A data scientist needs to allow a foundation model in Amazon Bedrock to access a specific S3 bucket containing reference documents. The bucket is in a different AWS account. What is the MOST secure way to grant access?
Trap 1: Use AWS Lake Formation to grant cross-account access to the bucket
Lake Formation governs data lakes in the same account or via Resource Access Manager, but direct S3 bucket access for Bedrock is not managed by Lake Formation.
Trap 2: Copy the S3 bucket to the same account as Bedrock
Copying data is inefficient and may violate data residency requirements; cross-account access can be secured with policies.
Trap 3: Make the S3 bucket public and use a pre-signed URL
Making the bucket public violates security best practices; pre-signed URLs are for temporary access, not for ongoing model access.
- A
Use AWS Lake Formation to grant cross-account access to the bucket
Why it fails: Lake Formation governs data lakes in the same account or via Resource Access Manager, but direct S3 bucket access for Bedrock is not managed by Lake Formation.
- B
Copy the S3 bucket to the same account as Bedrock
Why it fails: Copying data is inefficient and may violate data residency requirements; cross-account access can be secured with policies.
- C
Configure the S3 bucket policy to allow access from the Bedrock service role and add a Bedrock resource policy allowing the bucket
Cross-account access needs both sides: the S3 bucket policy grants the Bedrock service role permission, and the Bedrock resource policy authorises the bucket. This scoped, resource-based approach avoids broad IAM roles or public access, meeting the most-secure requirement.
- D
Make the S3 bucket public and use a pre-signed URL
Why it fails: Making the bucket public violates security best practices; pre-signed URLs are for temporary access, not for ongoing model access.