Which capabilities demonstrate regulatory compliance for a SageMaker chatbot?
A company wants to deploy a conversational chatbot to answer customer questions. The chatbot is based on a fine-tuned Amazon SageMaker JumpStart model. The application must comply with multiple regulatory frameworks. Which capabilities can the company show compliance for? (Choose two.)
Community Votes
100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the ability to distinguish between operational/business benefits and actual regulatory compliance requirements in AWS AI services.
When deploying a conversational chatbot using Amazon SageMaker JumpStart, regulatory compliance is demonstrated through threat detection and data protection capabilities. Community consensus strongly supports these two security-focused features as the correct answers.
Candidates often choose 'Auto scaling inference endpoints' thinking availability is a compliance requirement, but regulatory frameworks primarily focus on security controls like data protection and threat detection rather than performance scaling.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Regulatory Compliance in AWS AI Services
When deploying AI applications like conversational chatbots using Amazon SageMaker JumpStart, organizations must demonstrate compliance with various regulatory frameworks such as GDPR, HIPAA, PCI-DSS, or SOC 2. These frameworks primarily focus on security controls rather than operational efficiency.
Why Threat Detection and Data Protection Are Correct
B. Threat Detection: Regulatory frameworks universally require organizations to implement threat detection capabilities. Amazon SageMaker integrates with security services like Amazon GuardDuty and AWS CloudTrail to monitor for unauthorized access, suspicious activities, and potential security breaches. This continuous monitoring capability is essential for demonstrating compliance.
C. Data Protection: This is perhaps the most critical compliance requirement. SageMaker provides comprehensive data protection features including encryption at rest and in transit, integration with AWS KMS for key management, and Amazon Macie for sensitive data discovery. These capabilities directly address regulatory requirements for protecting customer data and maintaining confidentiality.
Why Other Options Are Incorrect
A. Auto scaling inference endpoints: While auto-scaling improves performance and availability, it is an operational capability, not a compliance requirement. Regulatory frameworks don't mandate specific scaling behaviors.
D. Cost optimization: This is a business objective, not a regulatory compliance requirement. No regulatory framework mandates cost optimization as a compliance control.
E. Loosely coupled microservices: This is an architectural design principle that improves maintainability and scalability, but it has no direct relationship with regulatory compliance requirements.
Community Insights
The community overwhelmingly supports BC with 92% agreement. Multiple users correctly identified that threat detection (GuardDuty) and data protection (encryption, Macie, KMS) are the security controls that regulatory frameworks actually require. As one community member noted, while auto-scaling might seem related to availability requirements, compliance frameworks focus on security controls rather than performance characteristics.
Official Reference
Exam Strategy
When questions ask about regulatory compliance, focus on security controls (encryption, monitoring, access control) rather than operational benefits (scaling, cost, architecture). Regulatory frameworks are primarily concerned with protecting data and detecting threats, not with system performance or cost efficiency.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →