How to restrict Amazon Bedrock data access per team?
A company wants to develop a large language model (LLM) application by using Amazon Bedrock and customer data that is uploaded to Amazon S3. The company's security policy states that each team can access data for only the team's own customers. Which solution will meet these requirements?
Community Votes
71% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the principle of least privilege applied to Amazon Bedrock's service role — the role Bedrock assumes to access S3 must itself be restricted, because downstream team IAM roles cannot prevent Bedrock from reading data the service role can see.
To enforce team-level data isolation in Amazon Bedrock, create a custom service role per team with S3 permissions scoped to only that team's customer data. This implements least privilege directly at the service role used by Bedrock to read knowledge base data.
Candidates often pick D, assuming team IAM roles on S3 folders are enough. They miss that Bedrock uses its own service role to read S3, so a single Bedrock role with full S3 access would let the model see and potentially expose all customers' data regardless of team IAM permissions.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
The correct answer is A. Amazon Bedrock accesses customer data in Amazon S3 through a service role that you attach to the model or knowledge base. If the security policy requires that each team can access only its own customers' data, the restriction must be enforced at the service role itself, because that is the identity Bedrock assumes when reading from S3. By creating a custom service role per team with an IAM policy scoped to the specific S3 prefix (folder) containing that team's customer data, you guarantee that Bedrock can only ever retrieve that team's data.
Why the other options fail:
- B is incorrect because asking teams to "specify the customer name" in each request does not enforce access control — it relies on user behavior and provides no technical guardrail. Bedrock would still need S3 access governed by the service role.
- C is incorrect because redacting data does not solve the access control requirement; teams could still access other teams' (redacted) data, and redaction is not a substitute for IAM-based isolation.
- D is the most common trap. It proposes a single Bedrock service role with full S3 access and relies on per-team IAM roles to restrict access. However, Bedrock reads S3 using the service role, not the calling team's IAM role. If the service role has full S3 access, Bedrock can read and potentially surface data from any customer folder, violating the policy. Community comment [8] correctly points out: "IAM roles for each team won't stop Bedrock from knowing and replying with that data."
Official Reference
Exam Strategy
When an AWS service accesses your data on your behalf, always identify the service-linked or service role it assumes. Access control must be enforced on that role, not just on the end-user's IAM identity.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →