An ML engineer must call Amazon Bedrock APIs from EC2 instances that are in a private subnet and must remain private. The instances have a security group allowing access within the private subnet. How should the engineer connect the EC2 instances to Amazon Bedrock?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS PrivateLink to access Amazon Bedrock through an interface VPC endpoint..
Why this is the answer
The correct solution is to use AWS PrivateLink to access Amazon Bedrock through an interface VPC endpoint. This allows EC2 instances in a private subnet to securely and privately access Bedrock APIs without traversing the public internet. Interface VPC endpoints powered by PrivateLink establish private connectivity between your VPC and AWS services. Modifying the security group to allow inbound and outbound traffic to and from Amazon Bedrock is incorrect because Bedrock is a public service, and this would still require internet access, violating the requirement for instances to remain private. Configuring Amazon Bedrock to use the private subnet is incorrect; Bedrock is a managed service and cannot be deployed directly into a customer's private subnet. Linking the VPC to Amazon Bedrock using AWS Direct Connect is incorrect; Direct Connect provides a private connection between your on-premises network and AWS, but it doesn't directly enable private access from a VPC to an AWS service like Bedrock within the AWS network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed