Question 1 · choose 1
An application in private subnets with no internet gateway or NAT gateway must call Amazon Bedrock models. Security requires that the traffic stay on the AWS network, that calls through this path be allowed only for the two approved models, and that the control sit in the network path rather than only in application roles. What should the developer configure?
- AA NAT gateway in a public subnet with a security group that allows only the Bedrock endpoint addresses
- BAn interface VPC endpoint for bedrock-agent with an endpoint policy that lists the two models
- CA gateway VPC endpoint for Amazon Bedrock with a route table entry in each private subnet
- DAn interface VPC endpoint for bedrock-runtime with an endpoint policy that allows only the two approved models
Show the answer and why
AA NAT gateway in a public subnet with a security group that allows only the Bedrock endpoint addresses
Incorrect
Traffic through a NAT gateway goes to the public service endpoint, and the subnets were designed without internet egress.
BAn interface VPC endpoint for bedrock-agent with an endpoint policy that lists the two models
Incorrect
The bedrock-agent endpoint serves build-time agent APIs. Model inference calls use the bedrock-runtime endpoint.
CA gateway VPC endpoint for Amazon Bedrock with a route table entry in each private subnet
Incorrect
Gateway endpoints exist only for Amazon S3 and DynamoDB. Bedrock is reached through interface endpoints.
DAn interface VPC endpoint for bedrock-runtime with an endpoint policy that allows only the two approved models
Correct
An interface endpoint (AWS PrivateLink) reaches Bedrock without an internet gateway or NAT, and its endpoint policy restricts which actions and resources can be used through it.
Private access to Bedrock uses interface endpoints, one per API family: bedrock (control plane), bedrock-runtime (inference), bedrock-mantle, bedrock-agent and bedrock-agent-runtime. Endpoint policies add a network-path control on top of IAM.
AWS documentation