Skip to content

Security, Compliance, and Governance for AI Solutions Questions

Practice questions for Security, Compliance, and Governance for AI Solutions topic in AWS Certified AI Practitioner. 28 questions covering this domain.

28 questions7 easy14 medium7 hard
Q1
medium

A compliance manager wants automated evidence collection to continually assess AWS usage against controls. Which AWS service should be used?

Q2
medium

An operations team needs to continually record configuration changes for AWS resources and evaluate them against desired state policies. Which service...

Q3
medium

A security team wants to discover sensitive data in Amazon S3 and gain visibility into data security risks at scale. Which AWS service is the best fit...

Q4
hard

A company is building an internal AI application on AWS and must encrypt sensitive data, restrict who can access resources, and keep service traffic p...

Q5
easy

Which AWS service provides access to AWS security and compliance reports?

Q6
medium

A company wants private connectivity from its VPC to AI-related AWS services without sending traffic over the public internet. Which AWS service shoul...

Q7
easy

Which AWS service tracks user activity and API usage to support governance, compliance, and operational auditing?

Q8
easy

Which AWS service centrally manages cryptographic keys to encrypt data at rest in AI workloads?

Q9
medium

An organization wants Amazon Bedrock model invocation requests and responses logged for security review. Which Bedrock capability should be enabled?

Q10
easy

Which AWS service enables fine-grained, identity-based access control to AWS resources used by AI workloads?

Q11
hard

A security architect uses the Generative AI Security Scoping Matrix to assess a use case where the company integrates a third-party SaaS GenAI app wit...

Q12
hard

A regulated company must demonstrate that AI training datasets in Amazon S3 are encrypted with customer-managed keys, are private to its VPC, and that...

Q13
medium

Which AWS networking feature lets a VPC reach Amazon Bedrock APIs without traversing the public internet?

Q14
medium

Which statement reflects AWS's documented data privacy stance for customer data submitted to Amazon Bedrock?

Q15
medium

A company wants to ensure AI development teams can only deploy approved foundation models and cannot create unapproved Bedrock resources. Which AWS fe...

Q16
easy

Which AWS security principle recommends granting users and services only the minimum permissions required to perform their tasks?

Q17
hard

A DevOps team is setting up an automated compliance pipeline for AI workloads on AWS. They want to continuously check whether Bedrock resources and as...

Q18
medium

A security team needs to ensure that custom model weights stored in Amazon S3 for a Bedrock fine-tuning job are encrypted at rest using customer-contr...

Q19
hard

A financial institution must demonstrate to regulators that all prompts sent to and responses received from Amazon Bedrock are retained for five years...

Q20
medium

A team wants to detect and flag potential security threats in AWS accounts running AI workloads, such as unusual API calls or compromised credentials,...

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.