nerdexam
Amazon

AIF-C01 · Question #92

A company wants to create a chatbot by using a foundation model (FM) on Amazon Bedrock. The FM needs to access encrypted data that is stored in an Amazon S3 bucket. The data is encrypted with Amazon…

The correct answer is A. Ensure that the role that Amazon Bedrock assumes has permission to decrypt data with the. Amazon Bedrock needs the appropriate IAM role with permission to access and decrypt data stored in Amazon S3. If the data is encrypted with Amazon S3 managed keys (SSE-S3), the role that Amazon Bedrock assumes must have the required permissions to access and decrypt the

Submitted by weili_xi· Mar 30, 2026Security, Compliance, and Governance for AI Solutions

Question

A company wants to create a chatbot by using a foundation model (FM) on Amazon Bedrock. The FM needs to access encrypted data that is stored in an Amazon S3 bucket. The data is encrypted with Amazon S3 managed keys (SSE-S3). The FM encounters a failure when attempting to access the S3 bucket data. Which solution will meet these requirements?

Options

  • AEnsure that the role that Amazon Bedrock assumes has permission to decrypt data with the
  • BSet the access permissions for the S3 buckets to allow public access to enable access over the
  • CUse prompt engineering techniques to tell the model to look for information in Amazon S3.
  • DEnsure that the S3 data does not contain sensitive information.

How the community answered

(57 responses)
  • A
    77% (44)
  • B
    12% (7)
  • C
    7% (4)
  • D
    4% (2)

Explanation

Amazon Bedrock needs the appropriate IAM role with permission to access and decrypt data stored in Amazon S3. If the data is encrypted with Amazon S3 managed keys (SSE-S3), the role that Amazon Bedrock assumes must have the required permissions to access and decrypt the

Topics

#IAM permissions#S3 encryption#Amazon Bedrock#access control

Community Discussion

No community discussion yet for this question.

Full AIF-C01 Practice