Question 1 · choose 1
A company with 60 AWS accounts in AWS Organizations must apply the same approved guardrail to every Amazon Bedrock model invocation in two OUs. Application teams must not need to change code or pass a guardrail ID, member accounts must not be able to weaken the guardrail, and the security team wants to confirm which guardrail is in force for any account. Which approach meets these requirements?
- AAttach an SCP to the OUs that denies bedrock:InvokeModel when the bedrock:GuardrailIdentifier condition key differs from the approved guardrail
- BAttach an Amazon Bedrock policy in AWS Organizations to the OUs that references a numbered guardrail version
- CDeploy the guardrail into every account with CloudFormation StackSets and let each team attach it to its own calls
- DShare the DRAFT version of the guardrail with every account through a resource-based policy and ask teams to reference it
Show the answer and why
AAttach an SCP to the OUs that denies bedrock:InvokeModel when the bedrock:GuardrailIdentifier condition key differs from the approved guardrail
Incorrect
Condition keys can require a guardrail, but every application would have to pass the guardrail ID in its calls, and calls without it would be rejected, which means code changes.
BAttach an Amazon Bedrock policy in AWS Organizations to the OUs that references a numbered guardrail version
Correct
Bedrock policies in Organizations enforce a guardrail automatically on every model invocation in the accounts beneath the node. A numbered version is immutable, and DescribeEffectivePolicy shows the effective policy for an account.
CDeploy the guardrail into every account with CloudFormation StackSets and let each team attach it to its own calls
Incorrect
Copies in each account can be modified by account administrators, and teams still have to add the guardrail to their calls.
DShare the DRAFT version of the guardrail with every account through a resource-based policy and ask teams to reference it
Incorrect
The working draft can change at any time, and asking teams to reference it relies on code changes in every application.
Organization-level enforcement applies safeguards for all inference calls without application changes. Reference an immutable guardrail version from the management account, attach the policy where it should apply, and check the result with DescribeEffectivePolicy because declarative policies resolve through inheritance rules.
AWS documentation