A team is building an LLM application using Amazon Bedrock and customer data stored in Amazon S3. Company policy requires that each team can access only their own customers' data. Which approach enforces this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon Bedrock custom service role for each team that has access to only the team's customer data..
Why this is the answer
Creating an Amazon Bedrock custom service role for each team, with policies explicitly granting access only to that team's specific customer data in Amazon S3, directly enforces the company's data isolation policy. This ensures that Bedrock, when acting on behalf of a team, can only access authorized data. The option to "ask teams to specify the customer name on each Amazon Bedrock request" relies on application-level enforcement and doesn't prevent unauthorized access at the underlying data layer. Redacting personal data in S3 doesn't address the access control requirement for different teams. Creating one Bedrock role with full S3 access and relying on IAM roles for teams is insufficient because the Bedrock service itself would still have broad S3 access, potentially allowing a misconfigured or malicious Bedrock request to bypass team-specific IAM roles.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed