MLS-C01 exam dumps

MLS-C01 practice question 342 of 389

AWS Certified Machine Learning - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

MLS-C01 Question 342

Single answer

You are a Machine Learning engineer responsible for storing large datasets in an Amazon S3 bucket that is used by a SageMaker training job. The SageMaker service role requires access to the S3 bucket, but you also want to ensure that no external entities can read or write to the bucket. Which S3 bucket policy configuration should you implement?

  1. A

    Allow access to the bucket for the SageMaker service role and deny all other actions.

  2. B

    Allow public read access to the bucket while restricting write access to the SageMaker service role.

  3. C

    Allow access to the bucket for the SageMaker service role and allow public access for other IAM users in your AWS account.

  4. D

    Deny all actions on the bucket and use S3 Access Points to provide access to the SageMaker service role.

Show answer and explanation

Correct answer: A

Explanation

To meet the requirements, the bucket policy must grant access only to the specific SageMaker service role while denying all other actions. This approach ensures that the bucket can be used securely by SageMaker while preventing unauthorized access.

  • A. Correct.

    This is the correct option. By allowing access for the SageMaker service role and denying all other actions, you ensure that only the SageMaker job can access the bucket while blocking any external or unauthorized access.

  • B. Incorrect.

    This is incorrect because public read access would expose the data to external entities, violating the security requirement to restrict access to the bucket.

  • C. Incorrect.

    This is incorrect because allowing public access for other IAM users in your account does not meet the requirement of restricting access only to the SageMaker service role. It opens access to potentially unauthorized users.

  • D. Incorrect.

    This is incorrect because denying all actions would prevent even the SageMaker service role from accessing the bucket. S3 Access Points are an advanced feature but are unnecessary for this scenario.

Timed practice exam

Take a MLS-C01 practice test under exam conditions

65 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam