AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions
A data scientist needs to restrict access to a SageMaker notebook instance to only the corporate network. Which configuration should they use?
⚠ Common exam trap
The trap is confusing authentication (IAM, MFA) with network-level restrictions. Candidates must remember that to restrict by network, you need VPC and security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the notebook instance in a VPC and configure security groups to allow only corporate IP ranges
To restrict access to a SageMaker notebook instance to only the corporate network, the best approach is to place the notebook instance in a VPC and configure security groups to allow inbound traffic only from corporate IP ranges. This network-level control ensures that only traffic from specified IPs can reach the notebook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable multi-factor authentication for the notebook
Why it's wrong here
Multi-factor authentication strengthens identity verification but does not restrict network origin, so traffic from any IP still reaches the notebook once credentials pass. It is tempting because MFA is a genuine access control, yet the requirement is network-level restriction, which a VPC endpoint or network isolation setting enforces.
- ✗
Use an IAM policy to allow only corporate users
Why it's wrong here
An IAM policy governs which principals may call AWS APIs; it does not filter by source network, so a corporate user connecting from home still succeeds. It is tempting because IAM is the standard authorisation mechanism, but restricting to the corporate network requires a VPC configuration or an IP condition on the notebook's access settings.
- ✓
Place the notebook instance in a VPC and configure security groups to allow only corporate IP ranges
Why this is correct
Placing the notebook in a VPC lets security groups act as stateful IP filters, permitting only the corporate CIDR ranges. Direct internet access is removed, so the network-origin constraint is enforced at the elastic network interface.
- ✗
Use a SageMaker lifecycle configuration to block external IPs
Why it's wrong here
Lifecycle configurations run shell scripts at notebook start or creation; they cannot intercept inbound network connections, so external IPs are never actually blocked. It is tempting because scripts feel powerful, but network restriction belongs to VPC placement or the notebook's direct internet access setting, not to startup scripting.
Go deeper
Related to this question
About these practice questions
This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.