
Ultimate access to all questions.
Deep dive into the quiz with AI chat providers.
We prepare a focused prompt with your quiz and certificate details so each AI can offer a more tailored, in-depth explanation.
Which AWS capability helps organizations restrict the regions where Amazon Bedrock can be accessed?
A
AWS Trusted Advisor
B
Service Control Policies (SCPs) in AWS Organizations
Explanation:
Service Control Policies (SCPs) in AWS Organizations is the correct answer.
SCPs are designed for centralized governance: Service Control Policies are a feature of AWS Organizations that allow you to set permission guardrails for what actions users and roles can perform across your AWS accounts.
Region restriction capability: SCPs can be used to restrict access to AWS services in specific regions. You can create policies that:
Deny access to Amazon Bedrock in certain regions
Allow access only to specific regions
Control which accounts can access Bedrock in which regions
Organizational-level control: SCPs work at the AWS Organizations level, making them ideal for enterprise-wide governance and compliance requirements.
AWS Trusted Advisor is an optimization tool that provides recommendations to help you follow AWS best practices for cost optimization, performance, security, and fault tolerance.
It does not have the capability to restrict access to AWS services or regions.
Trusted Advisor is advisory in nature and cannot enforce access controls.
Amazon Bedrock is a fully managed service that makes foundation models (FMs) from leading AI companies available through a single API. Organizations often need to control where their AI workloads run for compliance, data residency, or cost management reasons. SCPs provide the centralized governance mechanism to enforce these restrictions across all AWS accounts in an organization.