Courseiva
easyMultiple Select

MLA-C01 Practice Question: Using Amazon SageMaker to deploy a model for…

A company is using Amazon SageMaker to deploy a model for real-time inference. The model requires access to a private S3 bucket that contains reference data. The company wants to ensure that the endpoint can access the S3 bucket without using a public internet connection. Which TWO actions should they take? (Select TWO.)

⚠ Common exam trap

It's easy for candidates to confuse VPC endpoints (which keep traffic private) with NAT gateways or internet gateways (which route traffic over the public internet), and they may overlook the mandatory IAM permissions required for S3 access even when using a VPC endpoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach the endpoint to a VPC that has a VPC endpoint for S3.

Option B is correct because attaching the SageMaker endpoint to a VPC that has an S3 gateway VPC endpoint (or interface endpoint) allows traffic to reach the private S3 bucket through the AWS private network instead of the public internet, satisfying the no-public-internet requirement. Option C is correct because the SageMaker execution role must have an IAM policy granting s3:GetObject on the bucket, otherwise the endpoint cannot read the reference data regardless of network path. Option A is not correct because security groups cannot whitelist an S3 bucket's IP range reliably (S3 uses dynamic AWS IP ranges and gateway endpoints don't use those IPs), and network access alone doesn't grant authorization. Option D is not correct because routing S3 traffic through an internet gateway uses the public internet, violating the requirement. Option E is not correct because a NAT gateway also routes traffic over the public internet, so it does not meet the private-access requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the endpoint's security group to allow outbound traffic to the S3 bucket's IP range.

    Why it's wrong here

    Security groups filter traffic by protocol and port, not by destination IP range for AWS service endpoints, and S3 has no fixed public range to permit. It tempts those treating S3 as an external host. A VPC endpoint is required so traffic reaches S3 privately without internet routing.

  • ✓

    Attach the endpoint to a VPC that has a VPC endpoint for S3.

    Why this is correct

    A VPC endpoint for S3 (gateway endpoint) routes traffic from the endpoint's subnets to S3 over the AWS private network, keeping requests off the public internet. This satisfies the stem's constraint of private bucket access without public connectivity, since the endpoint must reside in a VPC to use it.

  • ✓

    Ensure the SageMaker execution role has an IAM policy that grants s3:GetObject access to the bucket.

    Why this is correct

    The execution role's identity-based policy must grant s3:GetObject on the reference bucket, otherwise every request is denied regardless of network path. This satisfies the stem's access requirement: private connectivity alone does not authorise reads, so the role needs explicit permission to fetch the reference data.

  • ✗

    Attach the endpoint to a VPC with an internet gateway and route the S3 traffic through the internet gateway.

    Why it's wrong here

    An internet gateway routes traffic over the public internet, directly contradicting the no-public-internet requirement. It tempts candidates who assume any VPC attachment suffices for connectivity. A VPC endpoint is needed to reach S3 privately, without traversing the internet gateway.

  • ✗

    Attach the endpoint to a VPC with a NAT gateway to route traffic to S3.

    Why it's wrong here

    A NAT gateway still routes traffic through the public internet, so the private-connection requirement fails. It tempts candidates seeking outbound access for private subnets generally. The correct mechanism is a VPC endpoint, which keeps S3 traffic on the AWS network entirely.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.