Courseiva
easyMultiple Choice

MLA-C01 Practice Question: Using Amazon SageMaker to train a model on…

A company is using Amazon SageMaker to train a model on sensitive customer data. The security team requires that all data be encrypted in transit and at rest, and that the training job does not have internet access. Which configuration should the team use to meet these requirements?

⚠ Common exam trap

Many candidates confuse a private subnet with a NAT gateway as providing no internet access, but a NAT gateway actually enables outbound internet connectivity, which violates the requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the training job to run in a private subnet with no internet access, and use a KMS key for encryption

Running the SageMaker training job in a private subnet with no internet access ensures the job cannot reach the public internet, satisfying the no-internet-access requirement. Using an AWS KMS key for encryption at rest (for the S3 bucket and EBS volumes) and enforcing encryption in transit (via HTTPS/TLS for SageMaker and S3 endpoints) meets the encryption requirements. SageMaker training jobs in a private subnet use VPC endpoints (e.g., S3 and SageMaker API endpoints) to communicate securely without internet access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the training job to run in a public subnet with a security group that blocks outbound traffic

    Why it's wrong here

    A public subnet with a blocking security group still places the job on a route to the internet, so it fails the no-internet requirement and relies on security groups rather than network isolation. It is tempting because security groups do restrict traffic, and would suit jobs needing controlled outbound access.

  • ✗

    Configure the training job to run in a private subnet, but disable encryption to reduce latency

    Why it's wrong here

    Disabling encryption breaches both the at-rest and in-transit requirements outright, regardless of subnet placement. A private subnet alone satisfies only the no-internet condition; encryption must still be configured with KMS keys. This option suits latency-sensitive, non-sensitive workloads where compliance rules permit unencrypted data.

  • ✓

    Configure the training job to run in a private subnet with no internet access, and use a KMS key for encryption

    Why this is correct

    Isolating the training job in a private subnet removes the internet route entirely, satisfying the no-internet-access constraint, while a KMS key encrypts the training data and volumes at rest. Together they meet both the in-transit and at-rest encryption requirements.

  • ✗

    Configure the training job to run in a VPC with a NAT gateway, and use default SageMaker encryption

    Why it's wrong here

    A NAT gateway provides outbound internet access, directly violating the no-internet requirement; default SageMaker encryption also leaves inter-node traffic and volumes unencrypted unless KMS keys are specified. NAT gateways suit private subnets needing patching or package downloads, not isolated training.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.