An AI workload may connect only to approved AWS services.
Prevent unexpected model or log exfiltration.
Choose two designs.
Combine routes, security groups, network ACLs, proxies, and allow-lists, then monitor destination, volume, failures, and changes.
Detailed explanation
Paths and destinations are limited.
Paths and destinations are limited.
Exfiltration and misconfiguration can be detected.
Exfiltration and misconfiguration can be detected.
Attack and exfiltration surface grows.
Attack and exfiltration surface grows.
Data and destination are still risks.
Data and destination are still risks.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.1のネットワーク、最小権限、データ保護を確認する。Expected result
AIワークロードの外向き通信もセキュリティ境界として設計できる。Key points
- Allow list
- Egress
- Monitoring
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.