Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A fraud-detection team runs a SageMaker real-time endpoint in a production account. Their security team requires that the endpoint be reachable only from within a specific Amazon VPC and that access to invoke the endpoint be governed by identity-based policies with least privilege. Which TWO configurations should the ML engineer implement to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that network isolation on the container restricts who can invoke the endpoint, when it only limits the container's outbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM policy to the calling role that allows sagemaker:InvokeEndpoint only for the specific endpoint ARN and denies other SageMaker actions.

Private connectivity through an interface VPC endpoint for SageMaker Runtime keeps invocation traffic inside the VPC and off the public internet, while an identity-based IAM policy scoped to the specific endpoint ARN enforces least-privilege authorization. Together they satisfy the network and identity requirements. Network isolation, volume encryption, and data capture address container egress, data-at-rest protection, and observability respectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the endpoint's DataCaptureConfig to capture 100 percent of requests and responses for monitoring.

    Why it's wrong here

    Data capture records request and response payloads to Amazon S3 for monitoring and analysis. It does not restrict network access or authorize callers, and capturing all traffic increases storage cost and may retain sensitive data. This setting addresses observability, not the access-control requirements.

  • ✗

    Enable network isolation on the endpoint configuration to block all outbound traffic from the model container.

    Why it's wrong here

    Network isolation restricts the container's outbound network access during inference, which is useful for sensitive models but does not control who can invoke the endpoint or from where. It does not create a private network path or govern caller identity. It addresses a different security concern than the stated requirements.

  • ✗

    Configure the endpoint to use a customer-managed KMS key for volume encryption and rotate the key annually.

    Why it's wrong here

    A customer-managed KMS key encrypts the endpoint's storage volume at rest, protecting model artifacts and temporary data. It does not restrict network reachability or define which principals can invoke the endpoint. Encryption at rest is valuable but unrelated to the VPC-only and least-privilege invocation requirements.

  • ✓

    Attach an IAM policy to the calling role that allows sagemaker:InvokeEndpoint only for the specific endpoint ARN and denies other SageMaker actions.

    Why this is correct

    An identity-based policy that grants sagemaker:InvokeEndpoint scoped to the specific endpoint ARN enforces least privilege for callers. This restricts which principals can invoke which endpoint and prevents broader SageMaker permissions. It complements the network control by governing authorization independently of the network path.

  • ✓

    Create an interface VPC endpoint (AWS PrivateLink) for the SageMaker Runtime service in the VPC and invoke the endpoint through it.

    Why this is correct

    An interface VPC endpoint for SageMaker Runtime uses AWS PrivateLink to provide private connectivity so that clients in the VPC invoke the endpoint without traversing the public internet. Combined with a restrictive endpoint policy and security groups, this confines invocation to the specified VPC and is the standard way to meet the network-isolation requirement.

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.