easyMultiple Choice
MLA-C01 Practice Question: Using Amazon SageMaker to train a model on…
A company is using Amazon SageMaker to train a model on sensitive customer data. The security team requires that all data be encrypted in transit and at rest, and that the training job does not have internet access. Which configuration should the team use to meet these requirements?
⚠ Common exam trap
Many candidates confuse a private subnet with a NAT gateway as providing no internet access, but a NAT gateway actually enables outbound internet connectivity, which violates the requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the training job to run in a private subnet with no internet access, and use a KMS key for encryption
Running the SageMaker training job in a private subnet with no internet access ensures the job cannot reach the public internet, satisfying the no-internet-access requirement. Using an AWS KMS key for encryption at rest (for the S3 bucket and EBS volumes) and enforcing encryption in transit (via HTTPS/TLS for SageMaker and S3 endpoints) meets the encryption requirements. SageMaker training jobs in a private subnet use VPC endpoints (e.g., S3 and SageMaker API endpoints) to communicate securely without internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the training job to run in a public subnet with a security group that blocks outbound traffic
Why it's wrong here
A public subnet with a blocking security group still places the job on a route to the internet, so it fails the no-internet requirement and relies on security groups rather than network isolation. It is tempting because security groups do restrict traffic, and would suit jobs needing controlled outbound access.
- ✗
Configure the training job to run in a private subnet, but disable encryption to reduce latency
Why it's wrong here
Disabling encryption breaches both the at-rest and in-transit requirements outright, regardless of subnet placement. A private subnet alone satisfies only the no-internet condition; encryption must still be configured with KMS keys. This option suits latency-sensitive, non-sensitive workloads where compliance rules permit unencrypted data.
- ✓
Configure the training job to run in a private subnet with no internet access, and use a KMS key for encryption
Why this is correct
Isolating the training job in a private subnet removes the internet route entirely, satisfying the no-internet-access constraint, while a KMS key encrypts the training data and volumes at rest. Together they meet both the in-transit and at-rest encryption requirements.
- ✗
Configure the training job to run in a VPC with a NAT gateway, and use default SageMaker encryption
Why it's wrong here
A NAT gateway provides outbound internet access, directly violating the no-internet requirement; default SageMaker encryption also leaves inter-node traffic and volumes unencrypted unless KMS keys are specified. NAT gateways suit private subnets needing patching or package downloads, not isolated training.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.