How to Identify Unauthorized Access Attempts to Amazon Bedrock?

A security company is using Amazon Bedrock to run foundation models (FMs). The company wants to ensure that only authorized users invoke the models. The company needs to identify any unauthorized access attempts to set appropriate AWS Identity and Access Management (IAM) policies and roles for future iterations of the FMs. Which AWS service should the company use to identify unauthorized users that are trying to access Amazon Bedrock?

  1. AWS Audit Manager
  2. AWS CloudTrail Source Reference Answer
  3. Amazon Fraud Detector
  4. AWS Trusted Advisor

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests knowledge of AWS logging and monitoring services, specifically identifying CloudTrail as the tool for tracking API-level access attempts to AWS services like Amazon Bedrock.

AWS CloudTrail is the correct service to identify unauthorized access attempts to Amazon Bedrock by logging all API calls and user activity across AWS services. This enables security teams to audit usage and refine IAM policies.

Candidates may confuse AWS CloudTrail with AWS Audit Manager, which focuses on compliance auditing and evidence collection rather than real-time API call logging and unauthorized access detection.

Community Discussion (6 comments)

Jessiii 👍 3 Selected: B
AWS CloudTrail: CloudTrail records all API requests made to AWS services, including Amazon Bedrock. By using CloudTrail, the security company can track and log all access attempts, including any unauthorized attempts, to access Amazon Bedrock. This helps the company identify and respond to unauthorized access, and also provides detailed logs for setting up appropriate IAM policies and roles.
eyzzeuss 👍 2 Selected: B
AWS CloudTrail is a service that records all API calls and user activity across AWS services, including Amazon Bedrock.
85b5b55 👍 1 Selected: B
Use AWS CloudTrail to track the API Calls to AWS resources.
nandhae 👍 1 Selected: B
B. AWS CloudTrail CloudTrail records API activity and user actions in your AWS account. It logs events such as unauthorized access attempts to Amazon Bedrock and other AWS services, making it the correct choice for identifying such attempts.
Moon 👍 2 Selected: B
B: AWS CloudTrail Explanation: AWS CloudTrail is a service that records all API calls and user activity across AWS services, including Amazon Bedrock. By analyzing CloudTrail logs, the company can identify unauthorized access attempts, track user activity, and audit the usage of foundation models. This information helps in setting appropriate AWS Identity and Access Management (IAM) policies and roles for future iterations of the models.
jove 👍 3 Selected: B
B. AWS CloudTrail is the most suitable service for identifying unauthorized access attempts to Amazon Bedrock, as it provides detailed logging and monitoring of API calls across AWS services, helping to enforce security and compliance.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Scenario

The question asks which AWS service should be used to identify unauthorized users attempting to access Amazon Bedrock. The key requirements are:

  • Tracking access attempts to a specific AWS service (Amazon Bedrock)
  • Identifying unauthorized users
  • Providing data to refine IAM policies and roles

Why AWS CloudTrail is Correct

AWS CloudTrail is the AWS service designed specifically for logging and monitoring API calls made to AWS services. Every time a user or application makes an API request to Amazon Bedrock (or any AWS service), CloudTrail records the event, including:

  • Who made the request (identity)
  • What action was attempted
  • When it occurred
  • Whether the request was authorized or denied
By analyzing CloudTrail logs, security teams can identify unauthorized access attempts, track patterns, and use this information to create more precise IAM policies and roles.

Why Other Options Are Incorrect

  • A. AWS Audit Manager: Helps manage compliance and audit evidence but does not provide real-time API-level logging of access attempts.
  • C. Amazon Fraud Detector: Designed for detecting fraudulent activities in business transactions, not for tracking AWS API access.
  • D. AWS Trusted Advisor: Provides best-practice recommendations for cost optimization, performance, and security, but does not log API calls or identify unauthorized access attempts.

Community Consensus

All community voters (100%) selected AWS CloudTrail, with comments emphasizing its role in recording API calls and user activity across AWS services, making it the definitive tool for this scenario.

Official Reference

Exam Strategy

When a question asks about identifying unauthorized access or tracking API calls to AWS services, immediately think of AWS CloudTrail. Eliminate options that focus on compliance, fraud detection, or best-practice recommendations.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide