hardMultiple Select
MLA-C01 Practice Question: A company operates multiple AWS accounts with…
A company operates multiple AWS accounts with SageMaker workloads. They need to implement governance and security controls for model monitoring and maintenance. Which THREE actions should they take to meet compliance requirements?
⚠ Common exam trap
Many candidates confuse VPC Flow Logs (network-level logging) with CloudTrail (API-level logging) or assume that cross-account IAM roles are a governance control rather than an access mechanism, leading them to select options that do not directly address compliance requirements for model monitoring and maintenance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a SageMaker model registry in a centralized account.
Option A is correct because a SageMaker Model Registry deployed in a centralized account provides a single governance point for cataloging, versioning, and approving models across multiple AWS accounts, which is essential for compliance and maintenance oversight. Option B is correct because AWS CloudTrail records all API activity, including calls to SageMaker and S3, giving the audit trail required to demonstrate who accessed or modified models and data. Option E is correct because AWS Config rules can continuously evaluate model artifacts in S3 for required encryption settings and flag or remediate noncompliant resources, directly enforcing a compliance control. Option C is not required because VPC Flow Logs capture network traffic metadata for notebooks, which is useful for network troubleshooting but does not address model monitoring or maintenance governance. Option D is not required because cross-account IAM trust policies for endpoints are an access mechanism, not a governance or compliance control, and the question asks for monitoring and maintenance actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a SageMaker model registry in a centralized account.
Why this is correct
A centralised SageMaker Model Registry in a dedicated account provides a single authoritative catalogue of model versions, approval statuses and metadata across all accounts. This satisfies the governance constraint by enabling consistent approval workflows and audit trails, while cross-account registry access lets teams publish and consume models without duplicating registries per account.
- ✓
Use AWS CloudTrail to log all API calls to SageMaker and S3.
Why this is correct
AWS CloudTrail records every SageMaker and S3 API call across all accounts, delivering the audit trail that compliance governance demands. This satisfies the requirement for centralised, immutable logging of model monitoring and maintenance activity, since CloudTrail captures management and data events needed to evidence who accessed or altered workloads.
- ✗
Enable VPC Flow Logs for SageMaker notebooks.
Why it's wrong here
VPC Flow Logs capture network traffic metadata, not model behaviour, drift or endpoint health, so they cannot satisfy model monitoring controls. It is tempting because flow logs are a standard governance control, and they would be correct if the requirement were network-level audit of SageMaker traffic.
- ✗
Use IAM roles with cross-account trust policies for all SageMaker endpoints.
Why it's wrong here
Cross-account trust policies grant access between accounts; they do not monitor models or enforce maintenance controls. It is tempting because IAM roles are central to multi-account governance, and they would be correct if the requirement were secure cross-account invocation of endpoints rather than monitoring.
- ✓
Use AWS Config rules to enforce encryption of model artifacts.
Why this is correct
AWS Config rules continuously evaluate resource configurations against compliance policies, detecting unencrypted model artefacts stored in S3 and flagging drift across accounts. This directly satisfies the governance requirement by enforcing encryption at rest for model artefacts, providing the auditable, automated control evidence that multi-account SageMaker compliance demands.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.