Skip to content
BytePatterns

AIP-C01 · Domain 3: AI Safety, Security, and Governance · 20% of the exam

Task 3.4: Implement responsible AI principles.

Transparency, fairness and policy compliance in practice: explaining answers with sources, measuring bias with evaluations and A/B tests, and documenting model limits.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A lender's affordability assistant calls a model on Amazon Bedrock through the Converse API to answer multi-step questions, such as how much a customer can borrow given income, debts and current rates. The model supports reasoning and returns it as readable text, but the application has not turned reasoning on. The responsible AI board now requires that customers can follow the intermediate steps the model worked through to reach each answer, not a justification written afterward. A downstream system parses the answer text, so the steps must come back separately from it. Which approach meets these requirements?

  1. AEnable model invocation logging to CloudWatch Logs and let customers view the log entries for their requests
  2. BTurn on the model's reasoning and show the reasoningContent blocks of each Converse response beside the answer
  3. CAdd a guardrail contextual grounding check and show the grounding and relevance scores next to each answer
  4. DSet the temperature to 0 in inferenceConfig so that the same question always produces the same answer
Show the answer and why
  • AEnable model invocation logging to CloudWatch Logs and let customers view the log entries for their requests

    Incorrect

    Invocation logging collects the request data, response data and metadata of calls in the account. It adds no steps to a response that has none, and an account log is not a customer-facing explanation.

  • BTurn on the model's reasoning and show the reasoningContent blocks of each Converse response beside the answer

    Correct

    With reasoning on, the model works through the problem step by step before it answers, and Converse returns that reasoning in reasoningContent blocks that are separate from the text block, so the app can display the steps and leave the answer text unchanged.

  • CAdd a guardrail contextual grounding check and show the grounding and relevance scores next to each answer

    Incorrect

    Grounding checks score how well a response is supported by a reference source and how relevant it is to the query. A score says nothing about the steps that led to the answer.

  • DSet the temperature to 0 in inferenceConfig so that the same question always produces the same answer

    Incorrect

    A lower temperature makes output more deterministic. Consistent answers are useful, but they do not show customers how an answer was reached.

A reasoning display is a transparency control: it shows users how the model reached an answer. Turning on reasoning for a model that supports it returns the chain of thought the model used as its own content blocks in the Converse response, which the application can present next to the answer. Invocation logs, grounding scores and temperature serve operations, hallucination filtering and consistency, not user-facing explanations.

Question 2 · choose 1

A recruiting platform generates candidate feedback with a model on Amazon Bedrock. Before launch, the responsible AI board wants evidence that the feedback does not differ in tone or content stereotypes for candidates who differ only in gender or ethnicity. The team wants a managed evaluation with repeatable scores and per-response explanations. What should the team do?

  1. ARun LLM-as-a-judge jobs with the Stereotyping metric on paired prompts that differ only in those attributes
  2. BUse Amazon Comprehend sentiment analysis on a random sample of production feedback after launch
  3. CAdd a guardrail denied topic for gender and ethnicity so that the model never mentions them
  4. DRun SageMaker Clarify bias analysis on the training data of the foundation model before the platform launches
Show the answer and why
  • ARun LLM-as-a-judge jobs with the Stereotyping metric on paired prompts that differ only in those attributes

    Correct

    Judge-based evaluations score each response with built-in metrics such as Stereotyping and explain each score, and paired prompts isolate the effect of the attribute.

  • BUse Amazon Comprehend sentiment analysis on a random sample of production feedback after launch

    Incorrect

    Sentiment on a random sample after launch does not compare otherwise identical candidates and comes too late for the launch decision.

  • CAdd a guardrail denied topic for gender and ethnicity so that the model never mentions them

    Incorrect

    Blocking a topic does not measure whether outputs differ between groups, which is the evidence the board wants.

  • DRun SageMaker Clarify bias analysis on the training data of the foundation model before the platform launches

    Incorrect

    Clarify is closed to new customers, and the team does not have the foundation model's training data. Its replacement for FM evaluation is Bedrock Evaluations.

Fairness evaluation compares outputs for inputs that differ only in a sensitive attribute. Bedrock LLM-as-a-judge jobs provide managed, repeatable scoring with explanations, including Stereotyping and Harmfulness metrics.

Question 3 · choose 1

A brokerage's responsible AI policy says its assistants must never give individualized investment recommendations, whether a customer asks for one or the model drifts into one, and must answer such attempts with a policy-approved message. The policy must apply the same way across five applications. Which control meets these requirements?

  1. AA guardrail denied topic for personalized investment advice on input and output, with the approved message
  2. BA sentence in each application's system prompt that forbids investment recommendations
  3. CA word filter with terms such as "buy", "sell" and "portfolio" applied to the model's output only
  4. DThe content filter Misconduct category set to HIGH for the input and output
Show the answer and why
  • AA guardrail denied topic for personalized investment advice on input and output, with the approved message

    Correct

    Denied topics detect a described subject in prompts and responses, and the guardrail returns the configured blocked message. One guardrail version can be used by all five applications.

  • BA sentence in each application's system prompt that forbids investment recommendations

    Incorrect

    Prompt instructions can be bypassed and are maintained separately in every application, so the policy would not apply consistently.

  • CA word filter with terms such as "buy", "sell" and "portfolio" applied to the model's output only

    Incorrect

    Keywords would block many harmless answers and miss rephrased advice, and filtering only the output ignores the customer's request.

  • DThe content filter Misconduct category set to HIGH for the input and output

    Incorrect

    Misconduct covers criminal or harmful activity, not lawful but prohibited advice such as investment recommendations.

Turning a written policy into a control usually means a guardrail policy: denied topics for subjects the business must not discuss, applied to both directions, with a message approved by the policy owner.

Question 4 · choose 1

An asset manager uses a model on Amazon Bedrock to draft marketing emails about its funds. Its financial-promotion policy says that every email must carry the firm's approved 60-word risk warning word for word, and the compliance team must be able to show, for each email sent, that the warning was included. The system prompt already quotes the warning and tells the model to copy it exactly, yet tests show the model sometimes shortens it, rewords it or leaves it out of long emails. Marketing wants the model to keep writing the rest of each email freely. What should the developer do?

  1. ASet the temperature to 0 so that the model copies the quoted warning word for word
  2. BHave a Lambda function append the approved warning to each draft and log the result
  3. CPut the approved warning in a guardrail custom word filter applied to the output
  4. DAdd a contextual grounding check that uses the approved warning as its source
Show the answer and why
  • ASet the temperature to 0 so that the model copies the quoted warning word for word

    Incorrect

    A lower temperature makes higher-probability tokens more likely. It does not guarantee that a 60-word passage comes back unchanged, and it leaves compliance with no record for each email.

  • BHave a Lambda function append the approved warning to each draft and log the result

    Correct

    The warning no longer depends on generation: the prompt stops asking for it, code adds the exact approved text after the body, and the function's log entry for each email, kept in CloudWatch Logs, gives compliance its record.

  • CPut the approved warning in a guardrail custom word filter applied to the output

    Incorrect

    Custom word filter entries are words or phrases of up to three words, and a word filter blocks matching text rather than requiring it. It cannot add a missing warning.

  • DAdd a contextual grounding check that uses the approved warning as its source

    Incorrect

    A grounding check treats information that is not in the source as ungrounded. Marketing copy goes far beyond the warning, so most emails would be blocked, and a missing warning is not what the check measures.

When a policy requires exact wording, do not ask a model to generate it. Let the model write the variable part and add the fixed, approved text in code, where the step is deterministic and can be logged as evidence.

Question 5 · choose 2

An online learning platform runs one tutoring assistant for two audiences: students aged 13 to 17, and adult professionals in forensic medicine courses who must discuss violent injuries in clinical detail. The responsible AI policy requires violent descriptions to be blocked for minors but allowed for the adult courses. Both audiences use the same code path and model, and each account's age group is verified at sign-in and stored in the session. Which actions should the developer take? (Choose TWO.)

  1. AAttach one guardrail with the Violence filter at HIGH strength to every request
  2. BAdd a system prompt instruction to avoid violent detail when the student is under 18
  3. CCreate two guardrails whose Violence filter strengths match each audience's policy
  4. DLet the model infer each user's audience from the conversation and pick the filter level
  5. EChoose the guardrail in each request's guardrailConfig from the verified age group in the session
Show the answer and why
  • AAttach one guardrail with the Violence filter at HIGH strength to every request

    Incorrect

    A single strict guardrail would also block the clinical discussions that the adult courses require.

  • BAdd a system prompt instruction to avoid violent detail when the student is under 18

    Incorrect

    An instruction asks the model to behave; it is not an enforced filter, and the policy requires blocking for minors.

  • CCreate two guardrails whose Violence filter strengths match each audience's policy

    Correct

    Content filter strength is set per guardrail, so a strict guardrail for minors and a permissive one for the adult courses encode the policy for each audience.

  • DLet the model infer each user's audience from the conversation and pick the filter level

    Incorrect

    A user can claim any age in a chat. The audience must come from the verified attribute, not from text the user controls.

  • EChoose the guardrail in each request's guardrailConfig from the verified age group in the session

    Correct

    The guardrail is specified per request, so the shared code path can apply the right one based on the verified attribute.

When one application serves audiences with different policies, keep the policies in separate guardrails and select the guardrail from trusted identity data on every call, rather than relying on prompts or on what the user says.

Question 6 · choose 1

A bank's model risk policy requires a record for every foundation model in use. The record must quote the provider's own statements about the model's intended use cases, known limitations and responsible AI design choices, and must keep these separate from the bank's internal test results, which are filed elsewhere. The team has chosen an Amazon Nova model on Amazon Bedrock. Where should the team source the provider's statements?

  1. AThe model's card in the Amazon Bedrock User Guide, with its lifecycle dates and supported features
  2. BThe AWS Responsible AI Policy that applies to every customer of AWS AI services
  3. CThe results of an Amazon Bedrock model evaluation job run on the bank's own prompts
  4. DThe AWS AI Service Card for that Amazon Nova model, cited with the release it covers
Show the answer and why
  • AThe model's card in the Amazon Bedrock User Guide, with its lifecycle dates and supported features

    Incorrect

    The Bedrock model card lists technical facts such as modalities, context window, lifecycle dates and supported features, and it points to the service card for model development details.

  • BThe AWS Responsible AI Policy that applies to every customer of AWS AI services

    Incorrect

    The policy sets rules for how customers may use AWS AI services. It is not a model-specific description of limitations or design choices.

  • CThe results of an Amazon Bedrock model evaluation job run on the bank's own prompts

    Incorrect

    Evaluation results describe how the model performed on the bank's data; they belong with the internal test results, not the provider's statements.

  • DThe AWS AI Service Card for that Amazon Nova model, cited with the release it covers

    Correct

    AI Service Cards explain the intended use cases, how machine learning is used and key considerations for the responsible design and use of the service, written by AWS as the provider.

Documenting a model's limitations starts with what the provider publishes about it. AI Service Cards are the provider's transparency documents for AWS models; a team's own evaluations then show how the model behaves on its use case.

Question 7 · choose 1

A company's responsible AI policy says every guardrail used in production must keep a sensitive information filter for card numbers and a contextual grounding check. Application teams own their guardrails and must remain free to tune them in the console at any time. The governance team wants every change to a guardrail evaluated against the policy automatically, a compliance history that auditors can review, and an alert within minutes when a guardrail stops complying. What should the developer build?

  1. ATag each approved guardrail with policy=approved and have teams filter the console by that tag
  2. BAn AWS Config custom rule with a Lambda function that evaluates guardrail configuration changes
  3. CAn SCP that denies bedrock:UpdateGuardrail to every application team role
  4. DAmazon Inspector scans enabled for all resources in the production accounts
Show the answer and why
  • ATag each approved guardrail with policy=approved and have teams filter the console by that tag

    Incorrect

    A tag records a claim made once. It does not check the guardrail's settings again after a team edits it, and it raises no alert.

  • BAn AWS Config custom rule with a Lambda function that evaluates guardrail configuration changes

    Correct

    AWS Config records AWS::Bedrock::Guardrail resources. A custom rule triggered by configuration changes can run a Lambda check of the required policies, keep a compliance history and notify through Amazon EventBridge.

  • CAn SCP that denies bedrock:UpdateGuardrail to every application team role

    Incorrect

    Blocking updates would stop teams from tuning their guardrails, which the policy explicitly allows, and it would not show whether existing guardrails comply.

  • DAmazon Inspector scans enabled for all resources in the production accounts

    Incorrect

    Inspector looks for software vulnerabilities and unintended network exposure in workloads such as EC2 instances, container images and Lambda functions. It does not evaluate guardrail settings.

Automated compliance checks turn a written responsible AI policy into a control that runs on every change. Recording the resource in AWS Config and evaluating it with a custom rule gives continuous detection and an audit trail without taking control away from the teams.

Question 8 · choose 1

A patient portal's assistant uses a guardrail. When it blocks something, patients see "Sorry, I can't help with that" and do not know what to do next. The responsible AI team wants blocked questions to explain that medical advice is outside the assistant's scope, and blocked answers to say that a response was withheld, both pointing to the nurse line. The wording must be changeable without a mobile app release, and the filters themselves must not become weaker. What should the team change?

  1. AAdd a system prompt instruction telling the model to mention the nurse line whenever it declines
  2. BLower the content filter strengths so that fewer patient questions are blocked
  3. CSet separate blocked messages for prompts and responses, then publish a new guardrail version
  4. DAdd the explanation and nurse line to the mobile app's localized strings for the blocked case
Show the answer and why
  • AAdd a system prompt instruction telling the model to mention the nurse line whenever it declines

    Incorrect

    When the guardrail blocks a prompt, the model's inference is discarded, and a blocked response is overridden by the guardrail's message, so the model's own wording never reaches the patient.

  • BLower the content filter strengths so that fewer patient questions are blocked

    Incorrect

    Filter strength changes what is blocked, not what patients are told, and weakening the filters is not allowed.

  • CSet separate blocked messages for prompts and responses, then publish a new guardrail version

    Correct

    Guardrails return the messages configured for blocked prompts and for blocked responses, so each can explain the limit and give the nurse line. Pointing the backend at the new guardrail version changes the wording without a mobile app release.

  • DAdd the explanation and nurse line to the mobile app's localized strings for the blocked case

    Incorrect

    Text bundled in the app can only change with an app release, which the requirement rules out.

A blocked response is part of the user experience. Transparent blocked messages tell users why something was withheld and where to go next, and they are managed with the guardrail rather than with application code.

Practise domain 3 →Practise all domains →