mediumMultiple Choice
AIF-C01 Practice Question: Ensure that only approved machine learning models…
A company wants to ensure that only approved machine learning models are deployed to production on Amazon SageMaker. Which combination of services can enforce this governance requirement?
⚠ Common exam trap
A common mix-up: candidates confuse monitoring/auditing services (like CloudTrail and CloudWatch) with enforcement mechanisms, failing to recognize that only AWS Config rules combined with IAM policies can actively prevent or flag non-compliant deployments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config custom rules and AWS IAM policies
AWS Config custom rules can evaluate SageMaker model deployment configurations against defined policies (e.g., requiring models to be from an approved registry), and AWS IAM policies can restrict who can create or update endpoints, together enforcing that only approved ML models are deployed. This combination provides both continuous compliance checking and access control, directly addressing the governance requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CodePipeline and Amazon CodeGuru
Why it's wrong here
CodeGuru reviews code quality and CodePipeline orchestrates builds; neither validates a registered model's approval status in SageMaker Model Registry. They fit CI/CD for application code, not model governance. Approval gating requires the registry's model package approval condition.
- ✗
Amazon CloudWatch Events and AWS CloudTrail
Why it's wrong here
CloudWatch Events and CloudTrail record and react to API activity after deployment; they cannot gate a SageMaker model registry approval before production. They suit auditing and alerting on deployed resources. Enforcement needs model registry approval status checked in a deployment pipeline.
- ✗
AWS Organizations and AWS Artifact
Why it's wrong here
AWS Organizations manages accounts and Artifact supplies compliance reports; neither inspects SageMaker model approval state. They suit multi-account governance and audit evidence collection. Blocking unapproved deployments requires Model Registry approval status enforced in the deployment workflow.
- ✓
AWS Config custom rules and AWS IAM policies
Why this is correct
AWS Config custom rules continuously evaluate SageMaker model deployments against approved-model criteria, flagging non-compliant resources, while IAM policies restrict which principals can invoke deployment APIs. Together they enforce the governance constraint that only approved models reach production.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.