MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A machine learning engineer must grant a data scientist the least-privilege permissions needed to invoke one specific SageMaker real-time endpoint from their own AWS account, and to view that endpoint's CloudWatch metrics without being able to modify the endpoint. The endpoint ARN is known. Which TWO IAM policy statements should the engineer include? (Choose two.)
⚠ Common exam trap
The trap here is bundling a write-oriented monitoring permission such as PutMetricAlarm with the read-only metrics permissions, when viewing metrics only requires the CloudWatch read actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow sagemaker:InvokeEndpoint on the specific endpoint ARN.
Least privilege here means two read/invoke capabilities and nothing that changes the endpoint. InvokeEndpoint scoped to the endpoint ARN provides inference access, and the CloudWatch read actions GetMetricData and GetMetricStatistics provide visibility into endpoint metrics. Management actions such as UpdateEndpoint, PutMetricAlarm, and CreateEndpointConfig are excluded because they either modify the endpoint or exceed the requested permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow cloudwatch:PutMetricAlarm on all resources so the data scientist can create alarms on endpoint metrics.
Why it's wrong here
PutMetricAlarm creates and modifies CloudWatch alarms, which is a write operation on monitoring configuration and exceeds the read-only metrics access requested. It also grants the action on all resources, violating least privilege. The requirement is to view metrics, not to author alarms, so this statement should not be included in the policy.
- ✗
Allow sagemaker:CreateEndpointConfig so the data scientist can tune the endpoint's instance type.
Why it's wrong here
CreateEndpointConfig creates new endpoint configuration resources and is used together with endpoint update operations to change instance types or model settings. It is a management action that enables modification of deployment topology, which directly conflicts with the requirement that the data scientist be unable to modify the endpoint. It also would not scope to a single existing endpoint ARN.
- ✓
Allow sagemaker:InvokeEndpoint on the specific endpoint ARN.
Why this is correct
InvokeEndpoint is the runtime action used to send inference requests to a real-time endpoint, and scoping the resource to the exact endpoint ARN grants access only to that endpoint rather than all endpoints in the account. This is the minimum permission required for the data scientist to call the model, and it does not confer any ability to change the endpoint's configuration.
- ✗
Allow sagemaker:UpdateEndpoint on the specific endpoint ARN.
Why it's wrong here
UpdateEndpoint changes the endpoint's model or configuration and can cause downtime or alter production behavior, which is exactly the modification capability the requirement excludes. Granting it would violate least privilege even though the resource is scoped narrowly, because the data scientist only needs to invoke the endpoint and read its metrics, not redeploy or reconfigure it.
- ✓
Allow cloudwatch:GetMetricData on the endpoint's metrics and allow cloudwatch:GetMetricStatistics for the relevant namespace.
Why this is correct
CloudWatch metrics for SageMaker endpoints live in the AWS/SageMaker namespace, and reading them requires cloudwatch:GetMetricData and cloudwatch:GetMetricStatistics. These are read-only actions that let the data scientist chart invocation counts, latency, and errors without granting any ability to modify the endpoint itself, matching the least-privilege requirement.
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.