A security firm running foundation models on Amazon Bedrock needs to detect unauthorized attempts to call those models so it can apply appropriate IAM policies. Which AWS service should they use to find who tried to access Bedrock?
Choose an answer
Tap an option to check your answer.
Correct answer: AWS CloudTrail.
Why this is the answer
AWS CloudTrail is the correct choice because it records API calls made to AWS services, including Amazon Bedrock. This allows the security firm to track who attempted to access their foundation models, when, and from where, providing the necessary audit trail to identify unauthorized access attempts and refine IAM policies. AWS Audit Manager helps with continuous auditing and compliance, but doesn't directly log API calls. Amazon Fraud Detector identifies potentially fraudulent online activities, which is a different use case. AWS Trusted Advisor provides recommendations for cost optimization, security, performance, and fault tolerance, but does not log individual API access attempts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed