easyMultiple Select
MLA-C01 Practice Question: A machine learning engineer is setting up an…
A machine learning engineer is setting up an Amazon SageMaker notebook instance. The instance needs to access a private S3 bucket that contains training data. The notebook instance is in a VPC. Which combination of steps will grant access to the S3 bucket? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC endpoint for S3 in the same VPC and subnet.
Option A is correct because a VPC gateway endpoint for S3 lets instances in the VPC reach S3 privately over the AWS network without needing internet access, NAT, or public IPs, which is exactly what a notebook instance in a VPC requires to reach a private S3 bucket. Option D is correct because S3 access is authorized through IAM: the notebook instance must assume an IAM role whose policy grants the required s3 actions (e.g., s3:GetObject, s3:ListBucket) on the bucket and its objects, and that role must be attached to the instance. Option B is not needed and does not by itself grant S3 permissions, since a public IP only provides internet routing and S3 access still requires IAM authorization. Option C is unnecessary because a NAT gateway only enables outbound internet traffic and would not be required when using an S3 VPC endpoint. Option E is also unnecessary, as an internet gateway only provides VPC internet connectivity and does not authorize or privately route S3 access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VPC endpoint for S3 in the same VPC and subnet.
Why this is correct
A gateway VPC endpoint for S3 lets the notebook instance reach the bucket over the private AWS network, satisfying the stem's requirement that traffic stay inside the VPC. It also removes the need for a NAT gateway or internet gateway, since the endpoint routes S3 traffic directly.
- ✗
Assign a public IP address to the notebook instance.
Why it's wrong here
A public IP address gives the notebook instance outbound internet access, which does not reach a private S3 bucket; S3 access requires either an S3 VPC endpoint or a NAT gateway for the S3 traffic. Public addressing is used for instances needing direct inbound internet connectivity.
- ✗
Set up a NAT gateway in the public subnet.
Why it's wrong here
A NAT gateway provides outbound internet access for private subnets, not S3 authorisation, and S3 traffic via a gateway endpoint bypasses it entirely. It is tempting as general VPC egress plumbing, but the correct approach is an S3 gateway VPC endpoint plus an IAM role or bucket policy granting the notebook access.
- ✓
Create an IAM role with S3 access permissions and attach it to the notebook instance.
Why this is correct
Attaching an IAM role with S3 permissions to the notebook instance supplies the AWS credentials SageMaker uses to call S3, satisfying the identity-based authorisation requirement. Because the instance sits in a VPC, this role-based access works alongside a gateway VPC endpoint, which provides the private network path to the bucket.
- ✗
Attach an internet gateway to the VPC.
Why it's wrong here
An internet gateway attaches to a VPC to enable public subnet internet routing; it does not by itself grant a private-subnet notebook instance access to a private S3 bucket. Internet gateways are used when resources need direct inbound or outbound internet connectivity.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.