AWS Shared Responsibility Model for Amazon Bedrock

Security, Identity, & Compliance

A company wants to use Amazon Bedrock. The company needs to review which security aspects the company is responsible for when using Amazon Bedrock. Which security aspect will the company be responsible for?

  1. Patching and updating the versions of Amazon Bedrock
  2. Protecting the infrastructure that hosts Amazon Bedrock
  3. Securing the company's data in transit and at rest Source Reference Answer
  4. Provisioning Amazon Bedrock within the company network

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the boundary of the shared responsibility model, specifically highlighting that customers must secure their data (encryption/access) even when using fully managed AI services where AWS handles patching and infrastructure.

In the AWS Shared Responsibility Model for managed services like Amazon Bedrock, customers retain responsibility for securing their own data in transit and at rest. The community consensus confirms that while AWS manages infrastructure security, data protection remains a customer obligation.

Candidates often incorrectly select options related to patching or provisioning infrastructure because they confuse general cloud service responsibilities with the specific 'customer' obligations for data governance and encryption.

Community Discussion (4 comments)

Jessiii 👍 1 Selected: C
When using Amazon Bedrock, AWS is responsible for managing and securing the infrastructure that supports the service, including patching and updating the service itself. However, the company still has responsibility for securing its own data, both during transmission (in transit) and when it is stored (at rest). This includes ensuring that sensitive data is protected using encryption, access controls, and other security best practices as part of shared responsibility.
85b5b55 👍 1 Selected: C
Encrypting the company's data In-TRANSIT and At-REST.
may2021_r 👍 1 Selected: C
The correct answer is C. Customers are responsible for securing their own data when using AWS services.
aws_Tamilan 👍 2 Selected: C
C. Securing the company's data in transit and at rest Explanation: When using Amazon Bedrock, the company is responsible for securing its data both in transit and at rest. This involves ensuring the confidentiality and integrity of the data that is uploaded to Amazon Bedrock or transmitted to and from the service.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Amazon Bedrock is a fully managed service, meaning AWS is responsible for the security OF the cloud, including patching the underlying models and infrastructure (Options A and B). However, under the shared responsibility model, the customer is always responsible for security IN the cloud, which explicitly includes protecting their data during transmission and storage (Option C). This involves managing encryption keys, access policies, and data classification.

Why the Other Options Are Wrong

Options A and B describe tasks strictly managed by AWS; customers do not have direct access to the host infrastructure or model version patching cycles. Option D is incorrect because Amazon Bedrock is a serverless API-based service accessed over the internet or VPC endpoints, not something provisioned within a local company network like an on-premises appliance.

Community Comment Notes

Commenters unanimously agree on Option C, reinforcing that 'securing your own data' is the primary customer duty. One comment highlights that this includes ensuring confidentiality and integrity via encryption, while another clarifies that AWS handles the service management, leaving data protection as the customer's burden.

Official Reference

Exam Strategy

When studying for AWS exams, always distinguish between 'Security OF the Cloud' (AWS responsibility: hardware, global infrastructure, host OS) and 'Security IN the Cloud' (Customer responsibility: IAM, data encryption, configuration). For managed services like Bedrock or Lambda, remember you never manage the underlying infrastructure patching.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide