MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A healthcare analytics team stores model artifacts and training datasets in Amazon S3 and uses SageMaker. An internal audit finds that some S3 buckets containing protected health information are missing encryption and that access is granted broadly. The team must remediate quickly and prevent future misconfiguration. Which combination of actions should the ML engineer take FIRST?
⚠ Common exam trap
The trap here is choosing monitoring or logging services as the fix, when detection does not remediate existing unencrypted or broadly accessible buckets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply default bucket encryption with a customer-managed KMS key, enable S3 Block Public Access, and tighten bucket policies to least privilege.
Applying default SSE-KMS encryption with a customer-managed key secures new objects, while S3 Block Public Access and least-privilege bucket policies eliminate broad access. These actions directly fix the audit findings and set secure defaults to prevent recurrence. Logging, detection services, and bucket migration address visibility or workaround concerns rather than correcting the misconfiguration itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply default bucket encryption with a customer-managed KMS key, enable S3 Block Public Access, and tighten bucket policies to least privilege.
Why this is correct
Default bucket encryption applies SSE-KMS with a customer-managed key to all new objects, addressing the encryption gap. S3 Block Public Access and tightened bucket policies remove broad access. Together these directly remediate the audit findings and establish secure defaults that prevent recurrence, which is the appropriate first action.
- ✗
Enable S3 server access logging and CloudTrail data events, then review the logs to identify who accessed the unencrypted data.
Why it's wrong here
Logging and auditing are important for investigation and compliance, but they do not encrypt existing objects or restrict access. Reviewing historical access may inform incident response, yet the immediate obligation is to close the encryption and access-control gaps. Logging complements, but does not replace, remediation.
- ✗
Enable AWS Config rules to detect unencrypted buckets and use AWS Security Hub to aggregate findings for remediation.
Why it's wrong here
AWS Config and Security Hub detect and surface misconfigurations, but detection alone does not remediate the existing unencrypted buckets or the overly broad access. The audit requires immediate correction of current issues, not only ongoing visibility. These services are valuable for prevention but insufficient as the first remediation step.
- ✗
Migrate all datasets and artifacts to a new bucket and delete the original buckets to eliminate the misconfiguration.
Why it's wrong here
Deleting buckets risks data loss and does not guarantee the new bucket is configured securely. Migration is disruptive and unnecessary when encryption and access controls can be corrected in place. This approach also fails to establish preventive defaults for future buckets.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.