Courseiva

MLA-C01 Deployment and Orchestration of ML Workflows Practice Question

An organization wants to ensure that only approved model versions can be deployed to production. They use the SageMaker Model Registry to track model versions. How can they enforce that only approved models are deployed?

⚠ Common exam trap

A common mix-up: candidates confuse SageMaker Model Monitor (post-deployment monitoring) with pre-deployment approval enforcement, or they assume custom external checks (DynamoDB) are necessary when SageMaker provides native IAM-based conditional enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use IAM policies to restrict deployment to only Approved model versions

AWS IAM policies can be used to conditionally restrict SageMaker API actions (e.g., CreateEndpointConfig, CreateModel) based on the model version's approval status. By evaluating the `sagemaker:ModelPackageApprovalStatus` condition key in an IAM policy, you can enforce that only model versions with an `Approved` status can be deployed, providing a native, automated, and auditable enforcement mechanism without manual intervention or external dependencies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually review each model before deployment

    Why it's wrong here

    Manual review is error-prone and not scalable; it does not enforce the policy in code.

  • ✗

    Use SageMaker Model Monitor to check model quality after deployment

    Why it's wrong here

    Model Monitor monitors deployed models, but does not prevent deployment of unapproved models.

  • ✓

    Use IAM policies to restrict deployment to only Approved model versions

    Why this is correct

    IAM policies can be written to allow SageMaker CreateEndpoint only for models with an Approved approval status, which is best practice.

  • ✗

    Store model metadata in a DynamoDB table and check it before deployment

    Why it's wrong here

    Storing metadata in DynamoDB requires a custom deployment pipeline to query the table and enforce approval status, whereas SageMaker Model Registry natively integrates with Model Registry approval statuses and SageMaker Pipelines to gate deployments. This approach is tempting because DynamoDB is a flexible store for arbitrary model metadata, and it would be correct if the organisation needed to enforce custom approval logic not supported by the registry’s built-in approval workflow.

About these practice questions

Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.