MLA-C01 exam dumps

MLA-C01 practice question 428 of 458

AWS Certified Machine Learning Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLA-C01 Question 428

Select 3

You are deploying a machine learning model on AWS SageMaker and need to ensure that the data used for training and inference is encrypted at rest and in transit. Which combination of actions should you take to secure your AWS resources?

  1. A

    Enable Amazon S3 default encryption for the bucket storing training data and specify an AWS Key Management Service (KMS) key.

  2. B

    Use a SageMaker endpoint configured with HTTPS to ensure encryption in transit.

  3. C

    Attach an IAM policy to the SageMaker role to allow unrestricted access to all S3 buckets in the account.

  4. D

    Enable VPC-only access for SageMaker to prevent public internet access to the model endpoint.

  5. E

    Disable AWS CloudTrail logging to reduce overhead and ensure faster model deployment.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure AWS resources when deploying a machine learning model, it's essential to encrypt data at rest (e.g., using S3 default encryption with a KMS key) and in transit (e.g., using HTTPS). Additionally, restricting SageMaker endpoint access to a VPC prevents exposure to the public internet. Adhering to the principle of least privilege and enabling monitoring via CloudTrail are also critical for maintaining a secure environment.

  • A. Correct.

    Correct. Enabling Amazon S3 default encryption ensures that data at rest in the S3 bucket is encrypted, which complies with security best practices.

  • B. Correct.

    Correct. Configuring the SageMaker endpoint with HTTPS ensures secure communication and encryption of data in transit.

  • C. Incorrect.

    Incorrect. Granting unrestricted access to all S3 buckets violates the principle of least privilege and poses a security risk.

  • D. Correct.

    Correct. Enabling VPC-only access for SageMaker restricts network access, ensuring the endpoint is not exposed to the public internet.

  • E. Incorrect.

    Incorrect. Disabling CloudTrail logging is not a security best practice. CloudTrail helps monitor and log API activity, which is crucial for auditing and troubleshooting.

Timed practice exam

Take a MLA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam