Which AWS Service Encrypts Amazon Bedrock Model Artifacts?
A company is using custom models in Amazon Bedrock for a generative AI application. The company wants to use a company managed encryption key to encrypt the model artifacts that the model customization jobs create. Which AWS service meets these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to map the requirement of 'company-managed encryption key' directly to AWS KMS, distinguishing it from services that handle secrets, vulnerability scanning, or data discovery.
Amazon Bedrock model customization jobs produce model artifacts that can be encrypted using a customer-managed key (CMK) in AWS Key Management Service (AWS KMS). KMS is the correct service for managing company-managed encryption keys for these artifacts.
Candidates sometimes choose AWS Secrets Manager because it also deals with secure credentials, but Secrets Manager is designed for storing and rotating secrets like passwords and API keys, not for encrypting data-at-rest artifacts.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Requirement
The scenario describes a company using custom models in Amazon Bedrock and needing to encrypt model artifacts generated by model customization jobs using a company-managed encryption key. The key phrase here is company-managed encryption key, which in AWS terminology refers to a Customer Master Key (CMK) managed within AWS Key Management Service (AWS KMS).
Why AWS KMS is Correct
AWS KMS is the AWS service purpose-built for creating, storing, and managing cryptographic keys. When you configure a model customization job in Amazon Bedrock, you can specify a KMS CMK to encrypt the output model artifacts at rest. This gives the company full control over the key lifecycle, key policies, and audit trails via AWS CloudTrail.
Why the Other Options Are Incorrect
- Amazon Inspector is an automated vulnerability management service that scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It has nothing to do with encryption key management.
- Amazon Macie is a data security service that uses machine learning to discover and protect sensitive data (e.g., PII) stored in Amazon S3. It does not manage encryption keys.
- AWS Secrets Manager is designed to store, rotate, and manage secrets such as database credentials, API keys, and OAuth tokens. While it also uses KMS under the hood, it is not the service you use to directly encrypt model artifacts with your own CMK.
Community Consensus
The community is unanimous (100% vote for A), and commenters correctly highlight that the phrase company-managed encryption key maps directly to KMS and its CMKs.
Official Reference
Exam Strategy
When a question mentions 'company-managed encryption key' or 'customer-managed key,' immediately think AWS KMS. Eliminate distractors like Secrets Manager (for credentials) and Macie (for sensitive data discovery) by focusing on the core function of each service.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →