hardMultiple Choice
MLA-C01 Practice Question: A company deploys a SageMaker model using AWS KMS…
A company deploys a SageMaker model using AWS KMS for encryption at rest. They have a compliance requirement to rotate the KMS key every year without causing downtime for the inference endpoint. Which approach should they take?
⚠ Common exam trap
Watch out — candidates often think rotating a KMS key requires creating a new key and updating the resource (Option B), or that manual recreation is necessary (Option C), when in fact AWS KMS automatic key rotation handles the rotation seamlessly without any endpoint modification or downtime.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation on the existing KMS key
AWS KMS supports automatic key rotation, which creates new backing keys annually while retaining the same key ID and metadata. This ensures that the SageMaker endpoint continues to use the same KMS key alias and configuration, so no endpoint update or downtime is required. Automatic rotation satisfies the compliance requirement without any manual intervention or endpoint recreation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Certificate Manager (ACM) for encryption
Why it's wrong here
ACM issues and rotates TLS certificates for in-transit encryption; it does not manage KMS keys or encryption at rest. It is tempting because ACM also handles rotation, but the requirement concerns the KMS key protecting the model, which ACM cannot rotate.
- ✗
Create a new KMS key and update the endpoint configuration
Why it's wrong here
Creating a new key and updating the endpoint configuration requires re-encrypting data and redeploying, causing the downtime the requirement forbids. It is tempting because new keys are a valid rotation method, but automatic rotation keeps the same key ARN, so endpoints continue uninterrupted.
- ✗
Manually rotate the key by recreating the endpoint
Why it's wrong here
Recreating the endpoint forces a full redeploy, so inference traffic is interrupted during the rebuild — directly violating the no-downtime requirement. Manual rotation is tempting because AWS KMS supports customer-managed key rotation, but that approach suits workloads where a brief endpoint outage is acceptable.
- ✓
Enable automatic key rotation on the existing KMS key
Why this is correct
Automatic key rotation generates new backing key material under the same KMS key ID, so existing ciphertext and the endpoint's references remain valid. This satisfies the annual rotation requirement without re-encrypting data or redeploying, avoiding inference downtime.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.