QuestionQ2

AI Safety, Security, and Governance

A company uses an AWS Organizations organization with all features enabled to manage multiple AWS accounts. Employees use Amazon Bedrock in multiple accounts. The company must prevent particular topics and proprietary information from being included in prompts submitted to Amazon Bedrock models. The company must ensure that employees can use only approved Amazon Bedrock models. The company centrally administers IAM roles for employees.

Which combination of solutions will satisfy these requirements?

Choose two
Explanation

Amazon Bedrock Guardrails can block denied topics and sensitive information in model input prompts. A block filtering policy prevents the content from being processed, whereas a mask policy redacts detected values. Deploying the guardrail configuration through AWS CloudFormation StackSets provides consistent central deployment to member accounts. An SCP can explicitly deny model invocations that do not include the required guardrail identifier, while permissions boundaries on centrally managed employee roles restrict invocation permissions to approved model resources.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!