Prompt logs and model calls need protection.
Check encryption boundaries.
Choose two controls.
Encrypt logs, stores, and backups at rest and use TLS for transfers, with key permissions, rotation, and monitoring.
Detailed explanation
Media leakage is reduced.
Media leakage is reduced.
Network interception is reduced.
Network interception is reduced.
The network is a separate risk.
The network is a separate risk.
A leaked key decrypts data.
A leaked key decrypts data.
Try it yourself
An example you can run in a temporary verification environment.
AWS公式AIF-C01 Domain 5.2の保存時暗号化、転送時暗号化、鍵管理を確認する。Expected result
保存と通信の両方の暗号化境界と鍵管理を説明できる。Key points
- At rest
- In transit
- Key management
Notes
- Environment: AWS公式AIF-C01試験ガイドとAWS公式ドキュメントの確認
- Command output formatting can vary slightly by distribution or tool version.
- Run the example in a temporary directory or process when possible.
Foundation review
Read the scope first
Check whether the command acts on the current shell, a new process, an existing process, or a file.
Verify the observable result
Use the supplied command and compare the output with the expected result.