An inference service searches sensitive documents.
Do not expose data directly to the public network.
Choose two designs.
Separate inference, retrieval, and storage paths and review security groups, egress controls, network logs, encryption, and IAM together.
Detailed explanation
Unneeded reachability is reduced.
Unneeded reachability is reduced.
Multiple boundaries are audited.
Multiple boundaries are audited.
The attack surface expands.
The attack surface expands.
Defense in depth remains required.
Defense in depth remains required.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.1のネットワーク、IAM、暗号化、AIワークロード保護を確認する。Expected result
AI推論からデータへの到達性を必要最小限に制限できる。Key points
- Network isolation
- Egress
- Reachability
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.