MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A healthcare company has deployed a SageMaker model that predicts patient risk scores. The security team requires that all access to the model's endpoint be authenticated and authorized, and that every invocation be traceable to a specific user or application for audit purposes. The team also wants to enforce least privilege so that only specific applications can invoke the endpoint. Which TWO actions should the machine learning engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is thinking that network-level controls like network isolation or storing the URL in Secrets Manager provide authentication and auditability, when they do not identify or authorize callers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to each calling application's IAM role that allows the sagemaker:InvokeEndpoint action on the specific endpoint ARN.
IAM policies scoped to the specific endpoint ARN enforce authentication and least privilege, ensuring only authorized applications can invoke the endpoint. CloudTrail data events for SageMaker endpoints record each invocation with caller identity and request details, providing the required audit trail. Together they satisfy authentication, authorization, and traceability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable network isolation on the endpoint to prevent unauthorized outbound calls.
Why it's wrong here
Network isolation controls whether the model container can make outbound network calls; it does not authenticate or authorize inbound invocation requests. It also does not provide an audit trail of who invoked the endpoint, so it does not meet the authentication or traceability requirements.
- ✓
Attach an IAM policy to each calling application's IAM role that allows the sagemaker:InvokeEndpoint action on the specific endpoint ARN.
Why this is correct
IAM policies with the sagemaker:InvokeEndpoint action scoped to the specific endpoint ARN enforce least privilege and ensure that only authorized applications can invoke the endpoint. This also provides authentication and authorization because every call is signed with AWS Signature Version 4 using the caller's IAM credentials, which can be audited.
- ✓
Enable AWS CloudTrail data events for the SageMaker endpoint to log every InvokeEndpoint API call.
Why this is correct
CloudTrail data events for SageMaker endpoints capture the identity of the caller, the time, and the request parameters for each InvokeEndpoint call. This provides the audit trail required to trace every invocation to a specific user or application, complementing IAM-based authorization.
- ✗
Store the endpoint's invocation URL in AWS Secrets Manager and require applications to retrieve it before calling.
Why it's wrong here
Storing the endpoint URL in Secrets Manager does not authenticate or authorize callers; the URL itself is not a secret that grants access. Any principal with network access and IAM permissions could still invoke the endpoint, and the secret retrieval would not provide per-caller auditability for invocations.
- ✗
Configure the endpoint to use a resource-based policy that allows anonymous invocation from the VPC.
Why it's wrong here
A resource-based policy allowing anonymous invocation would remove authentication entirely, violating the requirement that all access be authenticated. It would also make it impossible to trace invocations to a specific user or application, which is required for audit purposes.
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.