Courseiva
mediumMultiple Choice

AIF-C01 Practice Question: A data science team is using Amazon SageMaker…

A data science team is using Amazon SageMaker Studio. To meet compliance requirements, they need to ensure that all user activity in the environment is logged and that any unauthorized access attempts are detected. Which approach should they take?

⚠ Common exam trap

A common mix-up: candidates confuse logging (CloudTrail) with threat detection (GuardDuty) and assume that enabling CloudTrail alone satisfies both requirements, but GuardDuty is specifically needed to analyze logs for unauthorized access attempts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable AWS CloudTrail and Amazon GuardDuty for threat detection.

AWS CloudTrail logs all API activity in SageMaker Studio, including user actions and access attempts, while Amazon GuardDuty provides intelligent threat detection by analyzing CloudTrail logs, VPC flow logs, and DNS logs for unauthorized access patterns. Together, they meet compliance requirements for logging and detecting unauthorized access without additional configuration overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SageMaker Model Monitor and configure Amazon S3 server access logs.

    Why it's wrong here

    Model Monitor tracks data and model drift on deployed endpoints, and S3 server access logs record bucket requests, neither capturing Studio user activity or access attempts. It is tempting because both produce logs, and would be correct for monitoring inference quality and object-level storage access respectively.

  • ✓

    Enable AWS CloudTrail and Amazon GuardDuty for threat detection.

    Why this is correct

    CloudTrail records all API activity across SageMaker Studio, providing the audit trail compliance requires, while GuardDuty continuously analyses logs and behaviour to detect unauthorised access attempts. Together they satisfy both the logging and threat-detection requirements.

  • ✗

    Use AWS Config rules to track changes and Amazon Inspector for vulnerability scanning.

    Why it's wrong here

    AWS Config records resource configuration changes and Inspector scans workloads for vulnerabilities; neither logs interactive Studio user activity nor detects unauthorised access attempts. It is tempting because both support compliance auditing, and would be correct for tracking configuration drift and identifying software vulnerabilities.

  • ✗

    Enable SageMaker Studio with VPC only mode and use AWS CloudTrail.

    Why it's wrong here

    VPC-only mode blocks internet access but does not itself log user activity or detect unauthorised access attempts; CloudTrail records API calls, not in-Studio notebook actions. It is tempting because it hardens network isolation, and would be correct when the requirement is preventing direct internet exposure of Studio.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.