MLS-C01 exam dumps

MLS-C01 practice question 336 of 389

AWS Certified Machine Learning - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLS-C01 Question 336

Select 4

You are designing an ML solution on AWS to handle sensitive customer data. The solution uses Amazon SageMaker for training and inference, stores training data in Amazon S3, and uses Amazon CloudWatch for logging. Which of the following steps should you take to ensure that the solution adheres to basic AWS security practices for protecting sensitive data?

  1. A

    Enable server-side encryption for the S3 bucket storing the training data.

  2. B

    Use IAM roles to grant least privilege access to SageMaker and S3 resources.

  3. C

    Enable public access for the S3 bucket to allow external auditors to review the data.

  4. D

    Use AWS Key Management Service (AWS KMS) to manage encryption keys for SageMaker.

  5. E

    Ensure logs in CloudWatch are encrypted and restrict access using IAM policies.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

When building an ML solution on AWS that handles sensitive data, it is crucial to follow basic AWS security practices such as encrypting data at rest (S3, CloudWatch), using AWS KMS for key management, enforcing least privilege access with IAM roles, and securing logs. These measures help protect sensitive information from unauthorized access and ensure compliance with security principles.

  • A. Correct.

    Correct - Enabling server-side encryption for the S3 bucket ensures that data at rest is encrypted, which is a basic AWS security practice for protecting sensitive information.

  • B. Correct.

    Correct - Using IAM roles to enforce least privilege access ensures that SageMaker and other AWS services access only the necessary resources, following AWS security best practices.

  • C. Incorrect.

    Incorrect - Enabling public access for the S3 bucket violates AWS security best practices by exposing sensitive data to unauthorized users.

  • D. Correct.

    Correct - Using AWS Key Management Service (KMS) for managing encryption keys ensures secure key management for SageMaker resources, adhering to security best practices.

  • E. Correct.

    Correct - Encrypting CloudWatch logs and restricting access using IAM policies ensures that sensitive logging information remains secure and is only accessible to authorized users.

Timed practice exam

Take a MLS-C01 practice test under exam conditions

65 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam