Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A media company stores training data in an S3 bucket encrypted with an AWS KMS customer-managed key. A SageMaker training job runs inside a private VPC subnet with no internet access and must read that bucket. The job currently fails with an access-denied error from S3. Which change most directly resolves the failure while preserving the private-network requirement?

⚠ Common exam trap

The trap here is treating an access-denied error as purely an IAM permissions issue, when the real blocker is the missing private network route to S3 plus KMS key policy authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an interface VPC endpoint for S3 in the subnet and add the endpoint's condition to the bucket policy and KMS key policy so the endpoint can access both resources.

A training container in a subnet without internet access can only reach S3 through a VPC endpoint, and encrypted objects additionally require that the endpoint be authorized in both the S3 bucket policy and the KMS key policy. Supplying that endpoint plus the matching key and bucket policy conditions restores the data path while keeping all traffic inside the VPC and the data encrypted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SageMaker network isolation on the training job and grant the execution role kms:Decrypt on the customer-managed key.

    Why it's wrong here

    Network isolation blocks all outbound network calls from the training container, which prevents any S3 access at all, including the bucket read the job needs. Adding kms:Decrypt does not restore connectivity. This option actively worsens the situation because the container loses the ability to reach even the VPC endpoint that would otherwise serve the request.

  • ✗

    Move the training data into an Amazon EFS file system mounted in the subnet and grant the execution role elasticfilesystem:ClientMount permissions.

    Why it's wrong here

    Mounting EFS does provide in-VPC storage, but it requires migrating and re-encrypting the dataset, which is a large change unrelated to the stated failure of reading the existing S3 bucket. The requirement is to read the bucket as-is, not to relocate data. This option also introduces file-system semantics and throughput considerations that the scenario never asks for.

  • ✗

    Attach the AmazonS3FullAccess managed policy to the SageMaker execution role and disable the bucket's default encryption temporarily during training.

    Why it's wrong here

    Broader IAM permissions do not create a network path to S3 from a subnet without internet access, so the request would still time out or fail. Disabling encryption violates the company's security posture and does not address the KMS authorization that encrypted object retrieval requires. This change treats a networking and key-policy problem as an identity problem, leaving the job unable to reach the data.

  • ✓

    Add an interface VPC endpoint for S3 in the subnet and add the endpoint's condition to the bucket policy and KMS key policy so the endpoint can access both resources.

    Why this is correct

    With no internet access, traffic to S3 must traverse a VPC endpoint, and both the S3 bucket policy and the KMS key policy must permit the endpoint so that authorization succeeds for the encrypted objects. Using a gateway endpoint for S3 also works in many designs, but the interface endpoint with proper policy conditions is the pattern that satisfies both private connectivity and key-based decryption.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.