

  • CEach request is forwarded to the provider's own infrastructure for inference

    Incorrect

    Inference runs on copies of the model inside Bedrock-operated deployment accounts, not on the provider's systems.

  • DTurning on invocation logging also shares copies of the prompts with the provider

    Incorrect

    Invocation logs are delivered only to the CloudWatch Logs log group or S3 bucket that you configure in your own account.

Knowing the service's data isolation model answers this kind of governance question: providers cannot reach the deployment accounts, and logs stay in destinations you control. Protecting those log destinations then becomes the company's own responsibility.

Practise domain 3 →Practise all domains →