Skip to content
BytePatterns

AIP-C01 · Domain 3: AI Safety, Security, and Governance · 20% of the exam

Task 3.3: Implement AI governance and compliance mechanisms.

Proving what the system did and why: model cards, data lineage and source attribution, audit logs, organization-wide guardrail enforcement and continuous compliance monitoring.

Study it

  • Governance and audit: model cards, lineage, CloudTrail, invocation logs and organization-wide guardrails

    Partly covered by: CloudWatch, Alarms & X-Ray

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company with 60 AWS accounts in AWS Organizations must apply the same approved guardrail to every Amazon Bedrock model invocation in two OUs. Application teams must not need to change code or pass a guardrail ID, member accounts must not be able to weaken the guardrail, and the security team wants to confirm which guardrail is in force for any account. Which approach meets these requirements?

  1. AAttach an SCP to the OUs that denies bedrock:InvokeModel when the bedrock:GuardrailIdentifier condition key differs from the approved guardrail
  2. BAttach an Amazon Bedrock policy in AWS Organizations to the OUs that references a numbered guardrail version
  3. CDeploy the guardrail into every account with CloudFormation StackSets and let each team attach it to its own calls
  4. DShare the DRAFT version of the guardrail with every account through a resource-based policy and ask teams to reference it
Show the answer and why
  • AAttach an SCP to the OUs that denies bedrock:InvokeModel when the bedrock:GuardrailIdentifier condition key differs from the approved guardrail

    Incorrect

    Condition keys can require a guardrail, but every application would have to pass the guardrail ID in its calls, and calls without it would be rejected, which means code changes.

  • BAttach an Amazon Bedrock policy in AWS Organizations to the OUs that references a numbered guardrail version

    Correct

    Bedrock policies in Organizations enforce a guardrail automatically on every model invocation in the accounts beneath the node. A numbered version is immutable, and DescribeEffectivePolicy shows the effective policy for an account.

  • CDeploy the guardrail into every account with CloudFormation StackSets and let each team attach it to its own calls

    Incorrect

    Copies in each account can be modified by account administrators, and teams still have to add the guardrail to their calls.

  • DShare the DRAFT version of the guardrail with every account through a resource-based policy and ask teams to reference it

    Incorrect

    The working draft can change at any time, and asking teams to reference it relies on code changes in every application.

Organization-level enforcement applies safeguards for all inference calls without application changes. Reference an immutable guardrail version from the management account, attach the policy where it should apply, and check the result with DescribeEffectivePolicy because declarative policies resolve through inheritance rules.

Question 2 · choose 1

A lender fine-tunes a model for credit-memo drafting and registers each version in SageMaker Model Registry. Regulators ask for a standard record of each version's intended uses, risk rating, training data description and evaluation results, kept with the model and generated by the training pipeline rather than written by hand. What should the team use?

  1. ATags on each model package that hold the risk rating and a link to the evaluation report
  2. BAWS CloudTrail logs of the training and registration API calls for each version
  3. CA README file that the data scientists store next to the model artifacts in Amazon S3 after each training run
  4. DSageMaker model cards created by the pipeline through the model card APIs
Show the answer and why
  • ATags on each model package that hold the risk rating and a link to the evaluation report

    Incorrect

    Tags are short key-value labels, not a structured record of intended uses, training data and evaluation results.

  • BAWS CloudTrail logs of the training and registration API calls for each version

    Incorrect

    CloudTrail proves that API calls happened, but it does not document intended uses, risks or evaluation results.

  • CA README file that the data scientists store next to the model artifacts in Amazon S3 after each training run

    Incorrect

    A free-form file has no standard structure or link to the registry, and nothing ensures it is complete for each version.

  • DSageMaker model cards created by the pipeline through the model card APIs

    Correct

    Model cards document intended uses, risk ratings, training details and evaluation results, can be created programmatically through APIs, and are visible with registered models.

Model cards are the structured documentation artifact for models in SageMaker AI. Creating them from the pipeline through the APIs keeps the record complete and consistent for every version in the registry.

Question 3 · choose 1

An insurer's claims assistant answers adjusters' questions from a knowledge base. For each answer, auditors must later be able to see which documents, and which document versions, the answer was based on. Each source file in Amazon S3 has a metadata file with a version attribute. Which approach provides this traceability?

  1. AStore each answer with the retrieved references from its RetrieveAndGenerate citations
  2. BAsk the model in the system prompt to append a list of the titles of the documents it used to each answer it gives
  3. CEnable CloudTrail data events for the knowledge base and keep the trail for seven years
  4. DEnable S3 server access logging on the source bucket to record which objects were read
Show the answer and why
  • AStore each answer with the retrieved references from its RetrieveAndGenerate citations

    Correct

    RetrieveAndGenerate returns citations whose retrieved references hold the source chunk, the document location and its metadata, such as the version attribute, which the application can store with the answer.

  • BAsk the model in the system prompt to append a list of the titles of the documents it used to each answer it gives

    Incorrect

    A model-written list can be incomplete or invented. It is not a reliable record of what was retrieved.

  • CEnable CloudTrail data events for the knowledge base and keep the trail for seven years

    Incorrect

    CloudTrail records that Retrieve or RetrieveAndGenerate was called, not the content of the answer and its sources.

  • DEnable S3 server access logging on the source bucket to record which objects were read

    Incorrect

    Access logs show reads by the ingestion process, not which chunks were used to answer a specific question.

Source attribution comes from the retrieval layer, not from the model's own description. Citations from RetrieveAndGenerate carry the location and the metadata of each referenced document, so storing them with the answer gives an auditable trail.

Question 4 · choose 3

A company runs a public chatbot with a guardrail. It wants to detect a sudden rise in blocked prompts from abuse attempts, automatically put a user who keeps triggering the guardrail on a deny list without redeploying the application, and keep an audit trail of anyone who changes or deletes the guardrail. Which actions meet these requirements? (Choose THREE.)

  1. AHave the alarm invoke a Lambda function through SNS that adds the user to a deny list in AWS AppConfig
  2. BUse AWS CloudTrail to record UpdateGuardrail and DeleteGuardrail calls as management events
  3. CEnable SageMaker Model Monitor on the chatbot to detect abusive users
  4. DCreate a CloudWatch alarm on the guardrail's InvocationsIntervened metric for input content
  5. ERun AWS Trusted Advisor checks every hour to find users who trigger the guardrail
Show the answer and why
  • AHave the alarm invoke a Lambda function through SNS that adds the user to a deny list in AWS AppConfig

    Correct

    An alarm action can start automated remediation, and a deny list held in AppConfig changes application behavior without a redeployment.

  • BUse AWS CloudTrail to record UpdateGuardrail and DeleteGuardrail calls as management events

    Correct

    CloudTrail records Amazon Bedrock management API calls, so changes to the guardrail are captured with the caller's identity.

  • CEnable SageMaker Model Monitor on the chatbot to detect abusive users

    Incorrect

    Model Monitor is closed to new customers and monitors data and model quality on SageMaker endpoints, not guardrail interventions.

  • DCreate a CloudWatch alarm on the guardrail's InvocationsIntervened metric for input content

    Correct

    Guardrails publish InvocationsIntervened with a content source dimension, so an alarm can detect a rise in blocked prompts.

  • ERun AWS Trusted Advisor checks every hour to find users who trigger the guardrail

    Incorrect

    Trusted Advisor checks account configuration for best practices. It has no view of guardrail interventions or users.

Continuous governance combines detection (guardrail metrics and alarms), automated remediation (alarm actions that change configuration) and an audit trail of control changes (CloudTrail management events).

Question 5 · choose 1

An insurer's document pipeline runs in 25 accounts of an AWS Organizations organization. It uses Amazon Textract, Amazon Transcribe and Amazon Comprehend to prepare claims data, then Amazon Bedrock to draft decisions. The data governance board requires that no customer content processed by any AWS AI service is stored or used by AWS to improve its services. The rule must cover accounts created later, and account administrators must not be able to change it. What should the cloud team do?

  1. AAttach an SCP that denies Textract, Transcribe and Comprehend calls to every principal except the pipeline roles
  2. BAttach an AI services opt-out policy that opts out of all supported services at the organization root
  3. CEncrypt every bucket and service resource in the pipeline with customer managed AWS KMS keys
  4. DTake no action, because Amazon Bedrock does not use prompts or responses to train models
Show the answer and why
  • AAttach an SCP that denies Textract, Transcribe and Comprehend calls to every principal except the pipeline roles

    Incorrect

    SCPs limit which principals can call which APIs. They do not change how a service handles the content of the calls they still allow.

  • BAttach an AI services opt-out policy that opts out of all supported services at the organization root

    Correct

    An AI services opt-out policy stops supported AI services, including Textract, Transcribe and Comprehend, from storing or using content for service improvement. Attached at the root, it applies to every current and future account, and member accounts cannot change it.

  • CEncrypt every bucket and service resource in the pipeline with customer managed AWS KMS keys

    Incorrect

    Customer managed keys control access to stored data. They do not set whether a service may use content for service improvement.

  • DTake no action, because Amazon Bedrock does not use prompts or responses to train models

    Incorrect

    That is true for Amazon Bedrock, but the pipeline also sends content to Textract, Transcribe and Comprehend, which are covered by the opt-out policy rather than by Bedrock's data handling.

Governance for a generative AI system covers its whole pipeline, not only the model call. Organization-level policies make the choice consistent for every account and keep it out of the hands of individual administrators.

Question 6 · choose 1

A bank's credit-memo assistant answers from a knowledge base that ingests curated data written to Amazon S3 by 14 AWS Glue 5.0 Spark jobs, which use DataFrames and were created in the AWS Glue console. Regulators require the bank to show, for any curated dataset, which upstream tables and which job runs produced it, kept current automatically rather than in hand-written documents. The bank already catalogs its data in an Amazon SageMaker Unified Studio domain. What should the data team do?

  1. ARun an AWS Glue crawler on the curated bucket after each job so the Data Catalog lists every output table
  2. BTurn on CloudTrail S3 data events for the curated bucket to record which job roles wrote each object
  3. CHave every job write the names of its source tables into S3 object tags on the files it produces
  4. DConfigure the Glue jobs to send OpenLineage events to the Unified Studio domain and review lineage there
Show the answer and why
  • ARun an AWS Glue crawler on the curated bucket after each job so the Data Catalog lists every output table

    Incorrect

    A crawler infers schemas and registers tables. It does not record which job runs and source tables produced each dataset.

  • BTurn on CloudTrail S3 data events for the curated bucket to record which job roles wrote each object

    Incorrect

    Data events record individual API calls on objects. They do not connect a dataset to the upstream tables it was built from.

  • CHave every job write the names of its source tables into S3 object tags on the files it produces

    Incorrect

    Tags written by each job are custom documentation that must be kept correct by hand, and they do not form a navigable lineage graph.

  • DConfigure the Glue jobs to send OpenLineage events to the Unified Studio domain and review lineage there

    Correct

    Glue 5.0 includes the OpenLineage libraries for Spark DataFrames. With the listener pointed at the domain, each run emits lineage events that Unified Studio records as lineage between source and target datasets.

Data lineage is a compliance control for GenAI systems: it proves where the content behind an answer came from. Capturing it from the jobs themselves keeps it current, while catalogs, logs and tags each answer a different question.

Question 7 · choose 1

Analysts query a knowledge base of internal audit findings directly from notebooks by calling the Retrieve API with their own federated roles. For the next year, auditors must be able to show which principals queried this knowledge base, when, and from which IP addresses. The account's trail records management events only, and the team wants extra logging charges limited to this one knowledge base. What should the team configure?

  1. AAn advanced event selector for AWS::Bedrock::KnowledgeBase data events, scoped to this knowledge base
  2. BNothing new, because the trail already records Retrieve calls as management events with the caller's identity
  3. CAWS Config recording for the knowledge base resource type, with the history kept for one year
  4. DS3 server access logging on the bucket that holds the knowledge base's source documents
Show the answer and why
  • AAn advanced event selector for AWS::Bedrock::KnowledgeBase data events, scoped to this knowledge base

    Correct

    Retrieve and RetrieveAndGenerate calls are logged as data events for the knowledge base resource type, which a trail records only when selected. The resources.ARN field limits logging to this one knowledge base, and each event carries the caller identity, time and source IP.

  • BNothing new, because the trail already records Retrieve calls as management events with the caller's identity

    Incorrect

    CloudTrail records runtime calls such as InvokeModel and Converse as management events, but knowledge base Retrieve calls are data events, which are not logged by default.

  • CAWS Config recording for the knowledge base resource type, with the history kept for one year

    Incorrect

    AWS Config records configuration changes to the knowledge base resource. It does not record who called Retrieve or from where.

  • DS3 server access logging on the bucket that holds the knowledge base's source documents

    Incorrect

    Retrieve reads the knowledge base's vector index, not the source files in Amazon S3, so the bucket's access logs would not show these queries.

Audit trails for GenAI data sources depend on knowing which calls are management events and which are data events. Data events must be selected explicitly, and advanced selectors keep their cost limited to the resources that matter.

Question 8 · choose 1

A company runs GenAI workloads on Amazon Bedrock in 30 accounts of an AWS Organizations organization. The security team wants findings in its delegated security account when stolen credentials are used to call models in ways that differ from an identity's normal pattern, when someone floods a model with expensive requests, and when guardrails are unusually removed or invocation logging is turned off. It does not want to write or tune detection rules, and it does not want to depend on each account configuring its own trail correctly. What should the team do?

  1. ACreate Amazon EventBridge rules in every account that match DeleteGuardrail and logging configuration calls
  2. BDeploy an AWS Config conformance pack to every account and alert on noncompliant Bedrock resources
  3. CAggregate every account's findings in AWS Security Hub with the default security standards enabled
  4. DEnable Amazon GuardDuty with AI Protection for all accounts from the delegated administrator account
Show the answer and why
  • ACreate Amazon EventBridge rules in every account that match DeleteGuardrail and logging configuration calls

    Incorrect

    Rules match the exact events you write them for. They cannot judge whether model use differs from an identity's normal baseline, and they would have to be built and maintained in each account.

  • BDeploy an AWS Config conformance pack to every account and alert on noncompliant Bedrock resources

    Incorrect

    AWS Config evaluates resource configurations against rules. It does not analyze model invocation activity for misuse.

  • CAggregate every account's findings in AWS Security Hub with the default security standards enabled

    Incorrect

    Security Hub collects and scores findings from other services and runs posture checks; on its own it does not detect anomalous model use.

  • DEnable Amazon GuardDuty with AI Protection for all accounts from the delegated administrator account

    Correct

    AI Protection baselines model invocations per identity and reports anomalous use and cost harvesting, and GuardDuty's foundational detections flag unusual guardrail removal and disabled invocation logging. GuardDuty collects the events through its own service-linked channel.

Detecting misuse of foundation models is a continuous governance control. A managed threat detection service that learns normal behavior covers credential misuse and evasion attempts that hand-written rules miss, and organization-wide enablement keeps coverage independent of each account.

Question 9 · choose 1

Twelve customer-facing applications, owned by different teams, call models on Amazon Bedrock from one AWS account in one Region. A new regulation requires a copy of every prompt and model response, with the model ID and the calling identity, kept in company-owned storage in that Region for later review. The compliance office will not wait for twelve teams to change and redeploy their code. What should the platform team enable?

  1. AA CloudTrail trail that also records Amazon Bedrock data events for the account
  2. BA guardrail with tracing enabled that every application must add to its requests
  3. CModel invocation logging for the account and Region to a company-owned S3 bucket
  4. DThe Bedrock runtime metrics in CloudWatch, kept on a dashboard per application
Show the answer and why
  • AA CloudTrail trail that also records Amazon Bedrock data events for the account

    Incorrect

    CloudTrail records who called which API and when, but not the full prompt and response content that the regulation requires.

  • BA guardrail with tracing enabled that every application must add to its requests

    Incorrect

    A guardrail trace describes how content was assessed. It is not a stored copy of every exchange, and it would need code changes in every application.

  • CModel invocation logging for the account and Region to a company-owned S3 bucket

    Correct

    Invocation logging is configured once per account and Region and captures request and response data with metadata for invocations, so no application has to change.

  • DThe Bedrock runtime metrics in CloudWatch, kept on a dashboard per application

    Incorrect

    Runtime metrics are counts and latencies. They contain none of the request or response content.

Content-level audit records come from model invocation logging, which works at the account and Region level. Protect the destination with access controls, encryption and a retention policy, because the logs contain the same sensitive data as the prompts.

Practise domain 3 →Practise all domains →