Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A machine learning team needs to ensure that all model training and inference jobs within SageMaker Studio run in a private network without internet access. The team also requires that inter-container traffic within the same training job be encrypted. Which configurations should they combine?

⚠ Common exam trap

MLA-C01 often tests the confusion between VPC-only mode (which controls Studio access) and network isolation (which controls job containers), and candidates may overlook the need for inter-container encryption as a separate setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable network isolation mode and inter-container traffic encryption

To run SageMaker jobs in a private network without internet access, you enable network isolation mode, which prevents containers from accessing the internet. To encrypt inter-container traffic within the same training job, you enable inter-container traffic encryption. These two configurations together meet both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure SageMaker Studio in VPC-only mode and use KMS encryption

    Why it's wrong here

    VPC-only mode removes internet access, but KMS encryption protects data at rest, not inter-container traffic in transit. The stem requires encrypting traffic between containers within a training job, which KMS cannot do. KMS would be correct for encrypting volumes and artefacts at rest.

  • ✗

    Use a VPC with a NAT gateway and enable network isolation

    Why it's wrong here

    A NAT gateway provides outbound internet access, directly contradicting the no-internet requirement. Network isolation blocks outbound traffic but does not encrypt inter-container traffic. This pairing would suit jobs needing controlled egress, not fully private, encrypted inter-container communication.

  • ✗

    Enable inter-container traffic encryption and use a VPC with VPC endpoints

    Why it's wrong here

    VPC endpoints secure access to AWS services, but they do not encrypt traffic between containers in the same training job. Inter-container traffic encryption is a separate training-job parameter, not a VPC endpoint setting. This combination would be correct for private service access without internet.

  • ✓

    Enable network isolation mode and inter-container traffic encryption

    Why this is correct

    Network isolation mode blocks all outbound internet and VPC traffic from the training container, satisfying the private-network requirement. Inter-container traffic encryption secures communication between containers within the same job, meeting the encryption constraint for distributed training.

About these practice questions

One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.