MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A retail company runs a SageMaker real-time endpoint serving a demand forecasting model. Security policy requires that all inference requests travel over the AWS private network and never traverse the public internet, and that the endpoint cannot be invoked from outside the company VPC. The endpoint already uses a customer-managed KMS key for volume encryption. Which TWO configurations should the engineer apply to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is treating container network isolation or an IAM resource policy as sufficient for private-only invocation, when the request path and endpoint reachability are governed by PrivateLink and the endpoint's VPC network access configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the endpoint's network access type to VPC-only by attaching the appropriate VPC configuration so the endpoint is reachable only from the specified subnets and security groups.
Keeping inference traffic on the AWS private network and blocking external invocation requires two complementary controls. An interface VPC endpoint for the SageMaker runtime lets InvokeEndpoint calls resolve to a private IP inside the VPC, and configuring the endpoint for VPC-only network access restricts reachability to the specified subnets and security groups. IAM policies, network isolation, and data capture do not change the request path or prevent public invocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the endpoint with EnableNetworkIsolation set to true so the container cannot make outbound network calls.
Why it's wrong here
Network isolation prevents the inference container from making outbound calls, which improves security but does not by itself force traffic onto the AWS private network or block public invocation. It addresses egress from the container, not ingress paths to the endpoint. Requests could still reach the endpoint over the public internet, so isolation alone does not satisfy the private-network requirement.
- ✗
Enable request and response data capture on the endpoint and store the captures in an S3 bucket with a bucket policy that allows only the VPC endpoint.
Why it's wrong here
Data capture records payloads for monitoring and the bucket policy restricts access to capture objects, but neither affects how inference requests reach the endpoint. Capture happens after the request is processed and does not prevent public invocation or route traffic privately. This addresses observability and storage access, not the network isolation the policy demands.
- ✓
Set the endpoint's network access type to VPC-only by attaching the appropriate VPC configuration so the endpoint is reachable only from the specified subnets and security groups.
Why this is correct
Configuring the endpoint with a VPC configuration and restricting network access to VPC-only ensures the endpoint is accessible only through the specified subnets and security groups inside the VPC. This removes public invocation paths. Together with a PrivateLink interface endpoint for the runtime API, all inference traffic stays private and external invocation is blocked, meeting the stated policy.
- ✗
Attach an IAM resource policy to the endpoint that denies all principals except the account root, and enable AWS CloudTrail data events on the endpoint.
Why it's wrong here
An IAM resource policy limits which principals can invoke the endpoint, but it does not change the network path; calls could still originate over the public internet from allowed principals. CloudTrail data events provide auditing, not traffic isolation. Neither control forces requests onto the AWS private network or prevents invocation from outside the VPC, so this does not meet the requirement.
- ✓
Create an interface VPC endpoint (AWS PrivateLink) for the SageMaker runtime in the VPC and invoke the endpoint through that endpoint.
Why this is correct
An interface VPC endpoint powered by AWS PrivateLink provides a private IP address in the VPC for the SageMaker runtime API, so InvokeEndpoint calls stay on the AWS private network and never traverse the public internet. Combined with restricting the endpoint to VPC-only access, this satisfies the requirement that inference traffic remain private and be invocable only from within the VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.