AWS Certified AI Practitioner · AIF-C01 · Domain 5
AIF-C01 Domain 5: Security, compliance and governance
Domain 5 accounts for 14% of AIF-C01 and tests how AWS security and governance principles apply to AI data, models and applications.
What to understand
Apply least privilege throughout the AI workflow. Control who can invoke models, access source data, manage prompts and retrieve logs. Protect data in transit and at rest, and understand where sensitive information may enter or leave the system.
- Use IAM roles and policies for scoped access instead of shared credentials.
- Use encryption and key controls appropriate to the data classification.
- Log model and application activity for monitoring, incident response and audit.
- Review prompt injection, sensitive-data disclosure and excessive agent permissions.
Common AIF-C01 decisions
Security, privacy and compliance are related but not interchangeable. A technically secure system can still violate retention, residency or consent requirements. Governance defines ownership, approved use, monitoring and review.
Try the fixed 20-question AIF-C01 practice setAll five domains
