SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
AIF-C01 · Domain 5

Security, Compliance, and Governance for AI Solutions practice questions

Security, Compliance, and Governance for AI Solutions is worth 14% of the AIF-C01 exam — the 4th-heaviest of the 5 domains. Securing AI systems on AWS, and the governance and compliance regulations that apply to them. 6 fully worked examples are further down this page, answers included.

Exam weight
14%
the 4th-heaviest of the 5 domains
Questions
40
across 2 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Security, Compliance, and Governance for AI Solutions questions, fully explained

Questions from the AIF-C01 bank mapped to domain 5, with the answer key and the reasoning behind every option. None of them repeat the examples on the main AIF-C01 practice page.

Question 1Security, Compliance, and Governance for AI Solutions

Before fine-tuning a model, a team wants to scan its Amazon S3 training data to find personally identifiable information (PII) that should be removed. Which AWS service is designed for this?

Choose one.

  • a
    Amazon Inspector

    Inspector scans workloads for software vulnerabilities, not for sensitive data in storage.

  • b
    Amazon Macie Correct

    Macie uses machine learning to discover and protect sensitive data such as PII stored in Amazon S3.

  • c
    AWS Key Management Service (KMS)

    KMS manages encryption keys; it does not locate PII within a dataset.

  • d
    AWS PrivateLink

    PrivateLink provides private network connectivity, not sensitive-data discovery.

The concept

Amazon Macie discovers and protects sensitive data, such as PII, in Amazon S3.

Why that’s the answer

Finding PII in training data is Macie's core purpose. Inspector finds vulnerabilities, KMS handles keys, and PrivateLink handles private connectivity, so none of them locate sensitive data.

How to reason it out
  1. Identify the goal: find PII inside S3 training data.
  2. Match the goal to the sensitive-data discovery service.
  3. That service is Amazon Macie.

Exam tip: The trigger phrase find PII or sensitive data in training data points to Amazon Macie.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

Question 2Security, Compliance, and Governance for AI Solutions

A bank wants requests from its application to a foundation model to travel over a private connection instead of the public internet. Which AWS service provides this private connectivity from a VPC to the service?

Choose one.

  • a
    AWS PrivateLink Correct

    PrivateLink provides private connectivity between a VPC and AWS services so traffic never traverses the public internet.

  • b
    Amazon Macie

    Macie discovers sensitive data; it does not create private network paths.

  • c
    AWS Identity and Access Management (IAM)

    IAM controls who can perform actions, not how network traffic is routed.

  • d
    AWS Key Management Service (KMS)

    KMS manages encryption keys and does not affect network routing.

The concept

AWS PrivateLink keeps traffic between your VPC and AWS services off the public internet.

Why that’s the answer

Keeping AI traffic private is exactly what PrivateLink does. Macie finds data, IAM controls access, and KMS handles keys, so none of them provide private connectivity.

How to reason it out
  1. Identify the goal: keep model traffic off the public internet.
  2. Match it to the private-connectivity service.
  3. That service is AWS PrivateLink.

Exam tip: Keep traffic to an AI service private and off the internet with AWS PrivateLink.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

Question 3Security, Compliance, and Governance for AI Solutions

An application needs to call a foundation model and read one specific data store, and nothing else. Following AWS best practice, how should you grant this access?

Choose one.

  • a
    An IAM user with long-lived access keys and administrator permissions

    Administrator permissions violate least privilege, and long-lived keys can leak and linger.

  • b
    The AWS account root user credentials

    The root user has unrestricted access and should never be used for application access.

  • c
    A shared password stored in the application code

    Hard-coded secrets are insecure and are not how AWS access is granted.

  • d
    An IAM role scoped to only the permissions the application needs (least privilege) Correct

    A least-privilege IAM role grants exactly the required actions and issues temporary credentials to the application.

The concept

Least privilege means giving each component only the permissions it needs, ideally through an IAM role with temporary credentials.

Why that’s the answer

A tightly scoped IAM role is the secure pattern. Broad administrator keys, the root user, and hard-coded passwords all grant far more than needed or expose long-lived secrets.

How to reason it out
  1. Identify the requirement: minimum access to one model and one data store.
  2. Prefer a role that hands out temporary credentials over long-lived keys.
  3. Scope the role's permissions to only those actions.

Exam tip: Grant AI components access with least-privilege IAM roles, not broad users or root.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

Question 4Security, Compliance, and Governance for AI Solutions

A team must ensure that training datasets stored in Amazon S3 are unreadable to anyone who bypasses access controls. Which control addresses data at rest?

Choose one.

  • a
    Encryption in transit using TLS

    TLS protects data moving over the network, not data sitting in storage.

  • b
    Encryption at rest using AWS KMS keys Correct

    Encryption at rest with KMS-managed keys keeps stored files unreadable without the key.

  • c
    A least-privilege IAM policy

    IAM limits who can access the bucket but does not encrypt the stored files.

  • d
    AWS PrivateLink connectivity

    PrivateLink secures the network path, not stored data.

The concept

Encryption at rest protects stored data such as S3 training datasets, using keys managed in AWS KMS.

Why that’s the answer

Protecting stored files is encryption at rest. TLS covers data in transit, IAM controls access rather than encrypting, and PrivateLink secures the network path, so they address different states.

How to reason it out
  1. Identify the data state: stored files in S3.
  2. Match stored data to encryption at rest.
  3. AWS KMS manages the keys for that encryption.

Exam tip: Protect stored AI data with encryption at rest using AWS KMS.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

Question 5Security, Compliance, and Governance for AI Solutions

Which protocol protects a prompt as it travels over the network from an application to a foundation model so it cannot be read or altered in flight?

Choose one.

  • a
    AWS KMS encryption at rest

    Encryption at rest protects stored data, not data moving over the network.

  • b
    TLS (encryption in transit) Correct

    TLS encrypts data in transit so it cannot be read or tampered with while moving between components.

  • c
    An IAM role

    An IAM role controls permissions, not the confidentiality of network traffic.

  • d
    Amazon Macie

    Macie discovers sensitive data in storage; it does not encrypt network traffic.

The concept

Encryption in transit uses TLS (HTTPS) to protect data as it moves across the network.

Why that’s the answer

A prompt moving to a model is data in transit, protected by TLS. Encryption at rest covers storage, IAM covers permissions, and Macie discovers data, so they cover different concerns.

How to reason it out
  1. Identify the data state: a prompt moving over the network.
  2. Match moving data to encryption in transit.
  3. The mechanism is TLS.

Exam tip: Protect AI data moving over the network with TLS, which is encryption in transit.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

Question 6Security, Compliance, and Governance for AI Solutions

An attacker embeds hidden instructions inside user input so a large language model ignores its original instructions and reveals confidential data. What is this AI-specific threat called?

Choose one.

  • a
    Data residency

    Data residency concerns where data physically lives, not manipulating model input.

  • b
    Prompt injection Correct

    Prompt injection hides malicious instructions in the input so the model does something unintended.

  • c
    Model overfitting

    Overfitting is a training problem where a model memorizes data, not an input-based attack.

  • d
    Encryption in transit

    Encryption in transit is a protection, not an attack on the model.

The concept

Prompt injection is an attack that hides malicious instructions in input to make a model behave unintendedly.

Why that’s the answer

The described attack matches prompt injection exactly. Data residency is a location policy, overfitting is a training issue, and encryption in transit is a protection, so none describe this threat.

How to reason it out
  1. Note the behavior: hidden instructions override the model's intended behavior.
  2. Match that behavior to the AI-specific input attack.
  3. That attack is prompt injection.

Exam tip: Hidden instructions in input that hijack a model's behavior is prompt injection.

Securing AI Systems on AWS: IAM, Encryption, Guardrails, and Grounding — the lesson that teaches this.

What AIF-C01 domain 5 tests, topic by topic

The official exam guide breaks Security, Compliance, and Governance for AI Solutions into 2 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published AIF-C01 practice questions per topic in Security, Compliance, and Governance for AI Solutions
TopicWhat it coversQuestions
Explain methods to secure AI systemsExam guide task 5.1 (AIF-C01). AWS services and features to secure AI systems (IAM roles, policies, and permissions; encryption; Amazon Macie; AWS PrivateLink; the AWS shared responsibility model; Amazon Bedrock AgentCore Identity; Policy in AgentCore; Amazon Bedrock Guardrails); source citation and documenting data origins (data lineage, data cataloging, Amazon SageMaker Model Cards); best practices for secure data engineering (assessing data quality, privacy-enhancing technologies, data access control, data integrity); security and privacy considerations for AI systems (application security, threat detection, vulnerability management, infrastructure protection, prompt injection, encryption at rest and in transit, data leakage prevention, output filtering and validation, audit trail and logging requirements for AI interactions, toxicity); hallucination detection methods and grounding techniques (Retrieval Augmented Generation [RAG] grounding, output validation, confidence scoring).20
Recognize governance and compliance regulations for AI systemsExam guide task 5.2 (AIF-C01). AWS services and features for governance and regulation compliance (AWS Config, Amazon Inspector, AWS Artifact, AWS CloudTrail, AWS Trusted Advisor); data governance strategies (data lifecycles, logging, residency, monitoring, observation, retention); processes to follow governance protocols (policies, review cadence, review strategies, governance frameworks such as the Generative AI Security Scoping Matrix, transparency standards, team training requirements).20
Total40

Revise Security, Compliance, and Governance for AI Solutions before you drill it

Other AIF-C01 domains

Security, Compliance, and Governance for AI Solutions: your questions

Security, Compliance, and Governance for AI Solutions is domain 5 of the AIF-C01 exam guide and carries 14% of the scored content — the 4th-heaviest of the 5 domains. On a 65-question paper that works out to roughly 9 questions, though AWS does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official AIF-C01 exam guide.