Amazon AWS AIP-C01 AI Governance and Compliance Practice Test
Topic 14 focuses on AI Governance, Traceability, and Compliance for the AWS Certified Generative AI Developer – Professional certification and the AIP-C01 exam, using Amazon Bedrock and AWS generative AI services and architecture scenarios where relevant. For broader exam preparation, review the AWS Certified Generative AI Developer – Professional AIP-C01 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
The legal research platform has a design goal to document model purpose, limitations, evaluation results, and governance information. What should the team choose?
Correct Answer: C
Correct Answer
Answer C is correct because SageMaker model cards is designed to document model purpose, limitations, evaluation results, and governance information. It creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.
Incorrect Answers
Answer A is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Answer D is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Question 2
The research assistant application needs an architecture that can track how governed data moves and changes through processing pipelines. Which choice best meets that need?
Correct Answer: B
Correct Answer
Answer B is correct because AWS Glue data lineage is designed to track how governed data moves and changes through processing pipelines. It captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.
Incorrect Answers
Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Answer C is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Question 3
The AI product engineering team must associate generated or retrieved information with its authoritative source. Which approach is the strongest fit?
Correct Answer: D
Correct Answer
Answer D is correct because metadata source attribution is designed to associate generated or retrieved information with its authoritative source. It adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.
Incorrect Answers
Answer A is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Answer B is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Question 4
The supply-chain analytics group has a design goal to retain operational evidence about model requests, policy outcomes, and application decisions. What should the team choose?
Correct Answer: C
Correct Answer
Answer C is correct because CloudWatch decision logging is designed to retain operational evidence about model requests, policy outcomes, and application decisions. It stores searchable logs and metrics that support investigations, audits, and governance reviews.
Incorrect Answers
Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer B is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Answer D is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Question 5
The enterprise developer platform has a design goal to register governed datasets and technical metadata used by GenAI applications. What should the team choose?
Correct Answer: A
Correct Answer
Answer A is correct because AWS Glue Data Catalog is designed to register governed datasets and technical metadata used by GenAI applications. It provides a centralized catalog of data assets and schemas that can support discoverability and traceability.
Incorrect Answers
Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Answer C is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Answer D is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Question 6
The customer identity platform needs an architecture that can record AWS API activity for accountability and compliance investigations. Which choice best meets that need?
Correct Answer: D
Correct Answer
Answer D is correct because CloudTrail audit logging is designed to record AWS API activity for accountability and compliance investigations. It captures who or what called supported AWS APIs, when the call occurred, and relevant request context.
Incorrect Answers
Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Answer B is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Question 7
The business intelligence application has a design goal to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations. What should the team choose?
Correct Answer: B
Correct Answer
Answer B is correct because organizational AI governance framework is designed to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations. It defines enterprise rules and responsibilities instead of letting each application invent its own governance model.
Incorrect Answers
Answer A is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Answer C is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Question 8
The healthcare document platform needs an architecture that can identify GenAI usage patterns that violate acceptable-use or safety policies. Which choice best meets that need?
Correct Answer: D
Correct Answer
Answer D is correct because automated misuse detection is designed to identify GenAI usage patterns that violate acceptable-use or safety policies. It monitors interactions for suspicious patterns and can trigger review or containment workflows.
Incorrect Answers
Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer B is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Question 9
The e-commerce search team needs an architecture that can detect when model behavior or application outputs move outside approved operating bounds. Which choice best meets that need?
Correct Answer: D
Correct Answer
Answer D is correct because drift and policy-violation monitoring is designed to detect when model behavior or application outputs move outside approved operating bounds. It compares production observations with policy thresholds and baselines over time.
Incorrect Answers
Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Answer C is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Question 10
The risk analytics team is prioritizing a requirement to detect changes in fairness-related behavior after deployment. Which implementation is most appropriate?
Correct Answer: B
Correct Answer
Answer B is correct because bias-drift monitoring is designed to detect changes in fairness-related behavior after deployment. It tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated.
Incorrect Answers
Answer A is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Answer C is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Answer D is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Question 11
The fraud detection engineering team is prioritizing a requirement to respond consistently when a governance control detects a serious violation. Which implementation is most appropriate?
Correct Answer: A
Correct Answer
Answer A is correct because automated remediation workflow is designed to respond consistently when a governance control detects a serious violation. It invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction.
Incorrect Answers
Answer B is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer D is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Question 12
The technical documentation assistant needs an architecture that can remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response. Which choice best meets that need?
Correct Answer: A
Correct Answer
Answer A is correct because token-level redaction and output policy filtering is designed to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response. It applies fine-grained transformation and policy checks before output is released.
Incorrect Answers
Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Question 13
The model governance committee needs to identify a capability with this behavior: creates structured model documentation that supports review, transparency, and controlled lifecycle decisions. What is the best match?
Correct Answer: B
Correct Answer
Answer B is correct because the description directly matches SageMaker model cards. SageMaker model cards creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.
Incorrect Answers
Answer A is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Answer C is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Answer D is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Question 14
The AI governance program describes a component that captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems. Which capability is being described?
Correct Answer: C
Correct Answer
Answer C is correct because the description directly matches AWS Glue data lineage. AWS Glue data lineage captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.
Incorrect Answers
Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Answer B is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Answer D is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Question 15
Within the sales operations automation team’s architecture, which capability matches this technical description: adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them?
Correct Answer: A
Correct Answer
Answer A is correct because the description directly matches metadata source attribution. metadata source attribution adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.
Incorrect Answers
Answer B is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Answer D is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Question 16
Within the knowledge retrieval engineering team’s architecture, which capability matches this technical description: stores searchable logs and metrics that support investigations, audits, and governance reviews?
Correct Answer: C
Correct Answer
Answer C is correct because the description directly matches CloudWatch decision logging. CloudWatch decision logging stores searchable logs and metrics that support investigations, audits, and governance reviews.
Incorrect Answers
Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Question 17
The enterprise content repository team documents this GenAI behavior: provides a centralized catalog of data assets and schemas that can support discoverability and traceability. Which capability matches it?
Correct Answer: C
Correct Answer
Answer C is correct because the description directly matches AWS Glue Data Catalog. AWS Glue Data Catalog provides a centralized catalog of data assets and schemas that can support discoverability and traceability.
Incorrect Answers
Answer A is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Answer D is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Question 18
The manufacturing analytics team documents this GenAI behavior: captures who or what called supported AWS APIs, when the call occurred, and relevant request context. Which capability matches it?
Correct Answer: D
Correct Answer
Answer D is correct because the description directly matches CloudTrail audit logging. CloudTrail audit logging captures who or what called supported AWS APIs, when the call occurred, and relevant request context.
Incorrect Answers
Answer A is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Answer B is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Question 19
The developer productivity team describes a component that defines enterprise rules and responsibilities instead of letting each application invent its own governance model. Which capability is being described?
Correct Answer: C
Correct Answer
Answer C is correct because the description directly matches organizational AI governance framework. organizational AI governance framework defines enterprise rules and responsibilities instead of letting each application invent its own governance model.
Incorrect Answers
Answer A is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Answer B is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Question 20
The business process automation team documents this GenAI behavior: monitors interactions for suspicious patterns and can trigger review or containment workflows. Which capability matches it?
Correct Answer: A
Correct Answer
Answer A is correct because the description directly matches automated misuse detection. automated misuse detection monitors interactions for suspicious patterns and can trigger review or containment workflows.
Incorrect Answers
Answer B is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.
Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer D is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Question 21
The regulatory reporting platform describes a component that compares production observations with policy thresholds and baselines over time. Which capability is being described?
Correct Answer: A
Correct Answer
Answer A is correct because the description directly matches drift and policy-violation monitoring. drift and policy-violation monitoring compares production observations with policy thresholds and baselines over time.
Incorrect Answers
Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.
Answer C is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Answer D is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.
Question 22
The privacy engineering function needs to identify a capability with this behavior: tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated. What is the best match?
Correct Answer: D
Correct Answer
Answer D is correct because the description directly matches bias-drift monitoring. bias-drift monitoring tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated.
Incorrect Answers
Answer A is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.
Answer B is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.
Answer C is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.
Question 23
Within the logistics optimization team’s architecture, which capability matches this technical description: invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction?
Correct Answer: B
Correct Answer
Answer B is correct because the description directly matches automated remediation workflow. automated remediation workflow invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction.
Incorrect Answers
Answer A is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.
Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.
Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.
Question 24
Within the service reliability organization’s architecture, which capability matches this technical description: applies fine-grained transformation and policy checks before output is released?
Correct Answer: C
Correct Answer
Answer C is correct because the description directly matches token-level redaction and output policy filtering. token-level redaction and output policy filtering applies fine-grained transformation and policy checks before output is released.
Incorrect Answers
Answer A is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.
Answer B is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.
Answer D is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.
Question 25
The enterprise finance automation team has proposed SageMaker model cards for its design. Which requirement best justifies it?
Correct Answer: B
Correct Answer
Answer B is correct because SageMaker model cards is specifically used to document model purpose, limitations, evaluation results, and governance information. It creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.
Incorrect Answers
Answer A is incorrect because that requirement aligns with AWS Glue Data Catalog, not SageMaker model cards.
Answer C is incorrect because that requirement aligns with drift and policy-violation monitoring, not SageMaker model cards.
Answer D is incorrect because that requirement aligns with AWS Glue data lineage, not SageMaker model cards.
Question 26
The risk and controls team is considering AWS Glue data lineage. What problem is this choice primarily meant to solve?
Correct Answer: A
Correct Answer
Answer A is correct because AWS Glue data lineage is specifically used to track how governed data moves and changes through processing pipelines. It captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.
Incorrect Answers
Answer B is incorrect because that requirement aligns with metadata source attribution, not AWS Glue data lineage.
Answer C is incorrect because that requirement aligns with CloudTrail audit logging, not AWS Glue data lineage.
Answer D is incorrect because that requirement aligns with bias-drift monitoring, not AWS Glue data lineage.
Question 27
The enterprise search architecture group is considering metadata source attribution. What problem is this choice primarily meant to solve?
Correct Answer: D
Correct Answer
Answer D is correct because metadata source attribution is specifically used to associate generated or retrieved information with its authoritative source. It adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.
Incorrect Answers
Answer A is incorrect because that requirement aligns with CloudWatch decision logging, not metadata source attribution.
Answer B is incorrect because that requirement aligns with automated remediation workflow, not metadata source attribution.
Answer C is incorrect because that requirement aligns with organizational AI governance framework, not metadata source attribution.
Question 28
CloudWatch decision logging appears in an insurance automation architecture. What governance requirement does this capability satisfy most directly?
Correct Answer: B
Correct Answer
Answer B is correct because CloudWatch decision logging is specifically used to retain operational evidence about model requests, policy outcomes, and application decisions. It stores searchable logs and metrics that support investigations, audits, and governance reviews.
Incorrect Answers
Answer A is incorrect because that requirement aligns with token-level redaction and output policy filtering, not CloudWatch decision logging.
Answer C is incorrect because that requirement aligns with AWS Glue Data Catalog, not CloudWatch decision logging.
Answer D is incorrect because that requirement aligns with automated misuse detection, not CloudWatch decision logging.
Question 29
Within the procurement automation group’s design, the team highlights AWS Glue Data Catalog. Which need does that component address?
Correct Answer: B
Correct Answer
Answer B is correct because AWS Glue Data Catalog is specifically used to register governed datasets and technical metadata used by GenAI applications. It provides a centralized catalog of data assets and schemas that can support discoverability and traceability.
Incorrect Answers
Answer A is incorrect because that requirement aligns with drift and policy-violation monitoring, not AWS Glue Data Catalog.
Answer C is incorrect because that requirement aligns with CloudTrail audit logging, not AWS Glue Data Catalog.
Answer D is incorrect because that requirement aligns with SageMaker model cards, not AWS Glue Data Catalog.
Question 30
The observability engineering group is considering CloudTrail audit logging. What problem is this choice primarily meant to solve?
Correct Answer: A
Correct Answer
Answer A is correct because CloudTrail audit logging is specifically used to record AWS API activity for accountability and compliance investigations. It captures who or what called supported AWS APIs, when the call occurred, and relevant request context.
Incorrect Answers
Answer B is incorrect because that requirement aligns with AWS Glue data lineage, not CloudTrail audit logging.
Answer C is incorrect because that requirement aligns with bias-drift monitoring, not CloudTrail audit logging.
Answer D is incorrect because that requirement aligns with organizational AI governance framework, not CloudTrail audit logging.
Popular posts
Recent Posts
