Bedrock FM Access to SSE-S3 Encrypted Data

A company wants to create a chatbot by using a foundation model (FM) on Amazon Bedrock. The FM needs to access encrypted data that is stored in an Amazon S3 bucket. The data is encrypted with Amazon S3 managed keys (SSE-S3). The FM encounters a failure when attempting to access the S3 bucket data. Which solution will meet these requirements?

  1. Ensure that the role that Amazon Bedrock assumes has permission to decrypt data with the correct encryption key. Source Reference Answer
  2. Set the access permissions for the S3 buckets to allow public access to enable access over the internet.
  3. Use prompt engineering techniques to tell the model to look for information in Amazon S3.
  4. Ensure that the S3 data does not contain sensitive information.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the understanding that accessing SSE-S3 encrypted objects via a service requires the assuming role to have s3:GetObject and necessary KMS/encryption permissions, not just standard object read rights.

This question addresses IAM permissions required for Amazon Bedrock foundation models to access data encrypted with SSE-S3 in Amazon S3. The community consensus confirms that the service role must have explicit decryption permissions to resolve access failures.

Option C is a common distractor; candidates may think prompt engineering can bypass security restrictions, but it cannot grant IAM permissions required for API calls to encrypted resources.

Community Discussion (8 comments)

Jessiii 👍 2 Selected: A
Amazon S3 managed keys (SSE-S3) encrypt your data using an Amazon-managed key, and to access this encrypted data, the IAM role that the service (in this case, Amazon Bedrock) assumes must have the appropriate permissions to decrypt the data. This includes permissions to read the object from the S3 bucket and decrypt it using the SSE-S3 encryption key.
Moon 👍 2 Selected: A
A: Ensure that the role that Amazon Bedrock assumes has permission to decrypt data with the correct encryption key. Explanation: When data in an Amazon S3 bucket is encrypted using SSE-S3 (Server-Side Encryption with Amazon S3 managed keys), the IAM role used by the application (in this case, Amazon Bedrock) must have permissions to access and decrypt the data. Assigning the correct permissions to the role ensures that the Foundation Model (FM) can access the encrypted data.
kyo 👍 2 Selected: A
>Permissions to decrypt your AWS KMS key for your data sources in Amazon S3 https://docs.aws.amazon.com/ja_jp/bedrock/latest/userguide/encryption-kb.html
87ebc7d 👍 2 Selected: A
None of the options are correct. To retrieve an object encrypted via SSE-S3, you just need GetObject permission. If I had this question on the exam, I'd be ticked.
elf78 👍 1
A) The correct Answer! B) Not a security best practice. never open the access to public! C) Has nothing to do with security D) Doesn't solve the access permission issue
tgv 👍 1 Selected: A
A - all the way.
jove 👍 2 Selected: A
A for sure
tccusa 👍 3 Selected: A
Permissions issue

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Bedrock uses an IAM execution role to interact with AWS services like S3. When data is encrypted with SSE-S3 (Server-Side Encryption with Amazon S3 managed keys), the service must still authenticate and authorize access. Although S3 manages the keys, the IAM role assumed by Bedrock must explicitly have s3:GetObject permission on the bucket/object and, depending on the specific integration setup, potentially permissions related to the encryption context. Without these permissions, the API call fails.

Why the Other Options Are Wrong

Option B suggests public access, which violates security best practices and does not solve the underlying permission issue for private buckets. Option C suggests prompt engineering, which influences model output but cannot bypass infrastructure-level IAM policies. Option D is irrelevant because removing sensitive data does not grant the technical permissions needed to access the encrypted files.

Community Comment Notes

Comment [1] correctly identifies that the IAM role needs appropriate permissions to decrypt data. Comment [4] offers a nuanced view, stating that technically only GetObject is needed for SSE-S3, suggesting the question might be imprecise regarding 'decrypt' vs 'access', but agrees A is the intended answer. Comments [5] and [6] reinforce that this is primarily a permissions/security issue rather than a content or engineering one.

Official Reference

Exam Strategy

Always verify the IAM permissions of the service assuming the role when dealing with encrypted data sources. Remember that encryption does not remove the need for explicit access control policies.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide