Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A machine learning engineer is deploying a model to a SageMaker real-time endpoint that must be accessible only from within a specific Amazon VPC and must not have a public IP address. The engineer also needs to ensure that all data in transit between the endpoint and the calling application is encrypted. Which configuration should the engineer use?

⚠ Common exam trap

Watch out — candidates often confuse IAM-based access control with network-level isolation, assuming that restricting who can invoke the endpoint also makes it private on the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the model to a SageMaker endpoint configured with a VPC configuration specifying private subnets and a security group, and invoke it through an interface VPC endpoint.

To make a SageMaker endpoint private and accessible only within a VPC, the endpoint must be deployed with a VPC configuration that specifies private subnets and security groups, which places its network interfaces in the VPC. Invoking it through an interface VPC endpoint (AWS PrivateLink) ensures traffic stays private and encrypted in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the model to a SageMaker endpoint and attach an IAM resource policy that allows only principals from the VPC to invoke it.

    Why it's wrong here

    IAM resource policies control which principals can call the endpoint but do not change the endpoint's network placement or remove its public IP. The endpoint would still be publicly reachable at the network level, and encryption in transit would not be enforced by this configuration alone.

  • ✓

    Deploy the model to a SageMaker endpoint configured with a VPC configuration specifying private subnets and a security group, and invoke it through an interface VPC endpoint.

    Why this is correct

    Configuring the endpoint with a VPC configuration places the endpoint's elastic network interfaces in the specified private subnets, giving it private IP addresses and no public exposure. Invoking through an interface VPC endpoint (AWS PrivateLink) keeps traffic within the AWS network and supports TLS encryption in transit.

  • ✗

    Deploy the model to a SageMaker endpoint with network isolation enabled and use an interface VPC endpoint (AWS PrivateLink) for invocation.

    Why it's wrong here

    Network isolation prevents the container from making outbound network calls, which is useful for security but does not by itself provide private connectivity from the VPC to the endpoint. An interface VPC endpoint is needed for private invocation, but network isolation does not address encryption in transit or the endpoint's network placement.

  • ✗

    Deploy the endpoint with a public IP and use an AWS WAF web ACL to restrict access to the VPC CIDR range.

    Why it's wrong here

    AWS WAF filters HTTP traffic based on rules but does not remove the public IP address of the endpoint or provide private network isolation. The endpoint would still be publicly addressable, violating the requirement that it have no public IP and be accessible only within the VPC.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.