AWS Certified AI PractitionerAWS Services for AI/ML and Generative AIHard

A company is developing a new generative AI application using Amazon Bedrock. They want to ensure that all interactions with the foundation models (prompts and generated content) are encrypted both in transit and at rest to meet strict compliance mandates. Which AWS service is primarily responsible for managing the encryption keys used for this data protection within Bedrock?

  1. AAWS Secrets Manager
  2. BAWS CloudTrail
  3. CAWS Identity and Access Management (IAM)
  4. DAWS Key Management Service (KMS)
Show answer & explanation

Correct answer: D. AWS Key Management Service (KMS)

AWS Key Management Service (KMS) is the primary service for creating and managing cryptographic keys. Amazon Bedrock integrates with KMS to encrypt prompts and generated content at rest and in transit, allowing customers to use their own customer-managed keys (CMKs) for enhanced control.

Why the other options are wrong

  • A. Secrets Manager stores and manages database credentials, API keys, and other secrets, but not the encryption keys themselves for service data.
  • B. CloudTrail logs API activity for auditing, it does not manage encryption keys.
  • C. IAM manages access permissions, not encryption keys.

Encryption in AWS AI/ML

The practice of protecting data within AWS AI/ML services by converting it into a coded format, using AWS Key Management Service (KMS) for key management.

  • Crucial for data privacy and compliance.
  • Covers data at rest (storage) and in transit (network).
  • KMS provides centralized key management.
  • Customer-managed keys (CMKs) offer greater control.

Memory trick: KMS holds the keys to unlock your data's privacy.

More AWS Services for AI/ML and Generative AI questions