Building a Real-Time Fraud Detection Pipeline with Kinesis and SageMaker
A data engineering team is building a real-time fraud detection system. Transactions are ingested via Amazon Kinesis Data Streams, and a machine learning model (deployed on Amazon SageMaker) scores each transaction. The team needs to store the raw transactions and the model's predictions in Amazon S3 for later analysis. Which architecture should the team use?
Quick Answer
The design challenge in this scenario is that invoking a SageMaker model for every transaction is inherently an extra processing step layered onto a streaming pipeline, and the architecture needs to handle that enrichment without blocking or losing the continuous flow of ingested data. Kinesis Data Analytics for Apache Flink is well suited to this because Flink is a stream-processing engine capable of making external calls, such as invoking a SageMaker endpoint per record, as part of its processing logic, enriching each transaction record with the model's fraud score while still operating within a continuous streaming application rather than a batch job. Once records have been enriched with predictions, routing them to Kinesis Data Firehose for delivery to S3 hands off the final storage step to a service purpose-built for reliable, buffered delivery, Firehose batches and compresses records before writing them, and provides automatic retry behavior, which is a more robust way to land data in S3 than writing directly from the stream-processing layer itself. This separation of concerns, Flink for real-time enrichment logic, Firehose for durable delivery, lets each service do what it's built for, rather than asking a single component to handle both model invocation and reliable S3 writes. Whenever a scenario needs a streaming pipeline to enrich each record with a model prediction and then durably store the results in S3, expect the correct architecture to pair a stream-processing engine capable of calling external services with Firehose for the final storage step, rather than combining both responsibilities into one component.
⚠ Common exam trap
Many exam-takers assume Lambda is the only serverless option for real-time enrichment, but the exam tests whether you understand that Kinesis Data Analytics for Apache Flink is the correct service for asynchronous, stateful enrichment before delivery to S3 via Firehose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Amazon Kinesis Data Analytics for Apache Flink to enrich records with SageMaker predictions, then output to Firehose for S3.
It uses Amazon Kinesis Data Analytics for Apache Flink to perform real-time enrichment by invoking the SageMaker endpoint for each transaction, then streams the enriched records to Kinesis Data Firehose for reliable, batched delivery to S3. This architecture handles the asynchronous nature of model inference without blocking the ingestion stream, and Firehose provides automatic retry and compression for S3 storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Lambda to read from Kinesis, invoke SageMaker, and write directly to S3.
Why it's wrong here
Lambda is not optimized for high-frequency real-time scoring; may cause throttling.
- ✗
Use Amazon Kinesis Data Firehose with a transformation Lambda to call SageMaker.
Why it's wrong here
Firehose transformation Lambda has a 5-minute timeout and limited concurrency, not ideal for real-time scoring.
- ✓
Use Amazon Kinesis Data Analytics for Apache Flink to enrich records with SageMaker predictions, then output to Firehose for S3.
Why this is correct
Flink can handle high-throughput, call SageMaker per record, and output to Firehose.
- ✗
Use AWS Lambda to invoke the SageMaker endpoint for each record, then write to S3 via Firehose.
Why it's wrong here
Lambda concurrency limits may throttle under high throughput.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLS-C01 question from scratch — 1,672 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MLS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A data science team is building a real-time fraud detection system. Transactions are streamed via Amazon Kinesis Data Streams, and a Lambda function performs feature engineering and invokes an Amazon SageMaker endpoint for predictions. The team notices that the Lambda function is timing out and causing data loss. Which solution should the team implement to process the stream reliably and at low latency?
medium- ✓ A.Use Amazon Kinesis Data Analytics for Apache Flink to consume the stream, perform feature engineering, and invoke the SageMaker endpoint with exactly-once processing.
- B.Use the Kinesis Client Library (KCL) to process the stream in an Amazon EC2 instance, and store the predictions in Amazon DynamoDB.
- C.Increase the Lambda function timeout to 15 minutes and allocate more memory to reduce processing time.
- D.Configure Amazon Kinesis Firehose to deliver the stream to an Amazon S3 bucket, then trigger a Lambda function to process the data in batches.
Why A: Amazon Kinesis Data Analytics for Apache Flink provides a stateful, low-latency stream processing engine that can consume from Kinesis Data Streams, perform feature engineering in real-time, and invoke SageMaker endpoints with exactly-once processing semantics. This eliminates Lambda timeouts and data loss by using a long-running, scalable application instead of a short-lived function.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLS-C01 exam.