Which AWS Service Encrypts Amazon Bedrock Model Artifacts?

A company is using custom models in Amazon Bedrock for a generative AI application. The company wants to use a company managed encryption key to encrypt the model artifacts that the model customization jobs create. Which AWS service meets these requirements?

  1. AWS Key Management Service (AWS KMS) Source Reference Answer
  2. Amazon Inspector
  3. Amazon Macie
  4. AWS Secrets Manager

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to map the requirement of 'company-managed encryption key' directly to AWS KMS, distinguishing it from services that handle secrets, vulnerability scanning, or data discovery.

Amazon Bedrock model customization jobs produce model artifacts that can be encrypted using a customer-managed key (CMK) in AWS Key Management Service (AWS KMS). KMS is the correct service for managing company-managed encryption keys for these artifacts.

Candidates sometimes choose AWS Secrets Manager because it also deals with secure credentials, but Secrets Manager is designed for storing and rotating secrets like passwords and API keys, not for encrypting data-at-rest artifacts.

Community Discussion (4 comments)

Jessiii 👍 1 Selected: A
Amazon Bedrock supports encryption of model artifacts using AWS Key Management Service (AWS KMS). AWS KMS allows you to use a company-managed encryption key (customer-managed key or CMK) to encrypt the model artifacts created during model customization jobs.
Moon 👍 3 Selected: A
The company needs to use a company-managed encryption key to encrypt model artifacts. This points directly to key management. A. AWS Key Management Service (AWS KMS): This is the correct answer. AWS KMS allows you to create and manage encryption keys, including customer-managed keys (CMKs), which give you control over the key lifecycle and usage. B. Amazon Inspector: Inspector is a vulnerability management service that scans for security vulnerabilities in your AWS resources. C. Amazon Macie: Macie is a data security and privacy service that uses machine learning to discover and protect sensitive data in AWS. D. AWS Secrets Manager: Secrets Manager helps you manage secrets such as passwords, API keys, and database credentials. While it can store encrypted secrets, it's not the primary service for managing encryption keys used to protect model artifacts at rest.
Moon 👍 1
The company needs to use a company-managed encryption key to encrypt model artifacts. This points directly to key management. A. AWS Key Management Service (AWS KMS): This is the correct answer. AWS KMS allows you to create and manage encryption keys, including customer-managed keys (CMKs), which give you control over the key lifecycle and usage. B. Amazon Inspector: Inspector is a vulnerability management service that scans for security vulnerabilities in your AWS resources. C. Amazon Macie: Macie is a data security and privacy service that uses machine learning to discover and protect sensitive data in AWS. D. AWS Secrets Manager: Secrets Manager helps you manage secrets such as passwords, API keys, and database credentials. While it can store encrypted secrets, it's not the primary service for managing encryption keys used to protect model artifacts at rest.
aws_Tamilan 👍 1 Selected: A
To securely manage encryption keys for the custom models' artifacts, AWS Key Management Service (AWS KMS) is the correct service.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Requirement

The scenario describes a company using custom models in Amazon Bedrock and needing to encrypt model artifacts generated by model customization jobs using a company-managed encryption key. The key phrase here is company-managed encryption key, which in AWS terminology refers to a Customer Master Key (CMK) managed within AWS Key Management Service (AWS KMS).

Why AWS KMS is Correct

AWS KMS is the AWS service purpose-built for creating, storing, and managing cryptographic keys. When you configure a model customization job in Amazon Bedrock, you can specify a KMS CMK to encrypt the output model artifacts at rest. This gives the company full control over the key lifecycle, key policies, and audit trails via AWS CloudTrail.

Why the Other Options Are Incorrect

  • Amazon Inspector is an automated vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It has nothing to do with encryption key management.
  • Amazon Macie is a data security service that uses machine learning to discover and protect sensitive data (e.g., PII) stored in Amazon S3. It does not manage encryption keys.
  • AWS Secrets Manager is designed to store, rotate, and manage secrets such as database credentials, API keys, and OAuth tokens. While it also uses KMS under the hood, it is not the service you use to directly encrypt model artifacts with your own CMK.

Community Consensus

The community is unanimous (100% vote for A), and commenters correctly highlight that the phrase company-managed encryption key maps directly to KMS and its CMKs.

Official Reference

Exam Strategy

When a question mentions 'company-managed encryption key' or 'customer-managed key,' immediately think AWS KMS. Eliminate distractors like Secrets Manager (for credentials) and Macie (for sensitive data discovery) by focusing on the core function of each service.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide