Courseiva
hardMultiple Choice

MLA-C01 Practice Question: A healthcare startup has deployed a machine…

A healthcare startup has deployed a machine learning model on Amazon SageMaker that predicts patient readmission risks. The model uses sensitive health data stored in an S3 bucket encrypted with AWS KMS. The SageMaker endpoint is configured with an IAM role that has the following policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::healthcare-data/*", "Condition": { "Bool": { "aws:SecureTransport": "true" } } }, { "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "*" } ] }. During a security audit, the team discovers that the IAM role's KMS permission is too permissive because it allows decryption of any KMS key in the account. The team needs to modify the policy to follow the principle of least privilege while still allowing the SageMaker endpoint to read the encrypted data. Which modification should the team make?

⚠ Common exam trap

MLA-C01 often tests the misconception that adding a condition or changing the action is sufficient for least privilege; candidates must recognize that scoping the Resource to the specific key ARN is the precise fix for an overly permissive KMS statement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the KMS statement to: "Action": "kms:Decrypt", "Resource": "arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"

The KMS statement currently allows kms:Decrypt on Resource '*' , which permits decryption with any KMS key in the account. Restricting the Resource to the specific KMS key ARN used to encrypt the S3 bucket enforces least privilege while still allowing the SageMaker endpoint to decrypt the data. This is the correct modification to scope the permission to only the necessary key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the KMS statement Action to "kms:DescribeKey" instead of "kms:Decrypt"

    Why it's wrong here

    DescribeKey returns metadata only and cannot decrypt ciphertext, so the endpoint would fail to read the data. Restricting to DescribeKey is tempting as a minimal permission, but decryption of the specific KMS key is required; the fix is scoping kms:Decrypt to that key's ARN.

  • ✗

    Add a condition to the KMS statement: "Condition": { "StringEquals": { "kms:ViaService": "s3.us-east-1.amazonaws.com" } }

    Why it's wrong here

    The kms:ViaService condition restricts which service may use the key, not which key ARN the role can decrypt; the Resource remains "*", so least privilege is unmet. It is tempting because kms:ViaService genuinely scopes KMS calls to S3-originated requests, and would be correct alongside a specific key ARN.

  • ✗

    Remove the KMS statement entirely, as S3 bucket policies with SSE-KMS do not require KMS permissions

    Why it's wrong here

    SSE-KMS decryption always requires kms:Decrypt on the customer managed key, so removing the statement breaks the endpoint's read access to the encrypted objects. It is tempting because S3 handles envelope encryption transparently, but that transparency still depends on the caller holding KMS permissions.

  • ✓

    Change the KMS statement to: "Action": "kms:Decrypt", "Resource": "arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"

    Why this is correct

    Scoping the KMS statement to the specific key ARN satisfies least privilege by permitting decryption only with the key protecting the healthcare-data bucket, rather than every key in the account. The endpoint retains read access to the encrypted objects, since kms:Decrypt against that exact key still succeeds.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.