Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A fraud-detection team runs a SageMaker real-time endpoint. Compliance requires that every inference request be logged with its full request and response payloads, and that a security engineer be able to prove later which requests were captured. The team enables SageMaker Model Monitor data capture with a capture percentage of 100. Where are the captured records stored, and what must be configured so the records are encrypted with a customer-managed key rather than an AWS-managed key?

⚠ Common exam trap

The trap here is assuming that a KMS key parameter on the endpoint configuration governs captured payloads, when payload encryption is actually controlled by the destination S3 bucket's encryption settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Records are written to the S3 bucket specified in the DataCaptureConfig, and encryption with the customer-managed KMS key is applied by setting the KmsKeyId on that bucket's default encryption or by using an S3 bucket policy requiring the key.

Data capture stores request and response records as objects in the S3 bucket named in the endpoint's DataCaptureConfig, so key control is exercised at the S3 layer through default bucket encryption with a customer-managed KMS key or a bucket policy that denies uploads lacking that key. Endpoint volume keys and CloudWatch log groups do not govern those capture objects, making the S3-based approach the one that satisfies the audit and encryption requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Records are written to the S3 bucket in the DataCaptureConfig, and the customer-managed key is passed as the VolumeKmsKeyId property on the endpoint configuration.

    Why it's wrong here

    VolumeKmsKeyId encrypts the attached storage volume used by the hosting instances, not the captured payload objects delivered to S3. The capture data never lands on that volume, so this key choice has no effect on where or how the JSON records are encrypted at rest. The team would believe it met the requirement while the objects remained under default encryption.

  • ✗

    Records are written to Amazon CloudWatch Logs under the endpoint's log group, and the customer-managed key is supplied through the KmsKeyId parameter of the DataCaptureConfig object.

    Why it's wrong here

    Data capture does not publish payloads to CloudWatch Logs; the log group holds endpoint invocation metrics and error messages, not the request and response bodies. DataCaptureConfig has a DestinationS3Uri field rather than a KmsKeyId field for this purpose. Selecting CloudWatch would leave the team without the payload-level audit records compliance requires.

  • ✓

    Records are written to the S3 bucket specified in the DataCaptureConfig, and encryption with the customer-managed KMS key is applied by setting the KmsKeyId on that bucket's default encryption or by using an S3 bucket policy requiring the key.

    Why this is correct

    Data capture writes JSON lines to the S3 destination given in DataCaptureConfig, so the storage location is the customer's own bucket. Because SageMaker delivers with S3 PutObject, the SSE-KMS setting comes from the bucket's default encryption or a policy that rejects uploads not using the customer-managed key. This gives the audit trail and key control the scenario demands.

  • ✗

    Records are written to an Amazon Kinesis Data Firehose delivery stream created automatically by SageMaker, and the customer-managed key is set on the Firehose stream's SSE configuration.

    Why it's wrong here

    SageMaker data capture does not create or require a Firehose delivery stream; it writes capture files directly to the S3 location you provide. There is no automatic Firehose resource to attach a key to, so this design cannot be implemented as described. The team would need to add its own streaming layer, which the question does not call for.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.