Question 1 · choose 1
An insurance company wants an internal assistant that answers employee questions about underwriting guidelines. The guidelines live in Confluence and SharePoint, change several times a week, and are visible only to certain teams in those systems. Answers must cite the source page, must respect the existing permissions of each employee, and the team has no capacity to run or scale its own vector database. Which design meets these requirements?
- ACreate an Amazon Bedrock managed knowledge base with Confluence and SharePoint connectors and ACL awareness, and pass each user's identity
- BFine-tune a foundation model on an export of the guidelines every week and serve it through an on-demand custom model deployment
- CCreate a customer-managed knowledge base on Amazon OpenSearch Serverless and copy the pages into Amazon S3 with a nightly export job
- DPlace all guideline pages in the system prompt of every request and instruct the model to quote the title of each page it relied on in the answer
Show the answer and why
ACreate an Amazon Bedrock managed knowledge base with Confluence and SharePoint connectors and ACL awareness, and pass each user's identity
Correct
A managed knowledge base provides the Confluence and SharePoint connectors, crawls document permissions when ACL awareness is enabled, filters results by the user context supplied at query time, and returns citations. Bedrock manages the data store, so no vector database has to be operated.
BFine-tune a foundation model on an export of the guidelines every week and serve it through an on-demand custom model deployment
Incorrect
Fine-tuning bakes the content into model weights, so answers lag behind changes made between training runs, cannot cite a source page, and cannot enforce per-team visibility.
CCreate a customer-managed knowledge base on Amazon OpenSearch Serverless and copy the pages into Amazon S3 with a nightly export job
Incorrect
A customer-managed knowledge base means provisioning and managing the vector store, and the third-party connectors and document-level permission filtering are offered only for managed knowledge bases. A nightly copy to S3 also drops the source permissions.
DPlace all guideline pages in the system prompt of every request and instruct the model to quote the title of each page it relied on in the answer
Incorrect
Several systems' worth of pages do not fit in a context window, every request would pay for all of those tokens, and a prompt instruction cannot enforce which employee may see which page.
Frequently changing internal content with citations is a retrieval problem, not a training problem. When the sources are third-party systems with their own permissions and nobody wants to run a vector database, the managed knowledge base is the fit: native connectors, ACL-aware retrieval and a Bedrock-managed store. The application must still authenticate the user, because ACL awareness filters on the identity it is given.
AWS documentation
- Build a managed knowledge base (opens in a new tab)
- Access Control Lists awareness enablement (opens in a new tab)
- Retrieve data and generate AI responses with Amazon Bedrock Knowledge Bases (opens in a new tab)
- GENOPS05-BP01 Learn when to customize models (opens in a new tab)
- How tokens are counted in Amazon Bedrock (opens in a new tab)