Which capabilities demonstrate regulatory compliance for a SageMaker chatbot?

A company wants to deploy a conversational chatbot to answer customer questions. The chatbot is based on a fine-tuned Amazon SageMaker JumpStart model. The application must comply with multiple regulatory frameworks. Which capabilities can the company show compliance for? (Choose two.)

  1. Auto scaling inference endpoints
  2. Threat detection Source Reference Answer
  3. Data protection Source Reference Answer
  4. Cost optimization
  5. Loosely coupled microservices

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the ability to distinguish between operational/business benefits and actual regulatory compliance requirements in AWS AI services.

When deploying a conversational chatbot using Amazon SageMaker JumpStart, regulatory compliance is demonstrated through threat detection and data protection capabilities. Community consensus strongly supports these two security-focused features as the correct answers.

Candidates often choose 'Auto scaling inference endpoints' thinking availability is a compliance requirement, but regulatory frameworks primarily focus on security controls like data protection and threat detection rather than performance scaling.

Community Discussion (8 comments)

Jessiii 👍 2 Selected: BC
B. Threat detection: Regulatory frameworks often require companies to have the ability to detect and respond to threats, ensuring that sensitive data is protected from unauthorized access or misuse. Amazon services like Amazon GuardDuty can help with threat detection, which is an important part of compliance. C. Data protection: Compliance with regulatory frameworks typically involves ensuring that data is securely stored and processed. Amazon SageMaker provides built-in data protection features such as encryption, and it is essential to comply with privacy regulations like GDPR, HIPAA, etc. This ensures that sensitive data is properly handled.
85b5b55 👍 1 Selected: BC
Threat (Amazon GuardDuty) and Data Protection (Amazon Macie, KMS, Encrypt the data at REST and in-Transit.
Moon 👍 1 Selected: BC
Why not the other options? A: Auto scaling inference endpoints: Auto-scaling improves performance and cost-efficiency but is not directly related to regulatory compliance. D: Cost optimization: Cost optimization is beneficial for managing expenses but is not a compliance requirement. E: Loosely coupled microservices: While a good architectural principle, it does not directly address compliance with regulatory frameworks.
Moon 👍 1 Selected: BC
B: Threat detection C: Data protection Explanation: When deploying a conversational chatbot using a fine-tuned model from Amazon SageMaker JumpStart, the company can demonstrate compliance in the following areas: B: Threat detection: Amazon SageMaker integrates with AWS security services like Amazon GuardDuty and AWS CloudTrail to monitor for threats and unauthorized access. This ensures compliance with security regulations. C: Data protection: SageMaker supports encryption of data at rest and in transit, integration with AWS Key Management Service (KMS), and fine-grained access control through IAM. These features ensure compliance with regulatory frameworks requiring data protection.
eesa 👍 2 Selected: BC
The two capabilities that the company can show compliance for are: C. Data protection B. Threat detection Here's a breakdown: Data Protection: Amazon SageMaker offers robust data protection features, including data encryption at rest and in transit. By leveraging these features, the company can ensure that customer data is handled securely and complies with relevant data privacy regulations. Threat Detection: Amazon Web Services (AWS) provides a comprehensive security suite, including services like Amazon GuardDuty and AWS Security Hub. These services can help detect and respond to potential threats, such as unauthorized access, data breaches, and malicious activity. By utilizing these services, the company can demonstrate its commitment to security and compliance.
urbanmonk 👍 1 Selected: C
Data Protection - certainly. Not sure which other option fits into the regulatory context.
RY66 👍 1
The correct answers for this question are: A. Auto scaling inference endpoints C. Data protection Auto scaling inference endpoints: Amazon SageMaker provides auto-scaling capabilities that automatically adjust infrastructure based on traffic changes. This helps meet availability and performance requirements, which are crucial aspects of regulatory compliance. Many regulatory frameworks require service stability and availability, making this feature an important element in demonstrating compliance. Data protection: Data protection is a core requirement in most regulatory frameworks. Amazon SageMaker offers various data protection features including data encryption, access control, and audit logging. For a chatbot handling customer data, demonstrating data protection capabilities is essential for regulatory compliance.
jove 👍 4 Selected: BC
C. Data protection and B. Threat detection are the two key capabilities that can help the company meet regulatory compliance requirements when deploying a conversational chatbot using Amazon SageMaker JumpStart.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Regulatory Compliance in AWS AI Services

When deploying AI applications like conversational chatbots using Amazon SageMaker JumpStart, organizations must demonstrate compliance with various regulatory frameworks such as GDPR, HIPAA, PCI-DSS, or SOC 2. These frameworks primarily focus on security controls rather than operational efficiency.

Why Threat Detection and Data Protection Are Correct

B. Threat Detection: Regulatory frameworks universally require organizations to implement threat detection capabilities. Amazon SageMaker integrates with security services like Amazon GuardDuty and AWS CloudTrail to monitor for unauthorized access, suspicious activities, and potential security breaches. This continuous monitoring capability is essential for demonstrating compliance.

C. Data Protection: This is perhaps the most critical compliance requirement. SageMaker provides comprehensive data protection features including encryption at rest and in transit, integration with AWS KMS for key management, and Amazon Macie for sensitive data discovery. These capabilities directly address regulatory requirements for protecting customer data and maintaining confidentiality.

Why Other Options Are Incorrect

A. Auto scaling inference endpoints: While auto-scaling improves performance and availability, it is an operational capability, not a compliance requirement. Regulatory frameworks don't mandate specific scaling behaviors.

D. Cost optimization: This is a business objective, not a regulatory compliance requirement. No regulatory framework mandates cost optimization as a compliance control.

E. Loosely coupled microservices: This is an architectural design principle that improves maintainability and scalability, but it has no direct relationship with regulatory compliance requirements.

Community Insights

The community overwhelmingly supports BC with 92% agreement. Multiple users correctly identified that threat detection (GuardDuty) and data protection (encryption, Macie, KMS) are the security controls that regulatory frameworks actually require. As one community member noted, while auto-scaling might seem related to availability requirements, compliance frameworks focus on security controls rather than performance characteristics.

Official Reference

Exam Strategy

When questions ask about regulatory compliance, focus on security controls (encryption, monitoring, access control) rather than operational benefits (scaling, cost, architecture). Regulatory frameworks are primarily concerned with protecting data and detecting threats, not with system performance or cost efficiency.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide