MLA-C01 ML Model Development Practice Question
A company wants to detect anomalies in login events from a large user base, focusing on unusual patterns that may indicate compromised accounts. Which SageMaker built-in algorithm is most suitable for this task?
⚠ Common exam trap
The trap is confusing general anomaly detection algorithms with IP Insights, which is purpose-built for user-IP login anomaly detection and is the only option that directly addresses the scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP Insights
IP Insights is a SageMaker built-in unsupervised algorithm designed to learn the relationship between user entities and IP addresses, making it ideal for detecting anomalous login events such as a user logging in from an unusual IP or a compromised account accessing from a new location. It is specifically built for the login-anomaly use case described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP Insights
Why this is correct
IP Insights learns normal patterns of entity-to-IP associations, flagging unusual login behaviour such as an account authenticating from an atypical address. This directly targets compromised-account detection across a large user base, unlike classification or forecasting algorithms that require labelled anomaly data.
- ✗
K-Means
Why it's wrong here
K-Means partitions records into a fixed number of clusters by distance to centroids; it assigns every login to a group and cannot label outliers, since no cluster represents anomalous behaviour. It is tempting because it is unsupervised, and would be correct when segmenting users into distinct behavioural groups for profiling.
- ✗
DeepAR
Why it's wrong here
DeepAR forecasts future values in a time series using autoregressive recurrent networks; it predicts expected numeric sequences rather than flagging individual login events that deviate from learned patterns. It is tempting because it learns seasonal baselines, and would be correct when forecasting demand or metrics over time from historical series data.
- ✗
Factorisation Machines
Why it's wrong here
Factorisation Machines model sparse feature interactions for supervised prediction such as click-through or rating tasks; they require labelled targets and do not score deviation from normal login behaviour. They are tempting because they handle high-dimensional sparse data, and would be correct when predicting a known outcome from user-item interaction features.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.