easyMultiple Choice
MLA-C01 Practice Question: A company uses an Amazon SageMaker endpoint for…
A company uses an Amazon SageMaker endpoint for real-time inference. The security team requires that all traffic between the endpoint and the client application be encrypted in transit. Which configuration ensures this?
⚠ Common exam trap
The trap here is that candidates often overthink security requirements and assume additional configuration (like VPC endpoints or ACM certificates) is needed, when in fact SageMaker endpoints are inherently encrypted in transit via HTTPS by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The endpoint is automatically served over HTTPS; no additional configuration is needed.
Amazon SageMaker endpoints are automatically served over HTTPS, which encrypts all data in transit between the client application and the endpoint. This is a default behavior of SageMaker real-time inference endpoints, so no additional configuration is required to meet the encryption-in-transit requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the endpoint in a VPC and use VPC Endpoints.
Why it's wrong here
VPC endpoints (PrivateLink) keep traffic within the AWS network but do not themselves enforce TLS encryption between client and endpoint; the endpoint's HTTPS interface does that. PrivateLink is tempting because it removes public internet exposure, and it would be correct if the requirement were private connectivity rather than encryption in transit.
- ✗
Use AWS Key Management Service (KMS) to encrypt the data in transit.
Why it's wrong here
KMS encrypts data at rest; it does not encrypt traffic in transit. SageMaker endpoints accept HTTPS/TLS connections, and you enforce encryption in transit by configuring the endpoint with a TLS-enabled interface or requiring HTTPS. It tempts because KMS is the AWS encryption service, but its scope is stored data, not network traffic.
- ✓
The endpoint is automatically served over HTTPS; no additional configuration is needed.
Why this is correct
SageMaker real-time endpoints expose an HTTPS inference URL by default, with TLS terminating at the endpoint and enforced for every InvokeEndpoint call. Because the stem's constraint is encryption in transit between client and endpoint, this built-in TLS satisfies it without extra configuration, unlike custom inference code or VPC settings.
- ✗
Attach an AWS Certificate Manager (ACM) certificate to the endpoint.
Why it's wrong here
ACM certificates terminate TLS at load balancers and CloudFront distributions, not at SageMaker endpoints, which expose their own HTTPS listener. Attaching one is impossible here. ACM is tempting because it issues and renews public certificates, and it would be the right choice for encrypting traffic to an Application Load Balancer fronting the endpoint.
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.