MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A fraud detection team runs a SageMaker real-time endpoint that logs every request and response to an Amazon S3 bucket. Compliance requires that the model's prediction inputs and outputs be encrypted at rest with a customer-managed AWS KMS key, and that the endpoint be able to read the capture bucket only when necessary. The team enables data capture and specifies a KMS key on the endpoint configuration. Which additional configuration is required for the captured data written to S3 to be encrypted with that customer-managed key?
⚠ Common exam trap
The trap here is assuming the endpoint's KmsKeyId setting encrypts captured S3 objects, when it only encrypts attached storage volumes and the capture destination's own SSE-KMS configuration governs object encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption on the target S3 bucket using SSE-KMS with the customer-managed key, and grant the SageMaker execution role kms:GenerateDataKey and kms:Decrypt permissions on that key.
Captured data is written to S3 by the endpoint's execution role, so encryption with a customer-managed KMS key depends on the destination bucket applying SSE-KMS default encryption with that key and the role holding kms:GenerateDataKey and kms:Decrypt. A bucket policy or VPC endpoint can restrict access but does not encrypt capture objects. The endpoint's KmsKeyId protects attached volumes, not the S3 capture objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable default encryption on the target S3 bucket using SSE-KMS with the customer-managed key, and grant the SageMaker execution role kms:GenerateDataKey and kms:Decrypt permissions on that key.
Why this is correct
SageMaker Data Capture writes objects to S3 using the endpoint's execution role. To have those objects encrypted with a customer-managed KMS key, the destination bucket must apply SSE-KMS default encryption with that key, and the role must hold kms:GenerateDataKey and kms:Decrypt on the key. Without both, captures are written with SSE-S3 or fail, so this combination satisfies the compliance requirement.
- ✗
Attach the AWS managed policy AmazonSageMakerFullAccess to the execution role and set the endpoint's KmsKeyId to the capture bucket's bucket key.
Why it's wrong here
AmazonSageMakerFullAccess grants broad SageMaker permissions but does not by itself give the role kms:GenerateDataKey on a specific customer-managed key. Setting the endpoint's KmsKeyId encrypts attached storage volumes, not captured objects in S3, and a bucket key is an S3 Bucket Key, not a KMS key ID, so this does not meet the encryption-at-rest requirement.
- ✗
Create a VPC endpoint for S3 and configure the endpoint policy to require server-side encryption with the customer-managed key for all capture objects.
Why it's wrong here
A VPC endpoint controls network paths to S3 and can enforce access conditions, but it does not apply SSE-KMS encryption to objects written by Data Capture. The objects are encrypted based on the bucket's default encryption and the writer's KMS permissions. Network isolation is orthogonal to encryption at rest, so this does not satisfy the stated compliance control.
- ✗
Configure an S3 bucket policy that denies PutObject unless the request includes the aws:kms header, and grant the SageMaker execution role kms:GenerateDataKey and kms:Decrypt.
Why it's wrong here
A bucket policy can enforce that requests carry KMS headers, but it does not itself encrypt captured objects with the customer-managed key. Data capture writes objects through the SageMaker execution role, so the role needs KMS permissions and the capture destination must be configured to use SSE-KMS; a deny policy alone would block capture rather than encrypt it as required.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.