MLA-C01 exam dumps

MLA-C01 practice question 431 of 458

AWS Certified Machine Learning Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLA-C01 Question 431

Select 2

You are deploying a machine learning (ML) model on Amazon SageMaker and need to ensure that the inference endpoint is secure. The model processes sensitive customer data, so it is critical to enforce encryption in transit and restrict network access. Which actions should you take to secure the endpoint?

  1. A

    Enable Amazon SageMaker endpoint encryption using an AWS Key Management Service (KMS) key.

  2. B

    Configure the endpoint to only accept requests over HTTPS.

  3. C

    Attach a security group to the endpoint that allows unrestricted inbound traffic.

  4. D

    Use an AWS Identity and Access Management (IAM) policy to restrict access to the endpoint to specific IAM roles.

  5. E

    Disable logging for the endpoint to prevent sensitive data from being recorded.

Show answer and explanation

Correct answers: B, D

Explanation

To secure an Amazon SageMaker endpoint that processes sensitive data, encryption in transit must be enforced by configuring the endpoint to accept only HTTPS traffic. Additionally, access should be restricted using IAM policies to ensure that only authorized entities can use the endpoint. These measures protect data confidentiality and meet security requirements.

  • A. Incorrect.

    Amazon SageMaker endpoint encryption using AWS KMS is for encrypting data at rest, not in transit. While securing data at rest is important, it does not address encryption in transit, which is a requirement here.

  • B. Correct.

    Configuring the endpoint to accept only HTTPS ensures that data transmitted to and from the endpoint is encrypted in transit, meeting the security requirement.

  • C. Incorrect.

    Allowing unrestricted inbound traffic to the endpoint exposes it to potential unauthorized access. Instead, traffic should be restricted to trusted sources.

  • D. Correct.

    Using an IAM policy to restrict access to specific IAM roles ensures that only authorized users or services can access the endpoint, enhancing its security.

  • E. Incorrect.

    Disabling logging does not improve security; instead, it reduces visibility into the endpoint's operations and security events, which is not recommended.

Timed practice exam

Take a MLA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam