Bedrock FM Access to SSE-S3 Encrypted Data
A company wants to create a chatbot by using a foundation model (FM) on Amazon Bedrock. The FM needs to access encrypted data that is stored in an Amazon S3 bucket. The data is encrypted with Amazon S3 managed keys (SSE-S3). The FM encounters a failure when attempting to access the S3 bucket data. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the understanding that accessing SSE-S3 encrypted objects via a service requires the assuming role to have s3:GetObject and necessary KMS/encryption permissions, not just standard object read rights.
This question addresses IAM permissions required for Amazon Bedrock foundation models to access data encrypted with SSE-S3 in Amazon S3. The community consensus confirms that the service role must have explicit decryption permissions to resolve access failures.
Option C is a common distractor; candidates may think prompt engineering can bypass security restrictions, but it cannot grant IAM permissions required for API calls to encrypted resources.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Bedrock uses an IAM execution role to interact with AWS services like S3. When data is encrypted with SSE-S3 (Server-Side Encryption with Amazon S3 managed keys), the service must still authenticate and authorize access. Although S3 manages the keys, the IAM role assumed by Bedrock must explicitly haves3:GetObject permission on the bucket/object and, depending on the specific integration setup, potentially permissions related to the encryption context. Without these permissions, the API call fails.Why the Other Options Are Wrong
Option B suggests public access, which violates security best practices and does not solve the underlying permission issue for private buckets. Option C suggests prompt engineering, which influences model output but cannot bypass infrastructure-level IAM policies. Option D is irrelevant because removing sensitive data does not grant the technical permissions needed to access the encrypted files.Community Comment Notes
Comment [1] correctly identifies that the IAM role needs appropriate permissions to decrypt data. Comment [4] offers a nuanced view, stating that technically onlyGetObject is needed for SSE-S3, suggesting the question might be imprecise regarding 'decrypt' vs 'access', but agrees A is the intended answer. Comments [5] and [6] reinforce that this is primarily a permissions/security issue rather than a content or engineering one. Official Reference
Exam Strategy
Always verify the IAM permissions of the service assuming the role when dealing with encrypted data sources. Remember that encryption does not remove the need for explicit access control policies.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →