A company has access to Amazon Bedrock and wants to limit which Bedrock models specific employees can use. Which approach satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Identity and Access Management (IAM) policies to restrict model access..
Why this is the answer
AWS Identity and Access Management (IAM) policies are the correct and most granular way to control access to specific Amazon Bedrock models. IAM policies allow you to define permissions that specify which actions (e.g., bedrock:InvokeModel) can be performed on which resources (e.g., a specific Bedrock model ARN) by which users or roles. This directly addresses the requirement to limit model usage for specific employees. AWS Security Token Service (AWS STS) generates temporary credentials but doesn't define the permissions themselves; those are still governed by IAM policies attached to the role or user. IAM service roles are used for services to assume permissions, not typically for restricting individual user access to specific models within a service. Amazon Inspector is a security assessment service, not an access control mechanism.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed