How to Identify Unauthorized Access Attempts to Amazon Bedrock?
A security company is using Amazon Bedrock to run foundation models (FMs). The company wants to ensure that only authorized users invoke the models. The company needs to identify any unauthorized access attempts to set appropriate AWS Identity and Access Management (IAM) policies and roles for future iterations of the FMs. Which AWS service should the company use to identify unauthorized users that are trying to access Amazon Bedrock?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests knowledge of AWS logging and monitoring services, specifically identifying CloudTrail as the tool for tracking API-level access attempts to AWS services like Amazon Bedrock.
AWS CloudTrail is the correct service to identify unauthorized access attempts to Amazon Bedrock by logging all API calls and user activity across AWS services. This enables security teams to audit usage and refine IAM policies.
Candidates may confuse AWS CloudTrail with AWS Audit Manager, which focuses on compliance auditing and evidence collection rather than real-time API call logging and unauthorized access detection.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Scenario
The question asks which AWS service should be used to identify unauthorized users attempting to access Amazon Bedrock. The key requirements are:
- Tracking access attempts to a specific AWS service (Amazon Bedrock)
- Identifying unauthorized users
- Providing data to refine IAM policies and roles
Why AWS CloudTrail is Correct
AWS CloudTrail is the AWS service designed specifically for logging and monitoring API calls made to AWS services. Every time a user or application makes an API request to Amazon Bedrock (or any AWS service), CloudTrail records the event, including:
- Who made the request (identity)
- What action was attempted
- When it occurred
- Whether the request was authorized or denied
Why Other Options Are Incorrect
- A. AWS Audit Manager: Helps manage compliance and audit evidence but does not provide real-time API-level logging of access attempts.
- C. Amazon Fraud Detector: Designed for detecting fraudulent activities in business transactions, not for tracking AWS API access.
- D. AWS Trusted Advisor: Provides best-practice recommendations for cost optimization, performance, and security, but does not log API calls or identify unauthorized access attempts.
Community Consensus
All community voters (100%) selected AWS CloudTrail, with comments emphasizing its role in recording API calls and user activity across AWS services, making it the definitive tool for this scenario.
Official Reference
Exam Strategy
When a question asks about identifying unauthorized access or tracking API calls to AWS services, immediately think of AWS CloudTrail. Eliminate options that focus on compliance, fraud detection, or best-practice recommendations.
Related Analysis
Practice All AIF-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AIF-C01 Practice Test →