AWS Shared Responsibility Model for Amazon Bedrock
A company wants to use Amazon Bedrock. The company needs to review which security aspects the company is responsible for when using Amazon Bedrock. Which security aspect will the company be responsible for?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the boundary of the shared responsibility model, specifically highlighting that customers must secure their data (encryption/access) even when using fully managed AI services where AWS handles patching and infrastructure.
In the AWS Shared Responsibility Model for managed services like Amazon Bedrock, customers retain responsibility for securing their own data in transit and at rest. The community consensus confirms that while AWS manages infrastructure security, data protection remains a customer obligation.
Candidates often incorrectly select options related to patching or provisioning infrastructure because they confuse general cloud service responsibilities with the specific 'customer' obligations for data governance and encryption.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Amazon Bedrock is a fully managed service, meaning AWS is responsible for the security OF the cloud, including patching the underlying models and infrastructure (Options A and B). However, under the shared responsibility model, the customer is always responsible for security IN the cloud, which explicitly includes protecting their data during transmission and storage (Option C). This involves managing encryption keys, access policies, and data classification.Why the Other Options Are Wrong
Options A and B describe tasks strictly managed by AWS; customers do not have direct access to the host infrastructure or model version patching cycles. Option D is incorrect because Amazon Bedrock is a serverless API-based service accessed over the internet or VPC endpoints, not something provisioned within a local company network like an on-premises appliance.Community Comment Notes
Commenters unanimously agree on Option C, reinforcing that 'securing your own data' is the primary customer duty. One comment highlights that this includes ensuring confidentiality and integrity via encryption, while another clarifies that AWS handles the service management, leaving data protection as the customer's burden.Official Reference
Exam Strategy
When studying for AWS exams, always distinguish between 'Security OF the Cloud' (AWS responsibility: hardware, global infrastructure, host OS) and 'Security IN the Cloud' (Customer responsibility: IAM, data encryption, configuration). For managed services like Bedrock or Lambda, remember you never manage the underlying infrastructure patching.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →