Courseiva

AIF-C01 Practice Question: Security, Compliance, and Governance for AI Solutions

A data scientist needs to restrict access to a SageMaker notebook instance to only the corporate network. Which configuration should they use?

⚠ Common exam trap

The trap is confusing authentication (IAM, MFA) with network-level restrictions. Candidates must remember that to restrict by network, you need VPC and security groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place the notebook instance in a VPC and configure security groups to allow only corporate IP ranges

To restrict access to a SageMaker notebook instance to only the corporate network, the best approach is to place the notebook instance in a VPC and configure security groups to allow inbound traffic only from corporate IP ranges. This network-level control ensures that only traffic from specified IPs can reach the notebook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable multi-factor authentication for the notebook

    Why it's wrong here

    Multi-factor authentication strengthens identity verification but does not restrict network origin, so traffic from any IP still reaches the notebook once credentials pass. It is tempting because MFA is a genuine access control, yet the requirement is network-level restriction, which a VPC endpoint or network isolation setting enforces.

  • ✗

    Use an IAM policy to allow only corporate users

    Why it's wrong here

    An IAM policy governs which principals may call AWS APIs; it does not filter by source network, so a corporate user connecting from home still succeeds. It is tempting because IAM is the standard authorisation mechanism, but restricting to the corporate network requires a VPC configuration or an IP condition on the notebook's access settings.

  • ✓

    Place the notebook instance in a VPC and configure security groups to allow only corporate IP ranges

    Why this is correct

    Placing the notebook in a VPC lets security groups act as stateful IP filters, permitting only the corporate CIDR ranges. Direct internet access is removed, so the network-origin constraint is enforced at the elastic network interface.

  • ✗

    Use a SageMaker lifecycle configuration to block external IPs

    Why it's wrong here

    Lifecycle configurations run shell scripts at notebook start or creation; they cannot intercept inbound network connections, so external IPs are never actually blocked. It is tempting because scripts feel powerful, but network restriction belongs to VPC placement or the notebook's direct internet access setting, not to startup scripting.

About these practice questions

This AIF-C01 question is part of Courseiva's 862-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.