A company is using custom models in Amazon Bedrock for a generative AI application. The company wants to use a company managed encryption key to encrypt the model artifacts that the model customization jobs create. Which AWS service meets these requirements?
Select an option, then click Submit answer.
Reference / correct answer:
AWS Key Management Service (AWS KMS)
Most accepted answer: A. AWS Key Management Service (AWS KMS)
Community votes: A=5
Selected Answer: A The company needs to use a company-managed encryption key to encrypt model artifacts. This points directly to key management. A. AWS Key Management Service (AWS KMS): This is the correct answer. AWS KMS allows you to create and manage encryption keys, including customer-managed keys (CMKs), which give you control over the key lifecycle and usage. B. Amazon Inspector: Inspector is a vulnerability management service that scans for security vulnerabilities in your AWS resources. C. Amazon Macie: Macie is a data security and privacy service that uses machine learning to discover and protect sensitive data in AWS. D. AWS Secrets Manager: Secrets Manager helps you manage secrets such as passwords, API keys, and database credentials. While it can store encrypted secrets, it's not the primary service for managing encryption keys used to protect model artifacts at rest. upvoted 5 times
Selected Answer: A A. AWS Key Management Service (AWS KMS) upvoted 1 times
Selected Answer: A A is the correct answer upvoted 1 times
Selected Answer: A Amazon Bedrock supports encryption of model artifacts using AWS Key Management Service (AWS KMS). AWS KMS allows you to use a company-managed encryption key (customer-managed key or CMK) to encrypt the model artifacts created during model customization jobs. upvoted 2 times
The company needs to use a company-managed encryption key to encrypt model artifacts. This points directly to key management. A. AWS Key Management Service (AWS KMS): This is the correct answer. AWS KMS allows you to create and manage encryption keys, including customer-managed keys (CMKs), which give you control over the key lifecycle and usage. B. Amazon Inspector: Inspector is a vulnerability management service that scans for security vulnerabilities in your AWS resources. C. Amazon Macie: Macie is a data security and privacy service that uses machine learning to discover and protect sensitive data in AWS. D. AWS Secrets Manager: Secrets Manager helps you manage secrets such as passwords, API keys, and database credentials. While it can store encrypted secrets, it's not the primary service for managing encryption keys used to protect model artifacts at rest. upvoted 1 times