MLA-C01 ML Model Development Practice Question
A team is building a fraud detection model using SageMaker and wants to detect anomalies in user login events. Which SageMaker built-in algorithm is specifically designed for anomaly detection in event-based data?
⚠ Common exam trap
MLA-C01 often tests the distinction between IP Insights (IP/entity anomaly) and Random Cut Forest (general numeric anomaly), so candidates who see 'anomaly' and pick RCF miss the IP-event specificity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP Insights
IP Insights is a SageMaker built-in algorithm specifically designed to learn patterns of IP address usage and detect anomalous behaviour in event-based data such as login events. It embeds IP addresses and entities (e.g., user IDs) into a vector space and flags deviations, making it ideal for fraud detection on login events. The other algorithms serve different purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Factorisation Machines
Why it's wrong here
Factorisation Machines perform supervised classification and regression on sparse data; they do not detect anomalies in event streams. It is tempting because they handle high-dimensional sparse features, and would be correct for click-through or recommendation prediction tasks.
- ✓
IP Insights
Why this is correct
IP Insights learns normal patterns of entity-to-IP address associations and flags unusual login events, making it the built-in algorithm designed for anomaly detection in event-based data. It differs from unsupervised outlier algorithms that operate on tabular feature vectors rather than entity-IP interaction history.
- ✗
Random Cut Forest
Why it's wrong here
Random Cut Forest is for numeric anomaly detection, not specific to IP events.
- ✗
K-Means
Why it's wrong here
K-Means partitions data into a fixed number of clusters by minimising within-cluster variance, so it cannot flag individual login events as anomalous without labelled clusters. It is tempting because it does surface outliers lying far from centroids, and would suit customer segmentation or grouping unlabelled data into k distinct cohorts.
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.