Question 1 · choose 1
A production web service will call Amazon Bedrock using a Bedrock API key as a bearer token. Security requires that the key expire within hours and carry no more permissions than the service's existing IAM role. Which credential should the ML engineer use?
- AA short-term Bedrock API key from the service's IAM role
- BA long-term Bedrock API key with a one-year expiration
- CThe access keys of the account root user
- DAn IAM user access key shared by all services
Show the answer and why
AA short-term Bedrock API key from the service's IAM role
Correct
Short-term API keys last up to 12 hours or the session duration, inherit the permissions of the IAM principal that generated them, and are recommended for production.
BA long-term Bedrock API key with a one-year expiration
Incorrect
Long-term keys last until their configured expiration and create an IAM user with attached policies. AWS recommends them only for exploration.
CThe access keys of the account root user
Incorrect
Root user credentials have full access to the account and should not be used for everyday work, let alone embedded in an application.
DAn IAM user access key shared by all services
Incorrect
Long-lived shared keys break least privilege and are hard to rotate. Temporary credentials tied to a role are the recommended practice.
Bedrock API keys come in two kinds. Short-term keys inherit the caller's IAM permissions and expire within hours, which fits production. Long-term keys are for exploration.