Courseiva
hardMultiple SelectObjective-mapped

MLA-C01 Practice Question: A financial services company must ensure that all…

A financial services company must ensure that all data used by Amazon SageMaker training jobs is encrypted at rest. The company wants to use a customer-managed key (CMK) for the encryption. Which steps are necessary to achieve this? (Choose TWO.)

⚠ Common exam trap

Many candidates confuse encrypting data at rest in S3 (via S3 default encryption) with encrypting the SageMaker training job's local storage volumes, which are separate and require explicit configuration via the VolumeKmsKeyId parameter.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a CMK in AWS KMS and add the SageMaker service principal to the key policy to allow it to use the key.

To use a customer-managed key (CMK) for encrypting SageMaker training job data, you must first create a CMK in AWS KMS and then add the SageMaker service principal (sagemaker.amazonaws.com) to the key policy. This grants SageMaker the necessary permissions to use the key for encrypting the ML storage volume (e.g., EBS volumes) attached to the training instances. Without this policy statement, SageMaker cannot access the CMK, and the encryption request will fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable SageMaker's default encryption for the training job by setting the EnableDefaultEncryption flag.

    Why it's wrong here

    No such flag; default encryption uses AWS-managed keys.

  • Create a CMK in AWS KMS and add the SageMaker service principal to the key policy to allow it to use the key.

    Why this is correct

    SageMaker needs permission to use the CMK.

  • Enable S3 default encryption using the CMK on all buckets containing training data.

    Why it's wrong here

    This encrypts data at rest in S3, but not SageMaker's own storage volumes.

  • Specify the CMK's ARN in the VolumeKmsKeyId parameter when creating the training job.

    Why this is correct

    This encrypts the ML storage volume attached to the training instances.

  • Use CloudWatch Logs encryption to protect the training logs.

    Why it's wrong here

    Logs are not training data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 835 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.