MLA-C01 exam dumps

MLA-C01 practice question 101 of 458

AWS Certified Machine Learning Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLA-C01 Question 101

Select 3

You are designing a machine learning pipeline to process sensitive financial data on AWS. To ensure compliance with data protection regulations, you need to encrypt the data at rest. Which of the following approaches could you use to securely encrypt the data stored in Amazon S3?

  1. A

    Use Amazon S3 Server-Side Encryption with AWS Key Management Service (SSE-KMS).

  2. B

    Manually encrypt the data before uploading it to Amazon S3 using a client-side library like AWS SDK.

  3. C

    Store the data in an unencrypted Amazon S3 bucket but restrict access using IAM policies.

  4. D

    Enable Amazon S3 Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3).

  5. E

    Use AWS Secrets Manager to encrypt the data directly in Amazon S3.

Show answer and explanation

Correct answers: A, B, D

Explanation

To encrypt data at rest in Amazon S3, you can use either server-side encryption methods provided by AWS (SSE-KMS or SSE-S3) or implement client-side encryption before uploading the data. Both approaches ensure data is encrypted while stored in S3. IAM policies and AWS Secrets Manager, while useful for other aspects of security, do not directly meet the requirement of encrypting data at rest.

  • A. Correct.

    Correct: SSE-KMS provides server-side encryption with keys managed by AWS Key Management Service, ensuring strong encryption and regulatory compliance.

  • B. Correct.

    Correct: Client-side encryption allows you to encrypt data before uploading it to Amazon S3, giving you complete control over the encryption process.

  • C. Incorrect.

    Incorrect: While restricting access using IAM policies is important for security, it does not encrypt the data at rest, which is a separate requirement.

  • D. Correct.

    Correct: SSE-S3 provides server-side encryption managed by Amazon S3, which is a simple way to encrypt data at rest.

  • E. Incorrect.

    Incorrect: AWS Secrets Manager is used for securely storing and managing secrets, such as API keys and passwords. It is not used to encrypt data directly in Amazon S3.

Timed practice exam

Take a MLA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam