MLA-C01 Deployment and Orchestration of ML Workflows Practice Question
An organization wants to ensure that only approved model versions can be deployed to production. They use the SageMaker Model Registry to track model versions. How can they enforce that only approved models are deployed?
⚠ Common exam trap
A common mix-up: candidates confuse SageMaker Model Monitor (post-deployment monitoring) with pre-deployment approval enforcement, or they assume custom external checks (DynamoDB) are necessary when SageMaker provides native IAM-based conditional enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use IAM policies to restrict deployment to only Approved model versions
AWS IAM policies can be used to conditionally restrict SageMaker API actions (e.g., CreateEndpointConfig, CreateModel) based on the model version's approval status. By evaluating the `sagemaker:ModelPackageApprovalStatus` condition key in an IAM policy, you can enforce that only model versions with an `Approved` status can be deployed, providing a native, automated, and auditable enforcement mechanism without manual intervention or external dependencies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually review each model before deployment
Why it's wrong here
Manual review is error-prone and not scalable; it does not enforce the policy in code.
- ✗
Use SageMaker Model Monitor to check model quality after deployment
Why it's wrong here
Model Monitor monitors deployed models, but does not prevent deployment of unapproved models.
- ✓
Use IAM policies to restrict deployment to only Approved model versions
Why this is correct
IAM policies can be written to allow SageMaker CreateEndpoint only for models with an Approved approval status, which is best practice.
- ✗
Store model metadata in a DynamoDB table and check it before deployment
Why it's wrong here
Storing metadata in DynamoDB requires a custom deployment pipeline to query the table and enforce approval status, whereas SageMaker Model Registry natively integrates with Model Registry approval statuses and SageMaker Pipelines to gate deployments. This approach is tempting because DynamoDB is a flexible store for arbitrary model metadata, and it would be correct if the organisation needed to enforce custom approval logic not supported by the registry’s built-in approval workflow.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MLA-C01 question from scratch — 665 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.