How to prevent personal information in Amazon Bedrock model responses?
A medical company deployed a disease detection model on Amazon Bedrock. To comply with privacy policies, the company wants to prevent the model from including personal patient information in its responses. The company also wants to receive notification when policy violations occur. Which solution meets these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your ability to pair a content-filtering service (Guardrails) with a monitoring/notification service (CloudWatch); the common trap is choosing Macie, which scans data at rest in S3, not real-time model output.
Guardrails for Amazon Bedrock filter sensitive content from foundation model outputs, while Amazon CloudWatch alarms provide real-time notifications of policy violations. Community consensus confirms this is the only native, purpose-built solution for content-level privacy enforcement on Bedrock.
Option A (Amazon Macie) is the most common wrong answer because candidates associate Macie with sensitive-data detection, overlooking that Macie scans stored data in S3 buckets and cannot inspect streaming model responses.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Guardrails for Amazon Bedrock natively intercept foundation model input and output, applying configurable filters that block PII and other policy-violating content before it reaches the end user. Amazon CloudWatch integrates seamlessly with Bedrock to emit metrics on filtered content, enabling alarms and SNS notifications the moment a violation occurs. Together they satisfy both the prevention and notification requirements stated in the scenario.Why the Other Options Are Wrong
Amazon Macie (A) discovers sensitive data at rest in S3; it cannot inspect real-time Bedrock model responses. AWS CloudTrail (B) logs API calls but does not parse or analyze the textual content of model outputs for PII. SageMaker Model Monitor (D) detects data and concept drift in custom ML models, not content-policy violations in managed Bedrock foundation models.Community Comment Notes
Comment [1] concisely summarizes the pattern: "Guardrails to prevent, CloudWatch to notify." Comment [6] adds a valuable nuance—Macie would only be relevant if the question asked about scanning training data stored in S3, reinforcing why A is incorrect for output filtering.Official Reference
Exam Strategy
When a question asks to both block and alert on content-policy violations in a managed AI service, first identify the service-native content filter (Guardrails for Bedrock), then pair it with the standard AWS notification mechanism (CloudWatch alarms + SNS).
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →