AWS Certified AI PractitionerAWS Services for AI/ML and Generative AIHard
A company is developing a new large language model (LLM) and needs to ensure that the data used for training and fine-tuning is protected against unauthorized access and modification. They are particularly concerned about data at rest and in transit within AWS services like Amazon S3 and SageMaker. Which security best practice should they prioritize to address these concerns?
- AEncrypting data at rest using AWS Key Management Service (KMS) and data in transit using TLS.
- BImplementing strong IAM policies for SageMaker access only.
- CEnabling AWS WAF for web application security.
- DUtilizing AWS Shield Advanced for DDoS protection.
Show answer & explanationAnswer & explanation
Correct answer: A. Encrypting data at rest using AWS Key Management Service (KMS) and data in transit using TLS.
Protecting data at rest and in transit is a fundamental security best practice for sensitive training data. Encrypting data at rest using AWS KMS (e.g., S3 server-side encryption with KMS keys) prevents unauthorized access to stored data, while Transport Layer Security (TLS) ensures data privacy and integrity as it moves between services (e.g., S3 to SageMaker, or user to S3).
Why the other options are wrong
- B. Strong IAM policies are crucial for access control but don't directly protect the data itself from being read if accessed (at rest) or intercepted (in transit).
- C. AWS WAF protects web applications from common web exploits, which is relevant for application security but not directly for securing ML training data at rest or in transit between AWS services.
- D. AWS Shield Advanced provides DDoS protection at the network layer, which is important for availability but not for data confidentiality and integrity of training data.
Data Encryption in AWS AI/ML
The practice of encoding sensitive data to prevent unauthorized access, both when stored (at rest) and when being transmitted across networks (in transit).
- Data at rest: Encrypted using services like AWS KMS with S3, EBS, RDS, etc.
- Data in transit: Encrypted using Transport Layer Security (TLS) for network communication.
- Crucial for compliance (e.g., HIPAA, GDPR) and protecting intellectual property.
Memory trick: Encrypt data to keep it private, whether it's sitting still or moving around.