MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security
A retail company stores training datasets, model artifacts, and feature data in Amazon S3. An auditor requires that all objects be encrypted at rest with keys the company controls and that key usage be independently auditable. The team wants minimal operational overhead. Which approach should the ML engineer recommend?
⚠ Common exam trap
The trap here is treating SSE-S3 as equivalent to customer-controlled encryption, when SSE-S3 keys are managed entirely by AWS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use S3 server-side encryption with AWS KMS customer-managed keys (SSE-KMS) and enable AWS CloudTrail data events for the bucket.
SSE-KMS with customer-managed keys gives the company control over key policies, rotation, and access grants while offloading cryptographic operations to AWS. CloudTrail data events record object-level S3 activity, and KMS key usage is logged separately, providing the independent audit trail the auditor requires. SSE-S3, client-side encryption with local keys, and versioning do not meet the customer-controlled key requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default bucket encryption with SSE-S3 and rely on S3 Versioning to protect against unauthorized changes.
Why it's wrong here
Default encryption with SSE-S3 still uses Amazon-managed keys, so the company does not control the key material. Versioning preserves object history and helps recover from overwrites or deletions, but it does not provide encryption with customer-controlled keys or key-usage auditing. The auditor's requirement remains unmet.
- ✗
Use S3 client-side encryption with a key stored in the application's configuration file and rotate it manually each quarter.
Why it's wrong here
Client-side encryption puts key management entirely on the team, including secure storage and rotation, which increases operational overhead and risk. Storing the key in a configuration file is a weak practice that exposes the key material. It also complicates auditing because key usage is not centrally logged.
- ✗
Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3) and enable S3 access logging.
Why it's wrong here
SSE-S3 encrypts objects with keys fully managed by Amazon S3, so the company does not control the key material or its lifecycle. Access logging records requests to the bucket but does not provide independent auditability of encryption key usage. This does not satisfy the requirement for customer-controlled keys.
- ✓
Use S3 server-side encryption with AWS KMS customer-managed keys (SSE-KMS) and enable AWS CloudTrail data events for the bucket.
Why this is correct
SSE-KMS with customer-managed keys lets the company control key policies, rotation, and grants, and every use of the key is recorded. CloudTrail data events capture S3 object-level API calls, tying each access to the KMS key usage. This delivers encryption at rest under company-controlled keys with auditable usage and low operational overhead.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.