Courseiva
ML Model Development →mediumMultiple Choice

MLA-C01 ML Model Development Practice Question

A team is building a fraud detection model using SageMaker and wants to detect anomalies in user login events. Which SageMaker built-in algorithm is specifically designed for anomaly detection in event-based data?

⚠ Common exam trap

MLA-C01 often tests the distinction between IP Insights (IP/entity anomaly) and Random Cut Forest (general numeric anomaly), so candidates who see 'anomaly' and pick RCF miss the IP-event specificity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP Insights

IP Insights is a SageMaker built-in algorithm specifically designed to learn patterns of IP address usage and detect anomalous behaviour in event-based data such as login events. It embeds IP addresses and entities (e.g., user IDs) into a vector space and flags deviations, making it ideal for fraud detection on login events. The other algorithms serve different purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Factorisation Machines

    Why it's wrong here

    Factorisation Machines perform supervised classification and regression on sparse data; they do not detect anomalies in event streams. It is tempting because they handle high-dimensional sparse features, and would be correct for click-through or recommendation prediction tasks.

  • ✓

    IP Insights

    Why this is correct

    IP Insights learns normal patterns of entity-to-IP address associations and flags unusual login events, making it the built-in algorithm designed for anomaly detection in event-based data. It differs from unsupervised outlier algorithms that operate on tabular feature vectors rather than entity-IP interaction history.

  • ✗

    Random Cut Forest

    Why it's wrong here

    Random Cut Forest is for numeric anomaly detection, not specific to IP events.

  • ✗

    K-Means

    Why it's wrong here

    K-Means partitions data into a fixed number of clusters by minimising within-cluster variance, so it cannot flag individual login events as anomalous without labelled clusters. It is tempting because it does surface outliers lying far from centroids, and would suit customer segmentation or grouping unlabelled data into k distinct cohorts.

About these practice questions

One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.