AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A company needs to ensure that model inference endpoints in SageMaker are only accessible from a private subnet in their VPC, and no traffic goes over the public internet. Which network configuration should they use?
⚠ Common exam trap
AIF-C01 often tests the misconception that IAM policies or security groups alone can make an endpoint private — candidates must remember that network isolation requires PrivateLink/VPC endpoints, not just authorization controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a VPC interface endpoint for SageMaker and disable public access
To keep SageMaker inference traffic entirely off the public internet, you create a VPC interface endpoint (powered by AWS PrivateLink) for the SageMaker API and runtime, then disable the public endpoint so the service is reachable only from within the VPC. This forces all inference calls to traverse the private endpoint ENI in the subnet, never leaving the AWS network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a public endpoint and restrict access using IAM policies
Why it's wrong here
IAM policies authorise API calls but do not remove the endpoint's public internet path, so traffic still traverses the public network. It is tempting because IAM is the standard access-control mechanism, and would be correct if the requirement were only to restrict which principals may invoke the endpoint.
- ✗
Use AWS PrivateLink for the endpoint, but keep public endpoint enabled
Why it's wrong here
Leaving the public endpoint enabled preserves an internet-reachable path, violating the no-public-internet requirement. It is tempting because PrivateLink genuinely provides private connectivity, and would be correct if only the private subnet needed access while other consumers still used the public endpoint.
- ✓
Use a VPC interface endpoint for SageMaker and disable public access
Why this is correct
A VPC interface endpoint (AWS PrivateLink) provisions an elastic network interface with a private IP inside the subnet, letting inference calls reach SageMaker without traversing the public internet. Disabling public access enforces the stem's constraint that endpoints remain reachable only from the private subnet, satisfying the no-internet requirement.
- ✗
Deploy the endpoint in a public subnet with a security group blocking all inbound traffic
Why it's wrong here
A public subnet still routes through an internet gateway, and a security group denying inbound traffic blocks the private subnet's own requests. It is tempting because security groups do restrict access, and would be correct if the endpoint needed public reachability limited to specific source addresses.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.