MLS-C01 exam dumps

MLS-C01 practice question 341 of 389

AWS Certified Machine Learning - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLS-C01 Question 341

Single answer

You are working as a Machine Learning Engineer for a company that processes large amounts of training data stored in an Amazon S3 bucket. The data must be accessed by Amazon SageMaker for training jobs. To comply with security requirements, you are tasked with ensuring that only the SageMaker service has access to the data in the S3 bucket. Which S3 bucket policy configuration should you use?

  1. A

    Grant public read access to the S3 bucket so SageMaker can access the data.

  2. B

    Use an S3 bucket policy that allows access to the bucket only from the SageMaker service principal.

  3. C

    Attach an IAM policy to the SageMaker execution role to allow access to the S3 bucket.

  4. D

    Add the S3 bucket to the SageMaker notebook's security group.

Show answer and explanation

Correct answer: B

Explanation

To ensure only Amazon SageMaker can access the S3 bucket, you must configure an S3 bucket policy that allows access exclusively to the SageMaker service principal. This approach directly enforces resource-level security and satisfies the compliance requirements. Other methods like public access, IAM policies, or security groups do not provide the necessary level of restriction or violate best practices.

  • A. Incorrect.

    This option is incorrect because granting public read access would expose the bucket to everyone, violating security requirements and best practices.

  • B. Correct.

    This option is correct because using an S3 bucket policy that specifically allows access to the SageMaker service principal ensures that only SageMaker can access the bucket, meeting security compliance requirements.

  • C. Incorrect.

    This option is incorrect because IAM policies control what the SageMaker execution role can do, but it doesn't restrict bucket access only to SageMaker. A bucket policy is needed for this level of restriction.

  • D. Incorrect.

    This option is incorrect because security groups operate at the network level and cannot directly control access to an S3 bucket.

Timed practice exam

Take a MLS-C01 practice test under exam conditions

65 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam