MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A machine learning engineer needs to give a data scientist read-only access to the model artifacts, training metrics, and monitoring reports stored in a single Amazon S3 bucket used by a SageMaker project, while ensuring the data scientist cannot delete or overwrite any object. Which approach follows least-privilege practice?
⚠ Common exam trap
The trap here is reaching for a broad AWS managed read-only policy, which satisfies read access but violates least privilege by covering every bucket in the account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM policy to the data scientist's role granting s3:GetObject and s3:ListBucket scoped to the project bucket and its prefix, and deny s3:DeleteObject and s3:PutObject on the same resources.
Least privilege for this scenario means a scoped identity policy that allows only object reads and bucket listing on the project bucket and prefix, with write and delete actions denied. Managed read-only policies are too broad across the account, wildcard bucket policies grant write access, and presigned URLs are transient and cannot support ongoing browsing of project outputs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply an S3 bucket policy that allows the data scientist's role s3:* on the bucket, and rely on S3 versioning to recover any deleted objects.
Why it's wrong here
Allowing s3:* grants write and delete permissions, and versioning only preserves prior versions rather than preventing an authorized principal from deleting or overwriting current objects. This approach fails the requirement that the data scientist cannot delete or overwrite data, and it grants far more permission than read-only access.
- ✗
Attach the AmazonS3ReadOnlyAccess AWS managed policy to the data scientist's role so they can read any bucket in the account.
Why it's wrong here
AmazonS3ReadOnlyAccess grants read access to every S3 bucket in the account, which is broader than the single project bucket the scenario requires. Although it prevents deletion, it violates least privilege by exposing unrelated data, and it does not scope access to the SageMaker project's prefix as the requirement specifies.
- ✓
Attach an IAM policy to the data scientist's role granting s3:GetObject and s3:ListBucket scoped to the project bucket and its prefix, and deny s3:DeleteObject and s3:PutObject on the same resources.
Why this is correct
Granting only GetObject and ListBucket on the specific bucket and prefix provides the required read access for artifacts, metrics, and monitoring reports. Explicitly denying delete and put operations removes any write capability that a broader managed policy might have granted, which aligns with least privilege and prevents accidental or deliberate modification of project data.
- ✗
Create a presigned URL for each object and distribute the URLs to the data scientist as needed.
Why it's wrong here
Presigned URLs grant time-limited access to individual objects and expire, so they cannot serve as a durable read-only access mechanism for an ongoing project. They also do not provide ListBucket capability, making it impractical for browsing training metrics and monitoring reports, and they do not establish a reviewable least-privilege identity policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.