MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A machine learning team needs to ensure that all model training and inference jobs within SageMaker Studio run in a private network without internet access. The team also requires that inter-container traffic within the same training job be encrypted. Which configurations should they combine?
⚠ Common exam trap
MLA-C01 often tests the confusion between VPC-only mode (which controls Studio access) and network isolation (which controls job containers), and candidates may overlook the need for inter-container encryption as a separate setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable network isolation mode and inter-container traffic encryption
To run SageMaker jobs in a private network without internet access, you enable network isolation mode, which prevents containers from accessing the internet. To encrypt inter-container traffic within the same training job, you enable inter-container traffic encryption. These two configurations together meet both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure SageMaker Studio in VPC-only mode and use KMS encryption
Why it's wrong here
VPC-only mode removes internet access, but KMS encryption protects data at rest, not inter-container traffic in transit. The stem requires encrypting traffic between containers within a training job, which KMS cannot do. KMS would be correct for encrypting volumes and artefacts at rest.
- ✗
Use a VPC with a NAT gateway and enable network isolation
Why it's wrong here
A NAT gateway provides outbound internet access, directly contradicting the no-internet requirement. Network isolation blocks outbound traffic but does not encrypt inter-container traffic. This pairing would suit jobs needing controlled egress, not fully private, encrypted inter-container communication.
- ✗
Enable inter-container traffic encryption and use a VPC with VPC endpoints
Why it's wrong here
VPC endpoints secure access to AWS services, but they do not encrypt traffic between containers in the same training job. Inter-container traffic encryption is a separate training-job parameter, not a VPC endpoint setting. This combination would be correct for private service access without internet.
- ✓
Enable network isolation mode and inter-container traffic encryption
Why this is correct
Network isolation mode blocks all outbound internet and VPC traffic from the training container, satisfying the private-network requirement. Inter-container traffic encryption secures communication between containers within the same job, meeting the encryption constraint for distributed training.
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.