Which TWO actions are recommended best practices for securing an Amazon SageMaker notebook instance? (Select TWO.)
AWS KMS encryption protects the notebook instance's attached EBS storage volume at rest, satisfying the requirement to secure stored data, including notebooks and datasets. SageMaker integrates natively with customer managed KMS keys, so encryption applies to the volume without altering the instance's runtime behaviour or interrupting interactive development sessions.
Why this answer
Option C is correct because SageMaker notebook instances store data on an attached EBS volume, and AWS best practices recommend encrypting that storage with an AWS KMS customer managed key to protect data at rest, including notebooks, scripts, and artifacts. Option E is correct because disabling direct internet access forces the notebook instance to route traffic through a VPC (with NAT gateway or VPC endpoints), which prevents unauthorized outbound access and helps protect against data exfiltration while still allowing controlled access to AWS services. Option A is not a recommended best practice for securing a notebook instance because network ACLs are stateless subnet-level controls and do not govern SageMaker API calls, which are authorized via IAM policies and VPC endpoint policies.
Option B is incorrect because Multi-AZ deployment is not a feature of SageMaker notebook instances; they run in a single Availability Zone. Option D is incorrect because placing a notebook instance in a public subnet with an internet gateway exposes it to inbound internet traffic and violates the recommendation to keep notebook instances in private subnets without direct internet access.
Exam trap
The trap here is that candidates often confuse network-level controls (network ACLs) with API-level controls (IAM/VPC endpoints), or they mistakenly think Multi-AZ applies to all AWS services, when in fact it is specific to database and high-availability services.