Amazon AWS AIP-C01 AI Governance and Compliance Practice Test

 

Topic 14 focuses on AI Governance, Traceability, and Compliance for the AWS Certified Generative AI Developer – Professional certification and the AIP-C01 exam, using Amazon Bedrock and AWS generative AI services and architecture scenarios where relevant. For broader exam preparation, review the AWS Certified Generative AI Developer – Professional AIP-C01 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

The legal research platform has a design goal to document model purpose, limitations, evaluation results, and governance information. What should the team choose?

  1. drift and policy-violation monitoring
  2. AWS Glue Data Catalog
  3. SageMaker model cards
  4. AWS Glue data lineage

Correct Answer: C

 

Correct Answer

Answer C is correct because SageMaker model cards is designed to document model purpose, limitations, evaluation results, and governance information. It creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.

Incorrect Answers

Answer A is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

Answer D is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

 

Question 2

The research assistant application needs an architecture that can track how governed data moves and changes through processing pipelines. Which choice best meets that need?

  1. bias-drift monitoring
  2. AWS Glue data lineage
  3. CloudTrail audit logging
  4. metadata source attribution

Correct Answer: B

 

Correct Answer

Answer B is correct because AWS Glue data lineage is designed to track how governed data moves and changes through processing pipelines. It captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.

Incorrect Answers

Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

Answer C is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

 

Question 3

The AI product engineering team must associate generated or retrieved information with its authoritative source. Which approach is the strongest fit?

  1. automated remediation workflow
  2. CloudWatch decision logging
  3. organizational AI governance framework
  4. metadata source attribution

Correct Answer: D

 

Correct Answer

Answer D is correct because metadata source attribution is designed to associate generated or retrieved information with its authoritative source. It adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.

Incorrect Answers

Answer A is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

Answer B is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

 

Question 4

The supply-chain analytics group has a design goal to retain operational evidence about model requests, policy outcomes, and application decisions. What should the team choose?

  1. token-level redaction and output policy filtering
  2. automated misuse detection
  3. CloudWatch decision logging
  4. AWS Glue Data Catalog

Correct Answer: C

 

Correct Answer

Answer C is correct because CloudWatch decision logging is designed to retain operational evidence about model requests, policy outcomes, and application decisions. It stores searchable logs and metrics that support investigations, audits, and governance reviews.

Incorrect Answers

Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer B is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

Answer D is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

 

Question 5

The enterprise developer platform has a design goal to register governed datasets and technical metadata used by GenAI applications. What should the team choose?

  1. AWS Glue Data Catalog
  2. SageMaker model cards
  3. drift and policy-violation monitoring
  4. CloudTrail audit logging

Correct Answer: A

 

Correct Answer

Answer A is correct because AWS Glue Data Catalog is designed to register governed datasets and technical metadata used by GenAI applications. It provides a centralized catalog of data assets and schemas that can support discoverability and traceability.

Incorrect Answers

Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

Answer C is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

Answer D is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

 

Question 6

The customer identity platform needs an architecture that can record AWS API activity for accountability and compliance investigations. Which choice best meets that need?

  1. bias-drift monitoring
  2. AWS Glue data lineage
  3. organizational AI governance framework
  4. CloudTrail audit logging

Correct Answer: D

 

Correct Answer

Answer D is correct because CloudTrail audit logging is designed to record AWS API activity for accountability and compliance investigations. It captures who or what called supported AWS APIs, when the call occurred, and relevant request context.

Incorrect Answers

Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

Answer B is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

 

Question 7

The business intelligence application has a design goal to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations. What should the team choose?

  1. automated misuse detection
  2. organizational AI governance framework
  3. automated remediation workflow
  4. metadata source attribution

Correct Answer: B

 

Correct Answer

Answer B is correct because organizational AI governance framework is designed to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations. It defines enterprise rules and responsibilities instead of letting each application invent its own governance model.

Incorrect Answers

Answer A is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

Answer C is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

 

Question 8

The healthcare document platform needs an architecture that can identify GenAI usage patterns that violate acceptable-use or safety policies. Which choice best meets that need?

  1. token-level redaction and output policy filtering
  2. drift and policy-violation monitoring
  3. CloudWatch decision logging
  4. automated misuse detection

Correct Answer: D

 

Correct Answer

Answer D is correct because automated misuse detection is designed to identify GenAI usage patterns that violate acceptable-use or safety policies. It monitors interactions for suspicious patterns and can trigger review or containment workflows.

Incorrect Answers

Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer B is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

 

Question 9

The e-commerce search team needs an architecture that can detect when model behavior or application outputs move outside approved operating bounds. Which choice best meets that need?

  1. bias-drift monitoring
  2. SageMaker model cards
  3. AWS Glue Data Catalog
  4. drift and policy-violation monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because drift and policy-violation monitoring is designed to detect when model behavior or application outputs move outside approved operating bounds. It compares production observations with policy thresholds and baselines over time.

Incorrect Answers

Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

Answer C is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

 

Question 10

The risk analytics team is prioritizing a requirement to detect changes in fairness-related behavior after deployment. Which implementation is most appropriate?

  1. CloudTrail audit logging
  2. bias-drift monitoring
  3. AWS Glue data lineage
  4. automated remediation workflow

Correct Answer: B

 

Correct Answer

Answer B is correct because bias-drift monitoring is designed to detect changes in fairness-related behavior after deployment. It tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated.

Incorrect Answers

Answer A is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

Answer C is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

Answer D is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

 

Question 11

The fraud detection engineering team is prioritizing a requirement to respond consistently when a governance control detects a serious violation. Which implementation is most appropriate?

  1. automated remediation workflow
  2. metadata source attribution
  3. token-level redaction and output policy filtering
  4. organizational AI governance framework

Correct Answer: A

 

Correct Answer

Answer A is correct because automated remediation workflow is designed to respond consistently when a governance control detects a serious violation. It invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction.

Incorrect Answers

Answer B is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer D is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

 

Question 12

The technical documentation assistant needs an architecture that can remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response. Which choice best meets that need?

  1. token-level redaction and output policy filtering
  2. SageMaker model cards
  3. CloudWatch decision logging
  4. automated misuse detection

Correct Answer: A

 

Correct Answer

Answer A is correct because token-level redaction and output policy filtering is designed to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response. It applies fine-grained transformation and policy checks before output is released.

Incorrect Answers

Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

 

Question 13

The model governance committee needs to identify a capability with this behavior: creates structured model documentation that supports review, transparency, and controlled lifecycle decisions. What is the best match?

  1. drift and policy-violation monitoring
  2. SageMaker model cards
  3. AWS Glue Data Catalog
  4. AWS Glue data lineage

Correct Answer: B

 

Correct Answer

Answer B is correct because the description directly matches SageMaker model cards. SageMaker model cards creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.

Incorrect Answers

Answer A is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

Answer C is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

Answer D is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

 

Question 14

The AI governance program describes a component that captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems. Which capability is being described?

  1. bias-drift monitoring
  2. metadata source attribution
  3. AWS Glue data lineage
  4. CloudTrail audit logging

Correct Answer: C

 

Correct Answer

Answer C is correct because the description directly matches AWS Glue data lineage. AWS Glue data lineage captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.

Incorrect Answers

Answer A is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

Answer B is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

Answer D is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

 

Question 15

Within the sales operations automation team’s architecture, which capability matches this technical description: adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them?

  1. metadata source attribution
  2. organizational AI governance framework
  3. CloudWatch decision logging
  4. automated remediation workflow

Correct Answer: A

 

Correct Answer

Answer A is correct because the description directly matches metadata source attribution. metadata source attribution adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.

Incorrect Answers

Answer B is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

Answer C is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

Answer D is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

 

Question 16

Within the knowledge retrieval engineering team’s architecture, which capability matches this technical description: stores searchable logs and metrics that support investigations, audits, and governance reviews?

  1. token-level redaction and output policy filtering
  2. AWS Glue Data Catalog
  3. CloudWatch decision logging
  4. automated misuse detection

Correct Answer: C

 

Correct Answer

Answer C is correct because the description directly matches CloudWatch decision logging. CloudWatch decision logging stores searchable logs and metrics that support investigations, audits, and governance reviews.

Incorrect Answers

Answer A is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

 

Question 17

The enterprise content repository team documents this GenAI behavior: provides a centralized catalog of data assets and schemas that can support discoverability and traceability. Which capability matches it?

  1. CloudTrail audit logging
  2. SageMaker model cards
  3. AWS Glue Data Catalog
  4. drift and policy-violation monitoring

Correct Answer: C

 

Correct Answer

Answer C is correct because the description directly matches AWS Glue Data Catalog. AWS Glue Data Catalog provides a centralized catalog of data assets and schemas that can support discoverability and traceability.

Incorrect Answers

Answer A is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

Answer B is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

Answer D is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

 

Question 18

The manufacturing analytics team documents this GenAI behavior: captures who or what called supported AWS APIs, when the call occurred, and relevant request context. Which capability matches it?

  1. AWS Glue data lineage
  2. bias-drift monitoring
  3. organizational AI governance framework
  4. CloudTrail audit logging

Correct Answer: D

 

Correct Answer

Answer D is correct because the description directly matches CloudTrail audit logging. CloudTrail audit logging captures who or what called supported AWS APIs, when the call occurred, and relevant request context.

Incorrect Answers

Answer A is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

Answer B is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

Answer C is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

 

Question 19

The developer productivity team describes a component that defines enterprise rules and responsibilities instead of letting each application invent its own governance model. Which capability is being described?

  1. metadata source attribution
  2. automated remediation workflow
  3. organizational AI governance framework
  4. automated misuse detection

Correct Answer: C

 

Correct Answer

Answer C is correct because the description directly matches organizational AI governance framework. organizational AI governance framework defines enterprise rules and responsibilities instead of letting each application invent its own governance model.

Incorrect Answers

Answer A is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

Answer B is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

Answer D is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

 

Question 20

The business process automation team documents this GenAI behavior: monitors interactions for suspicious patterns and can trigger review or containment workflows. Which capability matches it?

  1. automated misuse detection
  2. drift and policy-violation monitoring
  3. token-level redaction and output policy filtering
  4. CloudWatch decision logging

Correct Answer: A

 

Correct Answer

Answer A is correct because the description directly matches automated misuse detection. automated misuse detection monitors interactions for suspicious patterns and can trigger review or containment workflows.

Incorrect Answers

Answer B is incorrect because drift and policy-violation monitoring is primarily used to detect when model behavior or application outputs move outside approved operating bounds, which is a different requirement from the one being tested.

Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer D is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

 

Question 21

The regulatory reporting platform describes a component that compares production observations with policy thresholds and baselines over time. Which capability is being described?

  1. drift and policy-violation monitoring
  2. AWS Glue Data Catalog
  3. SageMaker model cards
  4. bias-drift monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because the description directly matches drift and policy-violation monitoring. drift and policy-violation monitoring compares production observations with policy thresholds and baselines over time.

Incorrect Answers

Answer B is incorrect because AWS Glue Data Catalog is primarily used to register governed datasets and technical metadata used by GenAI applications, which is a different requirement from the one being tested.

Answer C is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

Answer D is incorrect because bias-drift monitoring is primarily used to detect changes in fairness-related behavior after deployment, which is a different requirement from the one being tested.

 

Question 22

The privacy engineering function needs to identify a capability with this behavior: tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated. What is the best match?

  1. AWS Glue data lineage
  2. CloudTrail audit logging
  3. automated remediation workflow
  4. bias-drift monitoring

Correct Answer: D

 

Correct Answer

Answer D is correct because the description directly matches bias-drift monitoring. bias-drift monitoring tracks fairness indicators across time, populations, or versions so emerging disparities can be investigated.

Incorrect Answers

Answer A is incorrect because AWS Glue data lineage is primarily used to track how governed data moves and changes through processing pipelines, which is a different requirement from the one being tested.

Answer B is incorrect because CloudTrail audit logging is primarily used to record AWS API activity for accountability and compliance investigations, which is a different requirement from the one being tested.

Answer C is incorrect because automated remediation workflow is primarily used to respond consistently when a governance control detects a serious violation, which is a different requirement from the one being tested.

 

Question 23

Within the logistics optimization team’s architecture, which capability matches this technical description: invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction?

  1. organizational AI governance framework
  2. automated remediation workflow
  3. token-level redaction and output policy filtering
  4. metadata source attribution

Correct Answer: B

 

Correct Answer

Answer B is correct because the description directly matches automated remediation workflow. automated remediation workflow invokes predefined containment, rollback, notification, or approval steps rather than relying only on manual reaction.

Incorrect Answers

Answer A is incorrect because organizational AI governance framework is primarily used to apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations, which is a different requirement from the one being tested.

Answer C is incorrect because token-level redaction and output policy filtering is primarily used to remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response, which is a different requirement from the one being tested.

Answer D is incorrect because metadata source attribution is primarily used to associate generated or retrieved information with its authoritative source, which is a different requirement from the one being tested.

 

Question 24

Within the service reliability organization’s architecture, which capability matches this technical description: applies fine-grained transformation and policy checks before output is released?

  1. CloudWatch decision logging
  2. automated misuse detection
  3. token-level redaction and output policy filtering
  4. SageMaker model cards

Correct Answer: C

 

Correct Answer

Answer C is correct because the description directly matches token-level redaction and output policy filtering. token-level redaction and output policy filtering applies fine-grained transformation and policy checks before output is released.

Incorrect Answers

Answer A is incorrect because CloudWatch decision logging is primarily used to retain operational evidence about model requests, policy outcomes, and application decisions, which is a different requirement from the one being tested.

Answer B is incorrect because automated misuse detection is primarily used to identify GenAI usage patterns that violate acceptable-use or safety policies, which is a different requirement from the one being tested.

Answer D is incorrect because SageMaker model cards is primarily used to document model purpose, limitations, evaluation results, and governance information, which is a different requirement from the one being tested.

 

Question 25

The enterprise finance automation team has proposed SageMaker model cards for its design. Which requirement best justifies it?

  1. Register governed datasets and technical metadata used by GenAI applications
  2. Document model purpose, limitations, evaluation results, and governance information
  3. Detect when model behavior or application outputs move outside approved operating bounds
  4. Track how governed data moves and changes through processing pipelines

Correct Answer: B

 

Correct Answer

Answer B is correct because SageMaker model cards is specifically used to document model purpose, limitations, evaluation results, and governance information. It creates structured model documentation that supports review, transparency, and controlled lifecycle decisions.

Incorrect Answers

Answer A is incorrect because that requirement aligns with AWS Glue Data Catalog, not SageMaker model cards.

Answer C is incorrect because that requirement aligns with drift and policy-violation monitoring, not SageMaker model cards.

Answer D is incorrect because that requirement aligns with AWS Glue data lineage, not SageMaker model cards.

 

Question 26

The risk and controls team is considering AWS Glue data lineage. What problem is this choice primarily meant to solve?

  1. Track how governed data moves and changes through processing pipelines
  2. Associate generated or retrieved information with its authoritative source
  3. Record AWS API activity for accountability and compliance investigations
  4. Detect changes in fairness-related behavior after deployment

Correct Answer: A

 

Correct Answer

Answer A is correct because AWS Glue data lineage is specifically used to track how governed data moves and changes through processing pipelines. It captures lineage relationships that help explain the origin and transformation path of information used by GenAI systems.

Incorrect Answers

Answer B is incorrect because that requirement aligns with metadata source attribution, not AWS Glue data lineage.

Answer C is incorrect because that requirement aligns with CloudTrail audit logging, not AWS Glue data lineage.

Answer D is incorrect because that requirement aligns with bias-drift monitoring, not AWS Glue data lineage.

 

Question 27

The enterprise search architecture group is considering metadata source attribution. What problem is this choice primarily meant to solve?

  1. Retain operational evidence about model requests, policy outcomes, and application decisions
  2. Respond consistently when a governance control detects a serious violation
  3. Apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations
  4. Associate generated or retrieved information with its authoritative source

Correct Answer: D

 

Correct Answer

Answer D is correct because metadata source attribution is specifically used to associate generated or retrieved information with its authoritative source. It adds consistent source identifiers and metadata so teams can trace outputs back to the data that informed them.

Incorrect Answers

Answer A is incorrect because that requirement aligns with CloudWatch decision logging, not metadata source attribution.

Answer B is incorrect because that requirement aligns with automated remediation workflow, not metadata source attribution.

Answer C is incorrect because that requirement aligns with organizational AI governance framework, not metadata source attribution.

 

Question 28

CloudWatch decision logging appears in an insurance automation architecture. What governance requirement does this capability satisfy most directly?

  1. Remove disallowed sensitive fragments while preserving the remainder of an otherwise acceptable response
  2. Retain operational evidence about model requests, policy outcomes, and application decisions
  3. Register governed datasets and technical metadata used by GenAI applications
  4. Identify GenAI usage patterns that violate acceptable-use or safety policies

Correct Answer: B

 

Correct Answer

Answer B is correct because CloudWatch decision logging is specifically used to retain operational evidence about model requests, policy outcomes, and application decisions. It stores searchable logs and metrics that support investigations, audits, and governance reviews.

Incorrect Answers

Answer A is incorrect because that requirement aligns with token-level redaction and output policy filtering, not CloudWatch decision logging.

Answer C is incorrect because that requirement aligns with AWS Glue Data Catalog, not CloudWatch decision logging.

Answer D is incorrect because that requirement aligns with automated misuse detection, not CloudWatch decision logging.

 

Question 29

Within the procurement automation group’s design, the team highlights AWS Glue Data Catalog. Which need does that component address?

  1. Detect when model behavior or application outputs move outside approved operating bounds
  2. Register governed datasets and technical metadata used by GenAI applications
  3. Record AWS API activity for accountability and compliance investigations
  4. Document model purpose, limitations, evaluation results, and governance information

Correct Answer: B

 

Correct Answer

Answer B is correct because AWS Glue Data Catalog is specifically used to register governed datasets and technical metadata used by GenAI applications. It provides a centralized catalog of data assets and schemas that can support discoverability and traceability.

Incorrect Answers

Answer A is incorrect because that requirement aligns with drift and policy-violation monitoring, not AWS Glue Data Catalog.

Answer C is incorrect because that requirement aligns with CloudTrail audit logging, not AWS Glue Data Catalog.

Answer D is incorrect because that requirement aligns with SageMaker model cards, not AWS Glue Data Catalog.

 

Question 30

The observability engineering group is considering CloudTrail audit logging. What problem is this choice primarily meant to solve?

  1. Record AWS API activity for accountability and compliance investigations
  2. Track how governed data moves and changes through processing pipelines
  3. Detect changes in fairness-related behavior after deployment
  4. Apply consistent policies, ownership, risk criteria, and approval processes across GenAI implementations

Correct Answer: A

 

Correct Answer

Answer A is correct because CloudTrail audit logging is specifically used to record AWS API activity for accountability and compliance investigations. It captures who or what called supported AWS APIs, when the call occurred, and relevant request context.

Incorrect Answers

Answer B is incorrect because that requirement aligns with AWS Glue data lineage, not CloudTrail audit logging.

Answer C is incorrect because that requirement aligns with bias-drift monitoring, not CloudTrail audit logging.

Answer D is incorrect because that requirement aligns with organizational AI governance framework, not CloudTrail audit logging.

 

img