MLA-C01 exam dumps

MLA-C01 practice question 443 of 458

AWS Certified Machine Learning Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLA-C01 Question 443

Select 3

An organization has deployed a machine learning model using Amazon SageMaker to process sensitive customer data. As a Machine Learning Engineer, you are tasked with ensuring the security and compliance of the SageMaker environment. Which actions should you take to meet these requirements?

  1. A

    Enable Amazon SageMaker VPC endpoints to ensure all communication stays within the AWS network.

  2. B

    Use SageMaker-provided encryption keys for data at rest to simplify key management.

  3. C

    Configure AWS Identity and Access Management (IAM) policies to restrict SageMaker users to specific actions and resources.

  4. D

    Enable Amazon SageMaker Model Monitoring to detect and alert on data drift in the model's predictions.

  5. E

    Use AWS Key Management Service (KMS) to encrypt data at rest in SageMaker.

Show answer and explanation

Correct answers: A, C, E

Explanation

When working with sensitive customer data in SageMaker, it is essential to implement security measures such as using VPC endpoints to isolate traffic, configuring IAM policies to enforce least privilege, and encrypting data at rest with AWS KMS for compliance. These steps collectively ensure a secure and compliant SageMaker environment.

  • A. Correct.

    Enabling Amazon SageMaker VPC endpoints ensures that SageMaker traffic remains within the AWS private network, improving security by avoiding exposure to the public internet.

  • B. Incorrect.

    Using SageMaker-provided encryption keys is not recommended for sensitive customer data since it does not provide the same level of control and compliance as customer-managed keys in AWS KMS.

  • C. Correct.

    Configuring IAM policies helps enforce the principle of least privilege, ensuring that only authorized users can perform specific actions in SageMaker, which is critical for security and compliance.

  • D. Incorrect.

    Enabling SageMaker Model Monitoring is useful for detecting issues like data drift but does not directly address security or compliance requirements.

  • E. Correct.

    Using AWS KMS to encrypt data at rest in SageMaker ensures that sensitive data is protected with customer-controlled encryption keys, meeting compliance and security requirements.

Timed practice exam

Take a MLA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam