MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A media company stores training data in an S3 bucket encrypted with an AWS KMS customer-managed key. A SageMaker training job runs inside a private VPC subnet with no internet access and must read that bucket. The job currently fails with an access-denied error from S3. Which change most directly resolves the failure while preserving the private-network requirement?
⚠ Common exam trap
The trap here is treating an access-denied error as purely an IAM permissions issue, when the real blocker is the missing private network route to S3 plus KMS key policy authorization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an interface VPC endpoint for S3 in the subnet and add the endpoint's condition to the bucket policy and KMS key policy so the endpoint can access both resources.
A training container in a subnet without internet access can only reach S3 through a VPC endpoint, and encrypted objects additionally require that the endpoint be authorized in both the S3 bucket policy and the KMS key policy. Supplying that endpoint plus the matching key and bucket policy conditions restores the data path while keeping all traffic inside the VPC and the data encrypted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SageMaker network isolation on the training job and grant the execution role kms:Decrypt on the customer-managed key.
Why it's wrong here
Network isolation blocks all outbound network calls from the training container, which prevents any S3 access at all, including the bucket read the job needs. Adding kms:Decrypt does not restore connectivity. This option actively worsens the situation because the container loses the ability to reach even the VPC endpoint that would otherwise serve the request.
- ✗
Move the training data into an Amazon EFS file system mounted in the subnet and grant the execution role elasticfilesystem:ClientMount permissions.
Why it's wrong here
Mounting EFS does provide in-VPC storage, but it requires migrating and re-encrypting the dataset, which is a large change unrelated to the stated failure of reading the existing S3 bucket. The requirement is to read the bucket as-is, not to relocate data. This option also introduces file-system semantics and throughput considerations that the scenario never asks for.
- ✗
Attach the AmazonS3FullAccess managed policy to the SageMaker execution role and disable the bucket's default encryption temporarily during training.
Why it's wrong here
Broader IAM permissions do not create a network path to S3 from a subnet without internet access, so the request would still time out or fail. Disabling encryption violates the company's security posture and does not address the KMS authorization that encrypted object retrieval requires. This change treats a networking and key-policy problem as an identity problem, leaving the job unable to reach the data.
- ✓
Add an interface VPC endpoint for S3 in the subnet and add the endpoint's condition to the bucket policy and KMS key policy so the endpoint can access both resources.
Why this is correct
With no internet access, traffic to S3 must traverse a VPC endpoint, and both the S3 bucket policy and the KMS key policy must permit the endpoint so that authorization succeeds for the encrypted objects. Using a gateway endpoint for S3 also works in many designs, but the interface endpoint with proper policy conditions is the pattern that satisfies both private connectivity and key-based decryption.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.