Courseiva

MLA-C01 Practice Question: ML Solution Monitoring, Maintenance, and Security

A retail company stores training datasets, model artifacts, and feature data in Amazon S3. An auditor requires that all objects be encrypted at rest with keys the company controls and that key usage be independently auditable. The team wants minimal operational overhead. Which approach should the ML engineer recommend?

⚠ Common exam trap

The trap here is treating SSE-S3 as equivalent to customer-controlled encryption, when SSE-S3 keys are managed entirely by AWS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use S3 server-side encryption with AWS KMS customer-managed keys (SSE-KMS) and enable AWS CloudTrail data events for the bucket.

SSE-KMS with customer-managed keys gives the company control over key policies, rotation, and access grants while offloading cryptographic operations to AWS. CloudTrail data events record object-level S3 activity, and KMS key usage is logged separately, providing the independent audit trail the auditor requires. SSE-S3, client-side encryption with local keys, and versioning do not meet the customer-controlled key requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default bucket encryption with SSE-S3 and rely on S3 Versioning to protect against unauthorized changes.

    Why it's wrong here

    Default encryption with SSE-S3 still uses Amazon-managed keys, so the company does not control the key material. Versioning preserves object history and helps recover from overwrites or deletions, but it does not provide encryption with customer-controlled keys or key-usage auditing. The auditor's requirement remains unmet.

  • ✗

    Use S3 client-side encryption with a key stored in the application's configuration file and rotate it manually each quarter.

    Why it's wrong here

    Client-side encryption puts key management entirely on the team, including secure storage and rotation, which increases operational overhead and risk. Storing the key in a configuration file is a weak practice that exposes the key material. It also complicates auditing because key usage is not centrally logged.

  • ✗

    Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3) and enable S3 access logging.

    Why it's wrong here

    SSE-S3 encrypts objects with keys fully managed by Amazon S3, so the company does not control the key material or its lifecycle. Access logging records requests to the bucket but does not provide independent auditability of encryption key usage. This does not satisfy the requirement for customer-controlled keys.

  • ✓

    Use S3 server-side encryption with AWS KMS customer-managed keys (SSE-KMS) and enable AWS CloudTrail data events for the bucket.

    Why this is correct

    SSE-KMS with customer-managed keys lets the company control key policies, rotation, and grants, and every use of the key is recorded. CloudTrail data events capture S3 object-level API calls, tying each access to the KMS key usage. This delivers encryption at rest under company-controlled keys with auditable usage and low operational overhead.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.