Courseiva
hardMultiple Select

MLA-C01 Practice Question: Secure a SageMaker notebook instance that…

A company needs to secure a SageMaker notebook instance that contains sensitive data. Which THREE of the following are effective security measures? (Select THREE.)

⚠ Common exam trap

A common trap is to consider AWS CloudTrail as an effective security measure for protecting the notebook instance itself. While CloudTrail provides an audit trail, it does not prevent unauthorized access or data leakage. Direct security controls like IAM, VPC configuration, and encryption are more effective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM policies to restrict who can access the notebook instance.

Option A is correct because IAM policies are the primary mechanism for controlling authentication and authorization to SageMaker notebook instances, allowing you to restrict which principals can create, access, or manage the instance via fine-grained permissions. Option B is correct because disabling direct internet access forces all outbound traffic through your VPC, and a NAT gateway provides controlled, monitored egress while preventing the notebook from being directly reachable from the internet. Option E is correct because encrypting the notebook instance's EBS volume with AWS KMS protects data at rest, ensuring that sensitive data stored on the volume is unreadable if the underlying storage is compromised. Option C is not a security measure because downloading data from a public S3 bucket introduces unnecessary exposure and does not secure the notebook. Option D, while useful for auditing, is a detective control rather than a preventive security measure and does not by itself secure the sensitive data on the instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use IAM policies to restrict who can access the notebook instance.

    Why this is correct

    IAM policies define which principals may invoke SageMaker notebook instance actions such as CreatePresignedNotebookInstanceUrl, directly restricting access to the sensitive data. This enforces least privilege at the identity layer, satisfying the requirement to secure the notebook.

  • ✓

    Disable direct internet access and use a VPC with a NAT gateway for outbound.

    Why this is correct

    Disabling direct internet access forces notebook traffic through the VPC, and a NAT gateway permits only outbound access, blocking inbound exposure from the internet. This satisfies the requirement to secure a notebook holding sensitive data by removing its public network path.

  • ✗

    Attach a lifecycle configuration that runs a script to download data from a public S3 bucket.

    Why it's wrong here

    Downloading data from a public S3 bucket introduces untrusted external content and broadens exposure, directly undermining the notebook's security posture. It is tempting because lifecycle configurations legitimately automate notebook setup tasks, but they are the right choice for installing approved packages or configuring settings from controlled, private sources.

  • ✗

    Enable AWS CloudTrail to log all notebook API calls.

    Why it's wrong here

    CloudTrail records API activity for auditing and detection; it does not restrict access to the notebook, encrypt its data, or isolate its network, so it cannot by itself secure sensitive content. It is tempting because logging is a genuine security control, and it would be correct when the requirement is audit visibility or compliance evidence.

  • ✓

    Encrypt the notebook instance's EBS volume using AWS KMS.

    Why this is correct

    AWS KMS encryption on the notebook instance's EBS volume protects data at rest, so sensitive contents remain unreadable if the underlying storage is compromised. This satisfies the requirement to secure a notebook containing sensitive data, complementing network controls that address data in transit.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.