AWA AIF-C01 - Domain 5 - Security, Compliance, and Governance for AI Solutions

AWS (Amazon Web Services) · AI Practitioner (AIF-C01)

By SpyderMan

Log in to rate

Certification Summary

The AWS Certified AI Practitioner AIF-C01 is for cloud engineers, data analysts, and developers who manage model deployments within an existing infrastructure. You take this exam when your manager decides the team needs a generative interface for internal documentation and you need to understand the service constraints before the inevitable integration failure occurs.

The test balances model selection and training strategies, with Applications of Foundation Models, Fundamentals of GenAI, and Fundamentals of AI and ML accounting for nearly three-quarters of the content. The remaining questions address Guidelines for Responsible AI and Security, Compliance, and Governance for AI Solutions. You spend your time identifying which Amazon Bedrock configurations minimize data leakage while keeping latency within acceptable parameters for downstream service calls.

Study

Card 1 of 40

Log in to mark cards as mastered and track progress.

The Imposter Hunt

The Imposter Hunt (Unlocked!)

Prove your knowledge to unlock this challenge.

Test your knowledge and spot the fake definitions.

0% / 75% mastery
0%

Mastery

0 of 40 cards mastered

All cards (40)

Scroll to review fronts and backs

Card 1

Front

AI Security

Back

Protecting AI systems, models, data, applications, and infrastructure against unauthorized access, misuse, manipulation, and attacks.

Card 2

Front

AI Governance

Back

Policies, processes, controls, and responsibilities used to manage AI systems throughout their lifecycle.

Card 3

Front

Data Governance

Back

Policies and practices for managing data availability, usability, integrity, security, privacy, and compliance.

Card 4

Front

Data Privacy

Back

Protecting personal and sensitive information from inappropriate collection, processing, access, disclosure, or use.

Card 5

Front

Data Residency

Back

The physical or geographic location where data is stored or processed.

Card 6

Front

Data Sovereignty

Back

The principle that data is subject to the laws and regulations of the country or jurisdiction where it is located.

Card 7

Front

Data Encryption

Back

Transforming data into an encoded form so it cannot be understood without the appropriate decryption mechanism.

Card 8

Front

Encryption at Rest

Back

Protecting stored data through encryption while it is not actively being transmitted.

Card 9

Front

Encryption in Transit

Back

Protecting data while it moves between systems, networks, or services.

Card 10

Front

AWS Key Management Service (KMS)

Back

An AWS service for creating and controlling cryptographic keys used to protect data and resources.

Card 11

Front

AWS Identity and Access Management (IAM)

Back

An AWS service for securely controlling access to AWS resources through identities, policies, roles, and permissions.

Card 12

Front

Least Privilege

Back

Granting users, applications, and services only the permissions required to perform their intended tasks.

Card 13

Front

IAM Role

Back

An AWS identity with permissions that can be assumed by trusted users, applications, or AWS services.

Card 14

Front

IAM Policy

Back

A document that defines permissions specifying which actions are allowed or denied on which resources.

Card 15

Front

Authentication

Back

Verifying the identity of a user, application, or system.

Card 16

Front

Authorization

Back

Determining which actions or resources an authenticated identity is permitted to access.

Card 17

Front

Multi-Factor Authentication (MFA)

Back

Requiring two or more authentication factors to verify an identity.

Card 18

Front

Access Control

Back

Mechanisms that determine who or what can access resources and what actions they are permitted to perform.

Card 19

Front

Prompt Injection

Back

An attack that attempts to manipulate an AI model by supplying malicious or conflicting instructions through input or retrieved content.

Card 20

Front

Jailbreaking

Back

Attempts to circumvent a model's built-in safety controls or restrictions through specially crafted inputs.

Card 21

Front

Data Poisoning

Back

Introducing malicious, incorrect, or manipulated data into training or other data sources to influence model behavior.

Card 22

Front

Model Poisoning

Back

Manipulating a model or its training process so that the resulting model behaves in an unintended or malicious way.

Card 23

Front

Adversarial Attack

Back

Deliberately crafted inputs designed to cause an AI model to produce incorrect, unsafe, or unintended results.

Card 24

Front

Adversarial Example

Back

An input intentionally modified in a way that can cause a machine learning model to make an incorrect prediction or classification.

Card 25

Front

Model Theft

Back

Unauthorized acquisition or reproduction of a model, its parameters, behavior, or capabilities.

Card 26

Front

Model Inversion

Back

An attack that attempts to infer sensitive information about the training data from a model's behavior or outputs.

Card 27

Front

Membership Inference

Back

An attack that attempts to determine whether a particular data record was included in a model's training dataset.

Card 28

Front

Prompt Leakage

Back

Unintended disclosure of system prompts, hidden instructions, or other information supplied to an AI model.

Card 29

Front

Sensitive Information Disclosure

Back

Exposure of confidential, personal, proprietary, or otherwise protected information through an AI system or its outputs.

Card 30

Front

Amazon Macie

Back

An AWS service that uses machine learning and pattern matching to discover and help protect sensitive data in Amazon S3.

Card 31

Front

AWS CloudTrail

Back

An AWS service that records API activity and actions taken in an AWS environment for auditing, monitoring, and governance.

Card 32

Front

Amazon CloudWatch

Back

An AWS monitoring and observability service used to collect metrics, logs, and other operational information.

Card 33

Front

AWS Config

Back

A service that continuously records and evaluates resource configurations to support compliance, auditing, and governance.

Card 34

Front

AWS Audit Manager

Back

An AWS service that helps collect evidence and continuously audit AWS usage against compliance frameworks and requirements.

Card 35

Front

AWS Artifact

Back

A self-service portal providing access to AWS security and compliance reports and agreements.

Card 36

Front

Amazon Bedrock Guardrails

Back

Controls that help filter harmful content, deny selected topics, and protect sensitive information when building generative AI applications with Amazon Bedrock.

Card 37

Front

Amazon Bedrock Model Invocation Logging

Back

A capability for logging model invocation inputs and outputs to support monitoring, auditing, and troubleshooting.

Card 38

Front

Compliance

Back

Meeting applicable laws, regulations, standards, contractual obligations, and organizational policies.

Card 39

Front

Audit Trail

Back

A chronological record of system activity that can be used to reconstruct events, investigate incidents, and demonstrate compliance.

Card 40

Front

Shared Responsibility Model

Back

AWS and the customer share responsibility for security and compliance: AWS secures the underlying cloud infrastructure, while customers remain responsible for security tasks within their use of AWS services.