Amazon AWS AI Practitioner AIF-C01 AI Security IAM Encryption AgentCore Guardrails And Lineage Practice Test

 

AIF-C01 skills 5.1 | 30 original questions

This AWS Certified AI Practitioner AIF-C01 practice test focuses on ai security iam encryption agentcore guardrails and lineage through original scenario-based questions aligned to AWS Exam Guide version 1.1 published April 30, 2026. Use the full ExamSnap AIF-C01 collection for broader practice across all five current exam domains. For broader exam preparation, review the Amazon AWS Certified AI Practitioner AIF-C01 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

A proof of concept at Woodgrove Bank exposed a design decision for the security architect: the solution must record structured model information such as intended use, evaluation, risk, and lifecycle details. Which option most directly solves that problem? Assume the required AWS capabilities are available in the selected Region and normal governance controls are in place. The control owner requires evidence from 3 test groups before the 929-day release review.

  1. Continuous monitoring
  2. SageMaker Model Cards
  3. Source citation
  4. Data cataloging
  5. Logging policy

Correct answer: B

Why: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

Option review:

A: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

C: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: A data catalog helps teams discover and govern data assets. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: SageMaker Model Cards – Model Cards improve documentation and traceability for model governance.

Question 2

Wide World Importers is documenting the target state for a knowledge-assistant rollout. The risk manager needs a solution that can connect supported services privately from a VPC without routing traffic over the public internet. Which option is the strongest fit? The review committee wants a direct mapping from the requirement to the chosen capability. The project has 8 downstream consumers and a monthly review of approximately 966 sampled interactions.

  1. Amazon Bedrock AgentCore Identity
  2. AWS Trusted Advisor
  3. AWS PrivateLink
  4. AWS Config
  5. Amazon Bedrock Guardrails

Correct answer: C

Why: PrivateLink provides private connectivity to supported AWS services and endpoints. It directly addresses the requirement in this scenario.

Option review:

A: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: PrivateLink provides private connectivity to supported AWS services and endpoints. It directly addresses the requirement in this scenario.

D: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS PrivateLink – PrivateLink provides private connectivity to supported AWS services and endpoints.

Question 3

VanArsdel Media is reviewing a claims-processing redesign. The security architect has one primary requirement: maintain searchable metadata about datasets, ownership, schema, classification, and approved use. Which choice best fits the requirement? The solution will serve multiple internal teams, so the recommendation should be reusable without changing the core requirement. The rollout spans 5 application teams, each using the same approved requirement set for the next 43 days.

  1. Data residency control
  2. Continuous monitoring
  3. Source citation
  4. Data cataloging
  5. SageMaker Model Cards

Correct answer: D

Why: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

Option review:

A: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

E: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data cataloging – A data catalog helps teams discover and govern data assets.

Question 4

During a design review for Datum Dynamics, the risk manager must apply configured safeguards to model inputs and outputs. The team also wants to reduce manual handling. What should the team choose? The decision must follow the workload characteristics rather than a preference for the largest model or newest service. The evaluation set contains examples from 2 business workflows and 80 recent production cases.

  1. Amazon Macie
  2. AWS CloudTrail
  3. AWS Trusted Advisor
  4. AWS Identity and Access Management (IAM)
  5. Amazon Bedrock Guardrails

Correct answer: E

Why: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. It directly addresses the requirement in this scenario.

Option review:

A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. It directly addresses the requirement in this scenario.

Learning point: Amazon Bedrock Guardrails – Bedrock Guardrails can help enforce content and data-safety policies around supported model calls.

Question 5

Alpine Ski House is moving a developer-productivity pilot from pilot to production. The key decision is how to record where data originated and how it moved or changed through the pipeline. Which option is the strongest fit if the team wants to use current managed AWS capabilities? The security baseline is already defined; the decision here concerns the specific capability described in the requirement. The initial rollout covers 117 internal users across 7 business units.

  1. Data lineage
  2. Continuous monitoring
  3. Data lifecycle policy
  4. Source citation
  5. Data cataloging

Correct answer: A

Why: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Option review:

A: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: A data catalog helps teams discover and govern data assets. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data lineage – Lineage supports governance, debugging, audit, and reproducibility.

Question 6

A workshop at Humongous Insurance focuses on a single decision: how to determine which security responsibilities belong to AWS and which remain with the customer for the selected service. Which option should the risk manager recommend? The recommendation must solve the stated requirement without introducing unrelated platform complexity. The workload processes about 154 requests during its busiest hour and has a documented fallback path.

  1. Amazon Bedrock AgentCore Identity
  2. AWS shared responsibility model
  3. Amazon Inspector
  4. Encryption
  5. AWS Artifact

Correct answer: B

Why: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. It directly addresses the requirement in this scenario.

Option review:

A: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. It directly addresses the requirement in this scenario.

C: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS shared responsibility model – The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control.

Question 7

For the analytics modernization at Graphic Design Institute, stakeholders need to show the specific supporting source used for a generated answer. Which concept, service, or technique most directly addresses this goal? The design must remain supportable after launch, but no additional feature is required beyond the stated need. The pilot uses 191 representative records from 9 approved data sources.

  1. Data lifecycle policy
  2. Data lineage
  3. Source citation
  4. Continuous monitoring
  5. Data residency control

Correct answer: C

Why: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

Option review:

A: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Lineage supports governance, debugging, audit, and reproducibility. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Source citation – Citations improve traceability and let users verify grounded claims.

Question 8

Relecloud is comparing alternatives for its compliance-assistant prototype. The risk manager needs to discover and classify sensitive data in Amazon S3 that may feed an AI workload. Which option is most appropriate while trying to meet a strict latency target? A short pilot window means the team prefers an approach that can be evaluated with clear success criteria. The first release supports 6 departments and is reviewed every 228 days.

  1. Encryption
  2. Amazon Bedrock AgentCore Identity
  3. AWS PrivateLink
  4. Amazon Macie
  5. AWS Identity and Access Management (IAM)

Correct answer: D

Why: Macie helps identify sensitive data in S3 and can support data-protection governance. It directly addresses the requirement in this scenario.

Option review:

A: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Macie helps identify sensitive data in S3 and can support data-protection governance. It directly addresses the requirement in this scenario.

E: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Amazon Macie – Macie helps identify sensitive data in S3 and can support data-protection governance.

Question 9

An architecture review at Adventure Works Manufacturing has narrowed a forecasting initiative decision to one requirement: record structured model information such as intended use, evaluation, risk, and lifecycle details. What should the security architect select? The architecture board will reject a choice that addresses a different problem from the one described. The service has a 265-millisecond internal response target for the affected workflow.

  1. Continuous monitoring
  2. Retention policy
  3. Logging policy
  4. Data lifecycle policy
  5. SageMaker Model Cards

Correct answer: E

Why: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

Option review:

A: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

Learning point: SageMaker Model Cards – Model Cards improve documentation and traceability for model governance.

Question 10

The risk manager at Proseware Services is preparing a recommendation for a customer-support modernization. The recommendation must enforce centralized fine-grained controls over agent-to-tool interactions outside the agent code. Which choice is the best match? Budget has been approved for the project, but the team still wants to avoid unnecessary recurring consumption. The team is comparing 8 candidate designs after a 302-day proof of concept.

  1. Policy in Amazon Bedrock AgentCore
  2. AWS Config
  3. AWS Identity and Access Management (IAM)
  4. AWS shared responsibility model
  5. Amazon Bedrock Guardrails

Correct answer: A

Why: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. It directly addresses the requirement in this scenario.

Option review:

A: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. It directly addresses the requirement in this scenario.

B: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Policy in Amazon Bedrock AgentCore – AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer.

Question 11

Lucerne Publishing has completed discovery for a agentic workflow trial. Before implementation, the security architect must decide how to show the specific supporting source used for a generated answer. Which choice best satisfies that requirement? The team will validate the result with representative production examples before rollout. The control owner requires evidence from 5 test groups before the 339-day release review.

  1. Data residency control
  2. Source citation
  3. Observability
  4. Logging policy
  5. Retention policy

Correct answer: B

Why: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

Option review:

A: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

C: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Source citation – Citations improve traceability and let users verify grounded claims.

Question 12

While planning a contact-center transformation, Lamna Healthcare identifies this requirement: grant only the identities and permissions required to call AI services or supporting resources. Which option should the risk manager prioritize if the goal is to limit exposure of sensitive data? The pilot has representative data, and the team will measure the selected approach against an agreed acceptance threshold. The project has 2 downstream consumers and a monthly review of approximately 376 sampled interactions.

  1. AWS shared responsibility model
  2. AWS Config
  3. AWS Identity and Access Management (IAM)
  4. Amazon Bedrock Guardrails
  5. Amazon Inspector

Correct answer: C

Why: IAM roles, policies, and permissions are core controls for least-privilege access. It directly addresses the requirement in this scenario.

Option review:

A: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: IAM roles, policies, and permissions are core controls for least-privilege access. It directly addresses the requirement in this scenario.

D: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Identity and Access Management (IAM) – IAM roles, policies, and permissions are core controls for least-privilege access.

Question 13

A proof of concept at Contoso Retail exposed a design decision for the security architect: the solution must maintain searchable metadata about datasets, ownership, schema, classification, and approved use. Which option most directly solves that problem? The team will document the rationale for auditors and wants the recommendation to be defensible from the scenario facts. The rollout spans 7 application teams, each using the same approved requirement set for the next 413 days.

  1. SageMaker Model Cards
  2. Data lifecycle policy
  3. Continuous monitoring
  4. Data cataloging
  5. Retention policy

Correct answer: D

Why: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

Option review:

A: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data cataloging – A data catalog helps teams discover and govern data assets.

Question 14

Fourth Coffee is documenting the target state for a sales-assistant rollout. The risk manager needs a solution that can handle agent authentication and permission delegation to external tools or services. Which option is the strongest fit? The team wants the least complex technically correct choice that satisfies the requirement. The evaluation set contains examples from 4 business workflows and 450 recent production cases.

  1. Amazon Inspector
  2. AWS Identity and Access Management (IAM)
  3. Amazon Bedrock Guardrails
  4. AWS shared responsibility model
  5. Amazon Bedrock AgentCore Identity

Correct answer: E

Why: AgentCore Identity integrates identity and authorization into agent workflows. It directly addresses the requirement in this scenario.

Option review:

A: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: AgentCore Identity integrates identity and authorization into agent workflows. It directly addresses the requirement in this scenario.

Learning point: Amazon Bedrock AgentCore Identity – AgentCore Identity integrates identity and authorization into agent workflows.

Question 15

Margie Travel is reviewing a internal search upgrade. The security architect has one primary requirement: record where data originated and how it moved or changed through the pipeline. Which choice best fits the requirement? The workload has passed basic feasibility checks, so the remaining question is which approach best matches the requirement. The initial rollout covers 487 internal users across 9 business units.

  1. Data lineage
  2. SageMaker Model Cards
  3. Data residency control
  4. Continuous monitoring
  5. Observability

Correct answer: A

Why: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Option review:

A: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

B: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data lineage – Lineage supports governance, debugging, audit, and reproducibility.

Question 16

During a design review for School of Fine Art, the risk manager must protect AI data at rest and in transit using cryptographic controls. The team also wants to reduce manual handling. What should the team choose? Stakeholders have ruled out a broad redesign and want the choice that most precisely addresses the stated need. The workload processes about 524 requests during its busiest hour and has a documented fallback path.

  1. AWS Artifact
  2. Encryption
  3. AWS PrivateLink
  4. AWS CloudTrail
  5. Amazon Macie

Correct answer: B

Why: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. It directly addresses the requirement in this scenario.

Option review:

A: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. It directly addresses the requirement in this scenario.

C: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Encryption – Encryption reduces unauthorized disclosure risk when combined with proper key and access management.

Question 17

Northwind Analytics is moving a knowledge-assistant rollout from pilot to production. The key decision is how to record structured model information such as intended use, evaluation, risk, and lifecycle details. Which option is the strongest fit if the team wants to use current managed AWS capabilities? Operational ownership is already assigned, so the team is comparing technical fit rather than staffing models. The pilot uses 561 representative records from 3 approved data sources.

  1. Source citation
  2. Data residency control
  3. SageMaker Model Cards
  4. Observability
  5. Data lifecycle policy

Correct answer: C

Why: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

Option review:

A: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

D: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: SageMaker Model Cards – Model Cards improve documentation and traceability for model governance.

Question 18

A workshop at Litware Financial focuses on a single decision: how to connect supported services privately from a VPC without routing traffic over the public internet. Which option should the risk manager recommend? Existing application interfaces can accommodate any of the listed choices, so functional fit is the deciding factor. The first release supports 8 departments and is reviewed every 598 days.

  1. AWS Config
  2. AWS Artifact
  3. AWS CloudTrail
  4. AWS PrivateLink
  5. AWS Identity and Access Management (IAM)

Correct answer: D

Why: PrivateLink provides private connectivity to supported AWS services and endpoints. It directly addresses the requirement in this scenario.

Option review:

A: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: PrivateLink provides private connectivity to supported AWS services and endpoints. It directly addresses the requirement in this scenario.

E: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS PrivateLink – PrivateLink provides private connectivity to supported AWS services and endpoints.

Question 19

For the personalization program at A. Datum Research, stakeholders need to record where data originated and how it moved or changed through the pipeline. Which concept, service, or technique most directly addresses this goal? Assume the required AWS capabilities are available in the selected Region and normal governance controls are in place. The service has a 635-millisecond internal response target for the affected workflow.

  1. Observability
  2. Continuous monitoring
  3. Data lifecycle policy
  4. Data cataloging
  5. Data lineage

Correct answer: E

Why: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Option review:

A: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: A data catalog helps teams discover and govern data assets. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Learning point: Data lineage – Lineage supports governance, debugging, audit, and reproducibility.

Question 20

Coho Winery is comparing alternatives for its developer-productivity pilot. The risk manager needs to grant only the identities and permissions required to call AI services or supporting resources. Which option is most appropriate while trying to meet a strict latency target? The review committee wants a direct mapping from the requirement to the chosen capability. The team is comparing 2 candidate designs after a 672-day proof of concept.

  1. AWS Identity and Access Management (IAM)
  2. Amazon Macie
  3. Amazon Inspector
  4. AWS Artifact
  5. Amazon Bedrock AgentCore Identity

Correct answer: A

Why: IAM roles, policies, and permissions are core controls for least-privilege access. It directly addresses the requirement in this scenario.

Option review:

A: IAM roles, policies, and permissions are core controls for least-privilege access. It directly addresses the requirement in this scenario.

B: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Identity and Access Management (IAM) – IAM roles, policies, and permissions are core controls for least-privilege access.

Question 21

An architecture review at Lucerne Retail has narrowed a fraud-review pilot decision to one requirement: maintain searchable metadata about datasets, ownership, schema, classification, and approved use. What should the security architect select? The solution will serve multiple internal teams, so the recommendation should be reusable without changing the core requirement. The control owner requires evidence from 7 test groups before the 709-day release review.

  1. Source citation
  2. Data cataloging
  3. Continuous monitoring
  4. Data residency control
  5. Retention policy

Correct answer: B

Why: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

Option review:

A: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

C: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data cataloging – A data catalog helps teams discover and govern data assets.

Question 22

The risk manager at Tailspin Toys is preparing a recommendation for a analytics modernization. The recommendation must apply configured safeguards to model inputs and outputs. Which choice is the best match? The decision must follow the workload characteristics rather than a preference for the largest model or newest service. The project has 4 downstream consumers and a monthly review of approximately 746 sampled interactions.

  1. AWS Identity and Access Management (IAM)
  2. AWS Trusted Advisor
  3. Amazon Bedrock Guardrails
  4. Encryption
  5. AWS shared responsibility model

Correct answer: C

Why: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. It directly addresses the requirement in this scenario.

Option review:

A: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. It directly addresses the requirement in this scenario.

D: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Amazon Bedrock Guardrails – Bedrock Guardrails can help enforce content and data-safety policies around supported model calls.

Question 23

City Power and Light has completed discovery for a compliance-assistant prototype. Before implementation, the security architect must decide how to show the specific supporting source used for a generated answer. Which choice best satisfies that requirement? The security baseline is already defined; the decision here concerns the specific capability described in the requirement. The rollout spans 9 application teams, each using the same approved requirement set for the next 783 days.

  1. Continuous monitoring
  2. SageMaker Model Cards
  3. Retention policy
  4. Source citation
  5. Observability

Correct answer: D

Why: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

Option review:

A: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Citations improve traceability and let users verify grounded claims. It directly addresses the requirement in this scenario.

E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Source citation – Citations improve traceability and let users verify grounded claims.

Question 24

While planning a forecasting initiative, Consolidated Messenger identifies this requirement: protect AI data at rest and in transit using cryptographic controls. Which option should the risk manager prioritize if the goal is to limit exposure of sensitive data? The recommendation must solve the stated requirement without introducing unrelated platform complexity. The evaluation set contains examples from 6 business workflows and 820 recent production cases.

  1. Amazon Macie
  2. AWS Identity and Access Management (IAM)
  3. AWS shared responsibility model
  4. Amazon Inspector
  5. Encryption

Correct answer: E

Why: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. It directly addresses the requirement in this scenario.

Option review:

A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. It directly addresses the requirement in this scenario.

Learning point: Encryption – Encryption reduces unauthorized disclosure risk when combined with proper key and access management.

Question 25

A proof of concept at Nod Publishers exposed a design decision for the security architect: the solution must record structured model information such as intended use, evaluation, risk, and lifecycle details. Which option most directly solves that problem? The design must remain supportable after launch, but no additional feature is required beyond the stated need. The initial rollout covers 857 internal users across 3 business units.

  1. SageMaker Model Cards
  2. Data residency control
  3. Observability
  4. Logging policy
  5. Data lifecycle policy

Correct answer: A

Why: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

Option review:

A: Model Cards improve documentation and traceability for model governance. It directly addresses the requirement in this scenario.

B: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: SageMaker Model Cards – Model Cards improve documentation and traceability for model governance.

Question 26

Fabrikam Health is documenting the target state for a agentic workflow trial. The risk manager needs a solution that can enforce centralized fine-grained controls over agent-to-tool interactions outside the agent code. Which option is the strongest fit? A short pilot window means the team prefers an approach that can be evaluated with clear success criteria. The workload processes about 894 requests during its busiest hour and has a documented fallback path.

  1. AWS PrivateLink
  2. Policy in Amazon Bedrock AgentCore
  3. AWS Config
  4. AWS Artifact
  5. Encryption

Correct answer: B

Why: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. It directly addresses the requirement in this scenario.

Option review:

A: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. It directly addresses the requirement in this scenario.

C: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Policy in Amazon Bedrock AgentCore – AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer.

Question 27

Wingtip Logistics is reviewing a contact-center transformation. The security architect has one primary requirement: maintain searchable metadata about datasets, ownership, schema, classification, and approved use. Which choice best fits the requirement? The architecture board will reject a choice that addresses a different problem from the one described. The pilot uses 931 representative records from 5 approved data sources.

  1. Logging policy
  2. Continuous monitoring
  3. Data cataloging
  4. Data lineage
  5. SageMaker Model Cards

Correct answer: C

Why: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

Option review:

A: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: A data catalog helps teams discover and govern data assets. It directly addresses the requirement in this scenario.

D: Lineage supports governance, debugging, audit, and reproducibility. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data cataloging – A data catalog helps teams discover and govern data assets.

Question 28

During a design review for Trey Research, the risk manager must handle agent authentication and permission delegation to external tools or services. The team also wants to reduce manual handling. What should the team choose? Budget has been approved for the project, but the team still wants to avoid unnecessary recurring consumption. The first release supports 2 departments and is reviewed every 968 days.

  1. AWS Config
  2. AWS shared responsibility model
  3. AWS Identity and Access Management (IAM)
  4. Amazon Bedrock AgentCore Identity
  5. Policy in Amazon Bedrock AgentCore

Correct answer: D

Why: AgentCore Identity integrates identity and authorization into agent workflows. It directly addresses the requirement in this scenario.

Option review:

A: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AgentCore Identity integrates identity and authorization into agent workflows. It directly addresses the requirement in this scenario.

E: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Amazon Bedrock AgentCore Identity – AgentCore Identity integrates identity and authorization into agent workflows.

Question 29

Bellows College is moving a sales-assistant rollout from pilot to production. The key decision is how to record where data originated and how it moved or changed through the pipeline. Which option is the strongest fit if the team wants to use current managed AWS capabilities? The team will validate the result with representative production examples before rollout. The service has a 45-millisecond internal response target for the affected workflow.

  1. Retention policy
  2. Data lifecycle policy
  3. Source citation
  4. SageMaker Model Cards
  5. Data lineage

Correct answer: E

Why: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Option review:

A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Citations improve traceability and let users verify grounded claims. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Model Cards improve documentation and traceability for model governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lineage supports governance, debugging, audit, and reproducibility. It directly addresses the requirement in this scenario.

Learning point: Data lineage – Lineage supports governance, debugging, audit, and reproducibility.

Question 30

A workshop at Blue Yonder Airlines focuses on a single decision: how to determine which security responsibilities belong to AWS and which remain with the customer for the selected service. Which option should the risk manager recommend? The pilot has representative data, and the team will measure the selected approach against an agreed acceptance threshold. The team is comparing 4 candidate designs after a 82-day proof of concept.

  1. AWS shared responsibility model
  2. AWS CloudTrail
  3. AWS Artifact
  4. Amazon Bedrock Guardrails
  5. Policy in Amazon Bedrock AgentCore

Correct answer: A

Why: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. It directly addresses the requirement in this scenario.

Option review:

A: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. It directly addresses the requirement in this scenario.

B: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS shared responsibility model – The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control.

Popular posts

img