hardMultiple Choice
MLA-C01 Practice Question: A healthcare startup has deployed a machine…
A healthcare startup has deployed a machine learning model on Amazon SageMaker that predicts patient readmission risks. The model uses sensitive health data stored in an S3 bucket encrypted with AWS KMS. The SageMaker endpoint is configured with an IAM role that has the following policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::healthcare-data/*", "Condition": { "Bool": { "aws:SecureTransport": "true" } } }, { "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "*" } ] }. During a security audit, the team discovers that the IAM role's KMS permission is too permissive because it allows decryption of any KMS key in the account. The team needs to modify the policy to follow the principle of least privilege while still allowing the SageMaker endpoint to read the encrypted data. Which modification should the team make?
⚠ Common exam trap
MLA-C01 often tests the misconception that adding a condition or changing the action is sufficient for least privilege; candidates must recognize that scoping the Resource to the specific key ARN is the precise fix for an overly permissive KMS statement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the KMS statement to: "Action": "kms:Decrypt", "Resource": "arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"
The KMS statement currently allows kms:Decrypt on Resource '*' , which permits decryption with any KMS key in the account. Restricting the Resource to the specific KMS key ARN used to encrypt the S3 bucket enforces least privilege while still allowing the SageMaker endpoint to decrypt the data. This is the correct modification to scope the permission to only the necessary key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Change the KMS statement Action to "kms:DescribeKey" instead of "kms:Decrypt"
Why it's wrong here
DescribeKey returns metadata only and cannot decrypt ciphertext, so the endpoint would fail to read the data. Restricting to DescribeKey is tempting as a minimal permission, but decryption of the specific KMS key is required; the fix is scoping kms:Decrypt to that key's ARN.
- ✗
Add a condition to the KMS statement: "Condition": { "StringEquals": { "kms:ViaService": "s3.us-east-1.amazonaws.com" } }
Why it's wrong here
The kms:ViaService condition restricts which service may use the key, not which key ARN the role can decrypt; the Resource remains "*", so least privilege is unmet. It is tempting because kms:ViaService genuinely scopes KMS calls to S3-originated requests, and would be correct alongside a specific key ARN.
- ✗
Remove the KMS statement entirely, as S3 bucket policies with SSE-KMS do not require KMS permissions
Why it's wrong here
SSE-KMS decryption always requires kms:Decrypt on the customer managed key, so removing the statement breaks the endpoint's read access to the encrypted objects. It is tempting because S3 handles envelope encryption transparently, but that transparency still depends on the caller holding KMS permissions.
- ✓
Change the KMS statement to: "Action": "kms:Decrypt", "Resource": "arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"
Why this is correct
Scoping the KMS statement to the specific key ARN satisfies least privilege by permitting decryption only with the key protecting the healthcare-data bucket, rather than every key in the account. The endpoint retains read access to the encrypted objects, since kms:Decrypt against that exact key still succeeds.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.