Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A machine learning engineer is configuring a SageMaker Processing job that runs a custom container to compute bias metrics on a dataset containing personally identifiable information. The job reads input data from one S3 bucket and writes reports to another, and the security team requires that the container has no outbound internet access and that the input and output buckets are reached without traversing the public internet. Which configuration satisfies these requirements?

⚠ Common exam trap

The trap here is assuming that enabling network isolation by itself secures S3 access, when private bucket reachability requires VPC endpoints on the processing subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set NetworkConfig.EnableNetworkIsolation to true, attach a VpcConfig with private subnets, and create S3 gateway VPC endpoints that the subnet route tables reference.

Network isolation removes the container's ability to make outbound calls, and the VPC configuration places processing instances in subnets you control. S3 gateway endpoints on those subnets' route tables provide a private path for reading inputs and writing reports, satisfying both the no-internet and no-public-traversal constraints without a NAT gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach a VpcConfig with private subnets and a NAT gateway in the route table, and leave network isolation disabled so the container can reach S3.

    Why it's wrong here

    A NAT gateway provides outbound internet access, which directly contradicts the requirement that the container have no outbound internet access. Leaving isolation disabled also permits the container to initiate arbitrary outbound connections, so this configuration fails the security team's constraint even though S3 would be reachable.

  • ✓

    Set NetworkConfig.EnableNetworkIsolation to true, attach a VpcConfig with private subnets, and create S3 gateway VPC endpoints that the subnet route tables reference.

    Why this is correct

    Network isolation blocks the container from making outbound network calls, while the VPC configuration places the processing instances in private subnets. S3 gateway endpoints attached to those subnets' route tables let the job download inputs and upload reports over the AWS private network, so both the no-internet and no-public-traversal requirements are met without opening a NAT path.

  • ✗

    Attach a VpcConfig with public subnets and an internet gateway, and set EnableNetworkIsolation to true so the container cannot use the gateway.

    Why it's wrong here

    Placing processing instances in public subnets exposes them to inbound internet routing and does not provide a private path to S3. Isolation would block the container's outbound calls but would also prevent it from reaching S3 unless a private endpoint or proxy exists, and public subnets violate the intent of keeping sensitive processing off public networks.

  • ✗

    Set NetworkConfig.EnableNetworkIsolation to true and rely on the default SageMaker service-linked network path to reach S3.

    Why it's wrong here

    Enabling network isolation without a VPC configuration means the processing instances use service-managed networking, and there is no route table you control to guarantee private S3 access. Traffic to S3 would not be pinned to a private path, so the requirement that bucket access avoid the public internet is not satisfied by isolation alone.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.