Courseiva
easyMultiple Choice

MLA-C01 Practice Question: Ensure that only authorized users and services…

A company wants to ensure that only authorized users and services can invoke a SageMaker real-time endpoint. Which AWS service can be used to manage access control?

⚠ Common exam trap

It's easy for candidates to confuse monitoring or auditing services (CloudWatch, CloudTrail, Config) with access control, mistakenly thinking they can restrict API calls when they only observe or log them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Identity and Access Management (IAM)

AWS Identity and Access Management (IAM) is the correct service because it allows you to create fine-grained permissions policies that control which users, roles, or services can invoke a SageMaker real-time endpoint via the InvokeEndpoint API. By attaching IAM policies to principals (e.g., IAM users, roles, or federated identities), you can restrict invocation based on conditions such as source IP, VPC endpoint, or MFA, ensuring only authorized entities can send inference requests.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon CloudWatch

    Why it's wrong here

    CloudWatch collects metrics, logs and alarms for monitoring; it cannot grant or deny permission to invoke an endpoint. It is tempting because it observes endpoint performance and invocation counts, which suits operational dashboards and alerting rather than access control.

  • ✓

    AWS Identity and Access Management (IAM)

    Why this is correct

    IAM controls authentication and authorisation for SageMaker endpoint invocation through identity-based policies and resource policies. It satisfies the requirement to restrict endpoint access to authorised users and services, unlike network-level controls that do not manage identity.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail logs API activity for auditing after the fact; it does not enforce who may call InvokeEndpoint. It is tempting because it records every invocation for investigation, which suits forensic review and compliance reporting rather than preventing unauthorised access.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records and evaluates resource configuration compliance; it does not authenticate callers or authorise InvokeEndpoint requests. It is tempting because it governs resource settings and can flag drift, which suits auditing whether endpoint configurations meet internal policy.

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.