Study guide · AIF-C01

Security, Compliance, and Governance for AI Solutions

14% of the exam by AWS's own published weighting.

What it covers

The official exam guide breaks this domain into 2 objectives:

  • Explain methods to secure AI systems
  • Recognize governance and compliance regulations for AI systems

Practice this domain

A drill pulls every published question in this domain and grades each one as you go. Flashcards skip the grading entirely — read the stem, flip when you're ready, move on.

A sample question

How does grounding a model's answers in retrieved source content help address hallucination?

  • AIt gives the model verified material to base its response upon.
  • BIt prevents the model from generating any text in its response.
  • CIt automatically corrects factual errors within the source material.
  • DIt removes the need for any human review of the generated answers.

Grounding supplies actual source material so responses rest on verified content rather than fabrication. It does not stop generation, fix errors in the sources themselves, or eliminate the value of review.

A company wants to control which employees may invoke its foundation model and which may only read results. Which AWS service provides this control?

  • AAWS Identity and Access Management, which controls access to AWS resources.
  • BAmazon CloudFront, which caches and delivers content from edge locations.
  • CAmazon Polly, which converts written text into natural-sounding speech.
  • DAWS Budgets, which alerts when spending approaches a defined threshold.

IAM governs who may perform which actions on which AWS resources, including invoking models. CloudFront delivers content, Polly generates speech, and Budgets handles cost alerting.

Unofficial study aid. Not affiliated with, endorsed by, or sponsored by Amazon Web Services.