Courseiva

CCNA ML Solution Monitoring, Maintenance, and Security Questions

75 of 94 questions · Page 1/2 · ML Solution Monitoring, Maintenance, and Security · Answers revealed

1
MCQmedium

A company wants to implement a retraining pipeline that automatically triggers when SageMaker Model Monitor detects data drift. The retraining job should use the latest approved pipeline version in SageMaker Pipelines. Which approach meets these requirements?

A.Use a scheduled EventBridge rule to run the pipeline every day
B.Use SageMaker Model Monitor to update the model registry and trigger a deployment
C.Configure SageMaker Model Monitor to directly invoke a Lambda function on violation
D.Create an EventBridge rule that listens for SageMaker Model Monitor violation events and triggers a Lambda function that starts the pipeline
AnswerD

EventBridge natively consumes SageMaker Model Monitor violation events, and the rule's target Lambda starts the latest approved pipeline version through the SageMaker Pipelines API. This satisfies both constraints: automatic triggering on drift detection and use of the newest approved pipeline version.

Why this answer

It uses an EventBridge rule to listen for SageMaker Model Monitor violation events (e.g., `aws.sagemaker.model-monitoring-violation`), which then triggers a Lambda function that starts the latest approved pipeline version in SageMaker Pipelines. This creates an automated, event-driven retraining pipeline without manual intervention or scheduled polling.

Exam trap

The trap here is that candidates may think SageMaker Model Monitor can directly invoke Lambda or update the model registry, but in reality, it only emits events to EventBridge, and the integration requires an intermediate Lambda function to orchestrate the pipeline execution.

How to eliminate wrong answers

Option A is wrong because a scheduled EventBridge rule runs the pipeline daily regardless of whether data drift has occurred, leading to unnecessary retraining and resource waste. Option B is wrong because SageMaker Model Monitor does not directly update the model registry or trigger a deployment; it only publishes violation events and metrics. Option C is wrong because SageMaker Model Monitor cannot directly invoke a Lambda function; it emits events to EventBridge, which can then trigger Lambda, but the direct invocation is not supported.

2
MCQeasy

A data scientist notices that a SageMaker endpoint is returning HTTP 5XX errors under high load. The endpoint uses a single ml.m5.large instance. The team wants to reduce these errors without changing the instance type. What is the most cost-effective step?

A.Increase the endpoint's invocation timeout to 120 seconds
B.Deploy the model on a SageMaker batch transform job
C.Configure auto-scaling for the endpoint with a target tracking policy
D.Create a new endpoint with multiple instances and use weighted routing
AnswerC

Auto-scaling adds instances behind the endpoint when invocations rise, spreading load so no single ml.m5.large instance saturates and returns 5XX errors. A target tracking policy on a metric such as InvocationsPerInstance scales capacity automatically, satisfying the no-instance-type-change constraint while avoiding over-provisioning costs.

Why this answer

Configuring auto-scaling with a target tracking policy allows the endpoint to dynamically add more instances under high load, distributing the traffic and reducing HTTP 5XX errors. Since the team cannot change the instance type, scaling out is the most cost-effective way to handle increased demand, as it only adds capacity when needed and avoids over-provisioning.

Exam trap

The trap here is that candidates may think increasing the timeout (Option A) or using batch transform (Option B) can solve real-time load issues, but these options do not address the fundamental need for horizontal scaling under high concurrency.

How to eliminate wrong answers

Option A is wrong because increasing the invocation timeout to 120 seconds does not address the root cause of 5XX errors under high load; it merely extends the time the endpoint has to respond, which can lead to increased latency and potential timeouts, but does not prevent the endpoint from being overwhelmed. Option B is wrong because deploying the model on a SageMaker batch transform job is for offline, asynchronous inference on a static dataset, not for real-time serving; it cannot replace a real-time endpoint that needs to handle live traffic. Option D is wrong because creating a new endpoint with multiple instances and weighted routing adds cost by requiring manual management and does not automatically scale based on load; it is less cost-effective than auto-scaling, which adjusts capacity dynamically.

3
MCQhard

A company uses SageMaker Model Monitor for data quality. They notice that monitoring jobs are failing intermittently with constraint violations. Upon review, they see that some features have different data types in production compared to the baseline (e.g., string instead of integer). Which type of drift is this?

A.Schema drift
B.Concept drift
C.Statistical drift
D.Bias drift
AnswerA

Schema drift occurs when the structure or data types of incoming features diverge from the baseline, such as a string arriving where an integer was expected. This mismatch triggers the constraint violations the monitoring jobs report.

Why this answer

Schema drift occurs when the structure or data types of features in production data differ from the baseline used during model training. In this scenario, a feature that was an integer in the baseline is now a string in production, which is a classic example of schema drift. SageMaker Model Monitor detects this by comparing the inferred schema of production data against the baseline schema, flagging any type mismatches as constraint violations.

Exam trap

The trap here is that candidates may confuse schema drift with statistical drift, thinking any change in feature values qualifies as statistical drift, but the key differentiator is that schema drift specifically involves changes in data type or structure, not just distributional shifts.

How to eliminate wrong answers

Option B is wrong because concept drift refers to changes in the underlying relationship between features and the target variable, not changes in data types or schema. Option C is wrong because statistical drift (e.g., distribution shift) involves changes in the statistical properties of features (like mean or variance) while data types remain consistent. Option D is wrong because bias drift relates to changes in model fairness metrics over time, such as disparate impact, not to data type mismatches.

4
MCQeasy

A data scientist wants to track the lineage of models, datasets, and training jobs in SageMaker. Which SageMaker feature should they use to capture these relationships as artifacts and actions?

A.SageMaker Model Registry
B.SageMaker Experiments
C.SageMaker ML Lineage Tracking
D.SageMaker Feature Store
AnswerC

SageMaker ML Lineage Tracking automatically records relationships between datasets, training jobs and model artifacts as lineage entities, capturing both artifacts and actions. This directly satisfies the stem's requirement to track provenance across the machine learning workflow, which generic logging or experiment tracking alone would not provide.

Why this answer

SageMaker ML Lineage Tracking creates a graph of artifacts (datasets, models) and actions (training jobs, endpoints) to track the provenance of ML workflows.

5
Multi-Selecteasy

A data science team wants to automate the retraining of a model when data drift is detected. Which TWO AWS services should they use in combination to achieve this? (Choose TWO)

Select 2 answers
A.AWS Cloud9
B.Amazon DynamoDB
C.SageMaker Model Monitor
D.AWS Lambda
E.Amazon Kinesis Data Analytics
AnswersC, D

SageMaker Model Monitor evaluates endpoint data against baselines and emits CloudWatch metrics when drift is detected, providing the detection half of the automation. Pairing it with an action service such as Lambda completes the retraining trigger.

Why this answer

SageMaker Model Monitor (C) is the correct service for detecting data drift: it continuously monitors a deployed model's endpoint, compares incoming inference data against a baseline, and can emit CloudWatch metrics/alerts when drift (or data quality, bias, or feature attribution issues) is detected. AWS Lambda (D) is the correct companion service because it can be triggered by those CloudWatch alarms/events to run the retraining logic — for example, invoking a SageMaker training job or pipeline to retrain and redeploy the model automatically. Together they form the detect-then-retrain automation loop the team needs.

AWS Cloud9 (A) is only a cloud IDE and provides no monitoring or automation capability. Amazon DynamoDB (B) is a NoSQL database and does not detect drift or orchestrate retraining. Amazon Kinesis Data Analytics (E) is for real-time stream processing with SQL/Flink, not for model drift detection or triggering retraining workflows.

6
MCQeasy

A company wants to automate remediation when a SageMaker endpoint's latency exceeds a threshold for more than 5 minutes. The team needs to be notified and a Lambda function should be invoked to scale up the endpoint. Which combination of services should be used?

A.CloudWatch Alarm → SNS topic → Lambda function
B.EventBridge rule to trigger Lambda
C.CloudWatch Logs subscription filter → Lambda function
D.SageMaker Model Monitor → Lambda function
AnswerA

A CloudWatch alarm on the endpoint's latency metric detects the five-minute threshold breach, publishing to an SNS topic that both notifies subscribers and invokes the Lambda function to scale the endpoint, satisfying the combined notification and automated remediation requirement.

Why this answer

CloudWatch Alarms evaluate SageMaker endpoint metrics (e.g., ModelLatency) against thresholds over evaluation periods; when the alarm fires after 5 minutes of breach, it publishes to an SNS topic, which can fan out to both email/SMS subscribers for notification and a Lambda function for automated scaling. This is the canonical AWS pattern for metric-driven remediation.

Exam trap

MLA-C01 often tests whether candidates know that EventBridge handles event-driven triggers while CloudWatch Alarms handle metric-threshold triggers — mixing these up is the most common wrong-answer path.

How to eliminate wrong answers

Option B is wrong because EventBridge rules react to events/state changes, not to metric threshold breaches over time — EventBridge cannot natively evaluate 'latency > X for 5 minutes'. Option C is wrong because CloudWatch Logs subscription filters process log events, not CloudWatch metrics, and SageMaker endpoint latency is a metric, not a log stream. Option D is wrong because SageMaker Model Monitor detects data drift, bias, and quality issues in model predictions — it does not monitor endpoint latency or trigger scaling actions.

7
Multi-Selecteasy

A machine learning engineer wants to set up a retraining pipeline that triggers when model quality degrades. Which TWO components are essential for this automated retraining pipeline? (Select TWO)

Select 2 answers
A.CloudWatch Alarm on model quality metric
B.SNS topic to send notification to a Lambda function
C.SageMaker Ground Truth to collect new labels
D.SageMaker Data Wrangler to preprocess data
E.EventBridge rule to schedule retraining weekly
AnswersA, B

The alarm detects when model quality drops below a threshold.

8
MCQeasy

A machine learning engineer wants to monitor a deployed model for data drift. Which SageMaker feature should they use to automatically detect drift in the input data distribution compared to the training data baseline?

A.SageMaker Pipelines
B.SageMaker Model Monitor
C.SageMaker Debugger
D.SageMaker Clarify
AnswerB

SageMaker Model Monitor continuously evaluates endpoint input data against a training baseline, computing statistical distances to raise CloudWatch alerts when drift exceeds thresholds. This directly satisfies the requirement for automatic detection of input distribution shifts, unlike Model Registry or Clarify, which address governance and bias respectively.

Why this answer

SageMaker Model Monitor can be configured to run monitoring jobs that compare live inference data against a baseline created from training data to detect data drift.

9
Multi-Selecthard

A company is deploying a foundation model using SageMaker JumpStart. They want to minimize inference costs while maintaining low latency. Which TWO strategies should they consider? (Select TWO)

Select 2 answers
A.Enable data capture for all requests to analyze usage patterns
B.Use SageMaker Savings Plans for discounted compute rates
C.Deploy the model on a single large instance to maximize throughput
D.Enable auto-scaling with a target tracking policy based on Invocations per instance
E.Use SageMaker Inference Recommender to select the most cost-effective instance type
AnswersD, E

Auto-scaling adjusts capacity to match demand, avoiding over-provisioning.

Why this answer

Auto-scaling with a target tracking policy based on Invocations per instance dynamically adjusts the number of instances to match demand, ensuring you only pay for the compute capacity you need while maintaining low latency. This avoids over-provisioning and reduces idle costs, directly addressing the goal of minimizing inference costs.

Exam trap

The AWS exam often tests the misconception that cost minimization is achieved solely through discount plans (Savings Plans) or instance size, rather than through dynamic scaling and right-sizing based on actual workload patterns.

10
MCQmedium

A fraud-detection team runs a SageMaker real-time endpoint. Compliance requires that every inference request be logged with its full request and response payloads, and that a security engineer be able to prove later which requests were captured. The team enables SageMaker Model Monitor data capture with a capture percentage of 100. Where are the captured records stored, and what must be configured so the records are encrypted with a customer-managed key rather than an AWS-managed key?

A.Records are written to the S3 bucket in the DataCaptureConfig, and the customer-managed key is passed as the VolumeKmsKeyId property on the endpoint configuration.
B.Records are written to Amazon CloudWatch Logs under the endpoint's log group, and the customer-managed key is supplied through the KmsKeyId parameter of the DataCaptureConfig object.
C.Records are written to the S3 bucket specified in the DataCaptureConfig, and encryption with the customer-managed KMS key is applied by setting the KmsKeyId on that bucket's default encryption or by using an S3 bucket policy requiring the key.
D.Records are written to an Amazon Kinesis Data Firehose delivery stream created automatically by SageMaker, and the customer-managed key is set on the Firehose stream's SSE configuration.
AnswerC

Data capture writes JSON lines to the S3 destination given in DataCaptureConfig, so the storage location is the customer's own bucket. Because SageMaker delivers with S3 PutObject, the SSE-KMS setting comes from the bucket's default encryption or a policy that rejects uploads not using the customer-managed key. This gives the audit trail and key control the scenario demands.

Why this answer

Data capture stores request and response records as objects in the S3 bucket named in the endpoint's DataCaptureConfig, so key control is exercised at the S3 layer through default bucket encryption with a customer-managed KMS key or a bucket policy that denies uploads lacking that key. Endpoint volume keys and CloudWatch log groups do not govern those capture objects, making the S3-based approach the one that satisfies the audit and encryption requirement.

Exam trap

The trap here is assuming that a KMS key parameter on the endpoint configuration governs captured payloads, when payload encryption is actually controlled by the destination S3 bucket's encryption settings.

11
Multi-Selecthard

A healthcare company has deployed a SageMaker model that predicts patient risk scores. The security team requires that all access to the model's endpoint be authenticated and authorized, and that every invocation be traceable to a specific user or application for audit purposes. The team also wants to enforce least privilege so that only specific applications can invoke the endpoint. Which TWO actions should the machine learning engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable network isolation on the endpoint to prevent unauthorized outbound calls.
B.Attach an IAM policy to each calling application's IAM role that allows the sagemaker:InvokeEndpoint action on the specific endpoint ARN.
C.Enable AWS CloudTrail data events for the SageMaker endpoint to log every InvokeEndpoint API call.
D.Store the endpoint's invocation URL in AWS Secrets Manager and require applications to retrieve it before calling.
E.Configure the endpoint to use a resource-based policy that allows anonymous invocation from the VPC.
AnswersB, C

IAM policies with the sagemaker:InvokeEndpoint action scoped to the specific endpoint ARN enforce least privilege and ensure that only authorized applications can invoke the endpoint. This also provides authentication and authorization because every call is signed with AWS Signature Version 4 using the caller's IAM credentials, which can be audited.

Why this answer

IAM policies scoped to the specific endpoint ARN enforce authentication and least privilege, ensuring only authorized applications can invoke the endpoint. CloudTrail data events for SageMaker endpoints record each invocation with caller identity and request details, providing the required audit trail. Together they satisfy authentication, authorization, and traceability.

Exam trap

The trap here is thinking that network-level controls like network isolation or storing the URL in Secrets Manager provide authentication and auditability, when they do not identify or authorize callers.

12
MCQeasy

A company has a SageMaker endpoint that serves a recommendation model. The security team wants to ensure that the model artifacts stored in Amazon S3 are encrypted at rest and that access to the S3 bucket is limited to the SageMaker execution role only. The team also wants to receive alerts if the bucket policy is changed. Which combination of actions should the machine learning engineer take?

A.Enable S3 Transfer Acceleration and restrict access using an IAM policy attached to the SageMaker execution role.
B.Enable S3 server access logging and use Amazon GuardDuty to monitor for unauthorized access to the bucket.
C.Use S3 Object Lock in compliance mode and attach a bucket policy that denies all principals except the SageMaker execution role.
D.Enable default encryption on the S3 bucket using AWS KMS, restrict the bucket policy to the SageMaker execution role, and enable AWS CloudTrail logging for S3 bucket policy changes with a CloudWatch alarm.
AnswerD

Enabling default encryption with AWS KMS ensures artifacts are encrypted at rest. Restricting the bucket policy to the SageMaker execution role enforces least privilege. CloudTrail logs S3 bucket policy changes, and a CloudWatch alarm on the relevant event pattern provides alerting when the policy is modified.

Why this answer

Encryption at rest is achieved with S3 default encryption using AWS KMS. Least privilege access is enforced by a bucket policy that allows only the SageMaker execution role. Alerting on bucket policy changes requires CloudTrail to log the event and a CloudWatch alarm to notify when the policy is modified.

Exam trap

The trap here is assuming that server access logging or GuardDuty provides encryption and policy-change alerting, when they only log access or detect threats.

13
MCQmedium

A fraud detection team runs a SageMaker real-time endpoint that logs every request and response to an Amazon S3 bucket. Compliance requires that the model's prediction inputs and outputs be encrypted at rest with a customer-managed AWS KMS key, and that the endpoint be able to read the capture bucket only when necessary. The team enables data capture and specifies a KMS key on the endpoint configuration. Which additional configuration is required for the captured data written to S3 to be encrypted with that customer-managed key?

A.Enable default encryption on the target S3 bucket using SSE-KMS with the customer-managed key, and grant the SageMaker execution role kms:GenerateDataKey and kms:Decrypt permissions on that key.
B.Attach the AWS managed policy AmazonSageMakerFullAccess to the execution role and set the endpoint's KmsKeyId to the capture bucket's bucket key.
C.Create a VPC endpoint for S3 and configure the endpoint policy to require server-side encryption with the customer-managed key for all capture objects.
D.Configure an S3 bucket policy that denies PutObject unless the request includes the aws:kms header, and grant the SageMaker execution role kms:GenerateDataKey and kms:Decrypt.
AnswerA

SageMaker Data Capture writes objects to S3 using the endpoint's execution role. To have those objects encrypted with a customer-managed KMS key, the destination bucket must apply SSE-KMS default encryption with that key, and the role must hold kms:GenerateDataKey and kms:Decrypt on the key. Without both, captures are written with SSE-S3 or fail, so this combination satisfies the compliance requirement.

Why this answer

Captured data is written to S3 by the endpoint's execution role, so encryption with a customer-managed KMS key depends on the destination bucket applying SSE-KMS default encryption with that key and the role holding kms:GenerateDataKey and kms:Decrypt. A bucket policy or VPC endpoint can restrict access but does not encrypt capture objects. The endpoint's KmsKeyId protects attached volumes, not the S3 capture objects.

Exam trap

The trap here is assuming the endpoint's KmsKeyId setting encrypts captured S3 objects, when it only encrypts attached storage volumes and the capture destination's own SSE-KMS configuration governs object encryption.

14
MCQhard

A machine learning team needs to ensure that all model training and inference jobs within SageMaker Studio run in a private network without internet access. The team also requires that inter-container traffic within the same training job be encrypted. Which configurations should they combine?

A.Configure SageMaker Studio in VPC-only mode and use KMS encryption
B.Use a VPC with a NAT gateway and enable network isolation
C.Enable inter-container traffic encryption and use a VPC with VPC endpoints
D.Enable network isolation mode and inter-container traffic encryption
AnswerD

Network isolation mode blocks all outbound internet and VPC traffic from the training container, satisfying the private-network requirement. Inter-container traffic encryption secures communication between containers within the same job, meeting the encryption constraint for distributed training.

Why this answer

To run SageMaker jobs in a private network without internet access, you enable network isolation mode, which prevents containers from accessing the internet. To encrypt inter-container traffic within the same training job, you enable inter-container traffic encryption. These two configurations together meet both requirements.

Exam trap

MLA-C01 often tests the confusion between VPC-only mode (which controls Studio access) and network isolation (which controls job containers), and candidates may overlook the need for inter-container encryption as a separate setting.

How to eliminate wrong answers

Option A is wrong because VPC-only mode for SageMaker Studio does not necessarily prevent internet access for training jobs, and KMS encryption is for data at rest, not inter-container traffic. Option B is wrong because a NAT gateway provides internet access, which contradicts the requirement for no internet access. Option C is wrong because using a VPC with VPC endpoints provides private access to AWS services but does not enforce network isolation or encrypt inter-container traffic; inter-container encryption is a separate setting.

15
Multi-Selectmedium

A data science team uses SageMaker to train and deploy models. They need to track model lineage, including datasets, training jobs, and model versions, to ensure reproducibility. Which THREE actions should they take? (Select THREE)

Select 3 answers
A.Enable SageMaker ML Lineage Tracking
B.Register all models in the SageMaker Model Registry
C.Store trained models in a public S3 bucket
D.Use SageMaker Experiments to organize training runs
E.Tag all resources with metadata such as project ID and training run ID
AnswersA, B, E

Lineage tracking automatically records artifacts, actions, and contexts.

Why this answer

A is correct because SageMaker ML Lineage Tracking automatically captures the relationships between datasets, training jobs, and model versions, creating a directed acyclic graph (DAG) of the ML workflow. This enables full reproducibility by allowing you to trace which data and code produced a specific model, without manual intervention.

Exam trap

The trap here is that candidates confuse SageMaker Experiments (which tracks metrics and parameters) with ML Lineage Tracking (which tracks the full provenance graph), leading them to select D instead of A, even though Experiments alone does not capture the inter-resource relationships needed for reproducibility.

16
MCQmedium

A data science team wants to track the lineage of models, including datasets, training jobs, and endpoints, for reproducibility and audit. They need a solution that captures relationships between artifacts automatically during training and deployment. Which service should they use?

A.Amazon S3 object versioning
B.SageMaker Experiments
C.SageMaker Model Registry
D.SageMaker ML Lineage Tracking
AnswerD

SageMaker ML Lineage Tracking automatically records relationships between datasets, training jobs, model artefacts, and endpoints as they are created, forming a queryable lineage graph. This satisfies the requirement for automatic capture during training and deployment for reproducibility and audit.

Why this answer

SageMaker ML Lineage Tracking automatically captures relationships among datasets, training jobs, model artifacts, and endpoints as the pipeline runs, producing a queryable lineage graph for reproducibility and audit. It records entities and associations without custom instrumentation, which is exactly what the team needs. SageMaker Experiments tracks runs and metrics but does not build the full artifact relationship graph.

Exam trap

MLA-C01 often tests the distinction between lineage tracking and model registry; candidates pick Model Registry because it sounds like governance, but it only catalogs models, not their data ancestry.

How to eliminate wrong answers

Option A is wrong because S3 object versioning only preserves object history; it has no concept of training jobs, endpoints, or relationships between artifacts. Option B is wrong because SageMaker Experiments organizes trials and metrics for comparison but does not automatically capture dataset-to-model-to-endpoint lineage. Option C is wrong because SageMaker Model Registry catalogs model versions and approval status, not the upstream dataset and training-job relationships required for full lineage.

17
Multi-Selectmedium

An ML team has deployed a model to a SageMaker real-time endpoint and wants to set up automated monitoring for model quality. Which TWO elements are required to configure SageMaker Model Monitor for model quality? (Select TWO.)

Select 2 answers
A.SHAP values for feature attribution
B.A constraints file with allowed deviation thresholds
C.A ground truth labels dataset for comparison
D.The endpoint's prediction output captured in real-time
E.A baseline statistics file derived from the training data
AnswersC, D

Ground truth labels are essential to compare against predictions and compute model quality metrics.

Why this answer

SageMaker Model Monitor for model quality requires a ground truth labels dataset to compare the model's predictions against actual outcomes. This comparison is essential for calculating quality metrics like accuracy, precision, recall, or F1 score, which indicate how well the model is performing over time.

Exam trap

The trap here is that candidates confuse the requirements for model quality monitoring (which needs ground truth labels and captured predictions) with those for data quality monitoring (which needs a baseline statistics file and constraints), leading them to select options B or E incorrectly.

18
MCQmedium

An ML engineer monitors a SageMaker endpoint for data drift. They set up SageMaker Model Monitor to compare inference data against a baseline created from the training dataset. The monitoring schedule runs daily and reports violations. Which monitoring type should be configured to detect if the distribution of a numerical feature in real-time inference data differs significantly from the training distribution?

A.Data quality monitoring
B.Feature attribution drift monitoring
C.Bias drift monitoring
D.Model quality monitoring
AnswerA

Data quality monitoring compares the statistical distribution of features in captured inference data against a baseline built from the training dataset, detecting drift in numerical features. This matches the stem's requirement to flag significant distribution differences.

Why this answer

SageMaker Model Monitor's data quality monitoring detects feature distribution drift (statistical drift) between baseline and live data. Model quality monitoring requires ground truth labels, bias drift monitors fairness metrics, and feature attribution drift monitors SHAP values.

19
MCQhard

A company uses SageMaker Model Monitor's feature attribution drift monitoring with SHAP. They receive an alert that the average SHAP value for a particular feature has increased significantly compared to the baseline. The feature's input distribution has not changed. What does this likely indicate?

A.The feature is no longer relevant to predictions
B.A bug in the SHAP computation
C.Data drift in that feature
D.Concept drift in the model
AnswerD

Feature attribution drift with unchanged input distribution isolates the model's learned relationship: SHAP values rising while inputs stay stable means the model now weights that feature differently, which is concept drift rather than data drift.

Why this answer

Feature attribution drift monitoring compares SHAP value distributions between baseline and current data. If the input distribution of a feature is unchanged but its average SHAP value shifts significantly, the model's learned relationship between that feature and the target has changed — this is the definition of concept drift. The model itself is unchanged, but the underlying mapping from inputs to outputs in the real world has shifted, so the same input values now contribute differently to predictions.

Exam trap

The trap is conflating data drift (change in input distribution P(X)) with concept drift (change in the relationship P(Y|X)) — the question deliberately states inputs are unchanged to force you to recognize concept drift.

How to eliminate wrong answers

Option A is wrong because an increased SHAP magnitude means the feature is contributing more to predictions, not less — irrelevance would show as SHAP values shrinking toward zero. Option B is wrong because a SHAP computation bug would typically produce erratic or uniform anomalies across many features, not a targeted, consistent increase for one feature while inputs remain stable. Option C is wrong because data drift refers to changes in the input distribution (P(X)), and the question explicitly states the input distribution has not changed — so data drift is ruled out by the premise.

20
MCQmedium

A financial institution uses SageMaker to train and deploy models. They need to track every experiment, model version, and deployment step for audit purposes. Which SageMaker feature should they use to capture the full lineage of artifacts, actions, and contexts?

A.SageMaker Clarify
B.SageMaker Model Registry
C.SageMaker Experiments
D.SageMaker ML Lineage Tracking
AnswerD

SageMaker ML Lineage Tracking automatically records relationships among artifacts, actions and contexts across training and deployment, giving the auditable end-to-end history the institution requires. Experiment tracking alone does not capture deployment steps or cross-resource lineage.

Why this answer

SageMaker ML Lineage Tracking is the feature designed to capture the full lineage of artifacts, actions, and contexts, providing an end-to-end audit trail of the machine learning workflow. It automatically records relationships between data, models, and experiments.

Exam trap

MLA-C01 often tests the confusion between SageMaker features, leading candidates to select Model Registry or Experiments when full lineage tracking across all artifacts is required.

How to eliminate wrong answers

Option A is wrong because SageMaker Clarify is used for bias detection and explainability, not lineage tracking. Option B is wrong because SageMaker Model Registry manages model versions and approval status but does not capture the full lineage of all artifacts and actions. Option C is wrong because SageMaker Experiments tracks experiment runs and metrics but does not provide comprehensive lineage across all entities like data and endpoints.

21
Multi-Selectmedium

A machine learning engineer must grant a data scientist the least-privilege permissions needed to invoke one specific SageMaker real-time endpoint from their own AWS account, and to view that endpoint's CloudWatch metrics without being able to modify the endpoint. The endpoint ARN is known. Which TWO IAM policy statements should the engineer include? (Choose two.)

Select 2 answers
A.Allow cloudwatch:PutMetricAlarm on all resources so the data scientist can create alarms on endpoint metrics.
B.Allow sagemaker:CreateEndpointConfig so the data scientist can tune the endpoint's instance type.
C.Allow sagemaker:InvokeEndpoint on the specific endpoint ARN.
D.Allow sagemaker:UpdateEndpoint on the specific endpoint ARN.
E.Allow cloudwatch:GetMetricData on the endpoint's metrics and allow cloudwatch:GetMetricStatistics for the relevant namespace.
AnswersC, E

InvokeEndpoint is the runtime action used to send inference requests to a real-time endpoint, and scoping the resource to the exact endpoint ARN grants access only to that endpoint rather than all endpoints in the account. This is the minimum permission required for the data scientist to call the model, and it does not confer any ability to change the endpoint's configuration.

Why this answer

Least privilege here means two read/invoke capabilities and nothing that changes the endpoint. InvokeEndpoint scoped to the endpoint ARN provides inference access, and the CloudWatch read actions GetMetricData and GetMetricStatistics provide visibility into endpoint metrics. Management actions such as UpdateEndpoint, PutMetricAlarm, and CreateEndpointConfig are excluded because they either modify the endpoint or exceed the requested permissions.

Exam trap

The trap here is bundling a write-oriented monitoring permission such as PutMetricAlarm with the read-only metrics permissions, when viewing metrics only requires the CloudWatch read actions.

22
MCQmedium

A healthcare analytics team stores model artifacts and training datasets in Amazon S3 and uses SageMaker. An internal audit finds that some S3 buckets containing protected health information are missing encryption and that access is granted broadly. The team must remediate quickly and prevent future misconfiguration. Which combination of actions should the ML engineer take FIRST?

A.Apply default bucket encryption with a customer-managed KMS key, enable S3 Block Public Access, and tighten bucket policies to least privilege.
B.Enable S3 server access logging and CloudTrail data events, then review the logs to identify who accessed the unencrypted data.
C.Enable AWS Config rules to detect unencrypted buckets and use AWS Security Hub to aggregate findings for remediation.
D.Migrate all datasets and artifacts to a new bucket and delete the original buckets to eliminate the misconfiguration.
AnswerA

Default bucket encryption applies SSE-KMS with a customer-managed key to all new objects, addressing the encryption gap. S3 Block Public Access and tightened bucket policies remove broad access. Together these directly remediate the audit findings and establish secure defaults that prevent recurrence, which is the appropriate first action.

Why this answer

Applying default SSE-KMS encryption with a customer-managed key secures new objects, while S3 Block Public Access and least-privilege bucket policies eliminate broad access. These actions directly fix the audit findings and set secure defaults to prevent recurrence. Logging, detection services, and bucket migration address visibility or workaround concerns rather than correcting the misconfiguration itself.

Exam trap

The trap here is choosing monitoring or logging services as the fix, when detection does not remediate existing unencrypted or broadly accessible buckets.

23
MCQhard

A retail company uses a SageMaker Model Monitor data quality monitor on a real-time endpoint. The monitor's baseline was generated from a training dataset in which the "promo_code" feature was often null. In production the feature is now populated for nearly every record, and the monitor reports violations even though model accuracy has not degraded. The team wants the monitor to stop flagging this expected change without disabling monitoring entirely. What should they do?

A.Regenerate the baseline statistics and constraints from a recent, representative production dataset and update the monitoring schedule to use the new baseline.
B.Delete the monitoring schedule and create a new one with a longer monitoring interval so that fewer violations accumulate over time.
C.Edit the constraints JSON file in Amazon S3 to remove the promo_code entry, then leave the schedule unchanged.
D.Enable explainability monitoring on the schedule so that feature attribution drift accounts for the change in promo_code.
AnswerA

Model Monitor compares incoming data against the statistics and constraints stored in the baseline. Because the production distribution of promo_code legitimately differs from the training data, the old constraints encode a stale expectation. Rebuilding the baseline from recent representative production data realigns the constraint thresholds with current behavior, so violations stop without turning monitoring off.

Why this answer

Data quality monitors flag when observed statistics fall outside the constraints derived from the baseline. When a feature's production distribution legitimately diverges from training, the correct fix is to re-establish the baseline from representative recent data so constraints reflect the new normal, rather than muting or deleting the check.

Exam trap

The trap here is treating monitor violations as a monitoring-configuration bug to be silenced, rather than as a stale-baseline problem to be corrected with fresh representative data.

24
MCQhard

A financial services company must ensure that a SageMaker model deployed to a real-time endpoint only produces predictions consistent with a fairness constraint on a protected attribute, and that any violation is detected within minutes and triggers an alert to the compliance team. The model is already deployed and monitored for data quality. Which approach should the machine learning engineer implement?

A.Enable SageMaker Model Monitor with a bias drift baseline created by SageMaker Clarify, schedule the monitoring job to run every few minutes, and configure CloudWatch alarms on the bias metrics.
B.Use SageMaker Model Registry to gate the model on a fairness condition and configure EventBridge to notify the compliance team when the model version changes.
C.Attach a Clarify explainability job to the endpoint and configure a CloudWatch alarm on the endpoint's ModelLatency metric.
D.Create a SageMaker Model Monitor data quality job with a custom metric that flags predictions where the protected attribute equals a specific value, and alarm on that metric.
AnswerA

Model Monitor supports bias drift monitoring using a Clarify-generated baseline, which defines the fairness constraint and computes bias metrics on captured data. Scheduling the job at a short interval detects violations within minutes, and emitting the metrics to CloudWatch lets alarms notify the compliance team. This directly ties the fairness constraint to automated detection and alerting.

Why this answer

Bias drift monitoring in Model Monitor compares live predictions against a Clarify-generated bias baseline that encodes the fairness constraint, computing metrics on captured data. Running the job frequently yields detection within minutes, and publishing those metrics to CloudWatch enables alarms that notify compliance. Explainability, data quality, and registry gating do not evaluate outcome fairness on a protected attribute.

Exam trap

The trap here is confusing Clarify explainability or data quality statistics with bias monitoring, when only a Clarify bias baseline evaluated by Model Monitor measures fairness constraints on a protected attribute over time.

25
Multi-Selecthard

A company wants to enable cross-account access to a SageMaker model endpoint. The model is in Account A, and Account B needs to invoke it. Which TWO steps are required? (Select TWO)

Select 2 answers
A.Attach a resource-based policy to the SageMaker model in Account A allowing access from Account B's IAM role
B.Export the model from Account A and re-deploy in Account B
C.Create an IAM role in Account B with permissions to invoke SageMaker endpoints
D.Configure VPC peering between the two accounts
E.Use a SageMaker notebook instance cross-account sharing
AnswersA, C

Resource policies grant cross-account permissions directly on the model.

Why this answer

SageMaker endpoints support resource-based policies that allow cross-account access. By attaching a resource-based policy to the model endpoint in Account A, you can grant the IAM role from Account B explicit permission to invoke the endpoint. This is the standard AWS mechanism for cross-account SageMaker endpoint invocation without needing to duplicate the model.

Exam trap

The trap here is that candidates often confuse network-level connectivity (VPC peering) with IAM-level authorization, or assume that cross-account access requires duplicating resources, when in fact SageMaker's resource-based policies provide a direct and secure solution.

26
MCQeasy

A retail company stores training datasets, model artifacts, and feature data in Amazon S3. An auditor requires that all objects be encrypted at rest with keys the company controls and that key usage be independently auditable. The team wants minimal operational overhead. Which approach should the ML engineer recommend?

A.Enable default bucket encryption with SSE-S3 and rely on S3 Versioning to protect against unauthorized changes.
B.Use S3 client-side encryption with a key stored in the application's configuration file and rotate it manually each quarter.
C.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3) and enable S3 access logging.
D.Use S3 server-side encryption with AWS KMS customer-managed keys (SSE-KMS) and enable AWS CloudTrail data events for the bucket.
AnswerD

SSE-KMS with customer-managed keys lets the company control key policies, rotation, and grants, and every use of the key is recorded. CloudTrail data events capture S3 object-level API calls, tying each access to the KMS key usage. This delivers encryption at rest under company-controlled keys with auditable usage and low operational overhead.

Why this answer

SSE-KMS with customer-managed keys gives the company control over key policies, rotation, and access grants while offloading cryptographic operations to AWS. CloudTrail data events record object-level S3 activity, and KMS key usage is logged separately, providing the independent audit trail the auditor requires. SSE-S3, client-side encryption with local keys, and versioning do not meet the customer-controlled key requirement.

Exam trap

The trap here is treating SSE-S3 as equivalent to customer-controlled encryption, when SSE-S3 keys are managed entirely by AWS.

27
MCQmedium

A team receives alerts that their SageMaker endpoint latency has increased significantly. They check CloudWatch metrics and see Invocations rising, but ModelLatency remains stable. Which metric should they investigate to find the source of the increased latency?

A.OverheadLatency
B.ModelLatency
C.5XXError
D.4XXError
AnswerA

OverheadLatency measures time spent outside the model, covering request routing, queueing and response handling. Since Invocations rose while ModelLatency stayed flat, the added delay sits in this overhead, not in model execution, pinpointing the source.

Why this answer

OverheadLatency measures the time taken by the SageMaker infrastructure to handle requests before and after model inference, including request routing, authentication, and response processing. Since ModelLatency is stable but total endpoint latency has increased, the extra time must be in the overhead component, making OverheadLatency the correct metric to investigate.

Exam trap

The trap here is that candidates assume increased Invocations directly cause higher ModelLatency, but the exam tests the distinction between inference time and infrastructure overhead, leading them to incorrectly select ModelLatency instead of OverheadLatency.

How to eliminate wrong answers

Option B is wrong because ModelLatency is explicitly stated as stable, so it cannot be the source of increased latency. Option C is wrong because 5XXError indicates server-side errors, not latency; while errors can correlate with latency, the question asks for the metric directly measuring the latency increase. Option D is wrong because 4XXError indicates client-side errors (e.g., invalid requests), which do not directly cause increased endpoint latency.

28
MCQmedium

A team uses SageMaker Clarify to monitor bias drift on a deployed model. They have defined a baseline with training data and set up a monitoring schedule. After one month, they receive a violation report indicating that the post-training metrics have deviated from the baseline. What does this violation indicate?

A.The model's predictions relative to sensitive attributes have shifted compared to the training baseline
B.The SHAP values for features have changed
C.The model's predictions are becoming less accurate
D.The distribution of input features has changed
AnswerA

Clarify's post-training bias metrics compare predicted labels across sensitive attribute groups against the training baseline. A violation means those group-conditional prediction rates have drifted, indicating the model now treats protected groups differently than when trained.

Why this answer

SageMaker Clarify bias drift monitoring compares predicted outcomes (post-training) against the baseline to detect changes in fairness metrics like disparate impact. It does not measure prediction accuracy or data quality.

29
MCQhard

An organization uses SageMaker Studio and needs to restrict Studio's internet access while allowing users to install custom packages from a private PyPI mirror hosted in a VPC. Which networking configuration should they use?

A.Use a NAT gateway to allow outbound traffic to the private PyPI mirror
B.Disable internet access for Studio and rely on SageMaker's default VPC configuration
C.Disable internet access for Studio and configure VPC-only mode, then use a VPC endpoint to the private PyPI mirror
D.Enable internet access for Studio and use a VPC endpoint to the private PyPI mirror
AnswerC

VPC-only mode blocks internet; VPC endpoint to the private mirror allows package installation from the VPC.

Why this answer

To restrict Studio's internet access while allowing access to a private PyPI mirror in a VPC, you must disable internet access for Studio and configure VPC-only mode, then create a VPC endpoint (e.g., an interface endpoint or a private link) to the mirror. This keeps all traffic within the VPC and avoids public internet exposure. The VPC endpoint provides private connectivity to the mirror without a NAT gateway or internet gateway.

Exam trap

MLA-C01 often tests the confusion between NAT gateway (internet access) and VPC endpoint (private access), tricking candidates into choosing NAT when the requirement is to restrict internet while allowing private resources.

How to eliminate wrong answers

Option A is wrong because a NAT gateway provides outbound internet access, which contradicts the requirement to restrict Studio's internet access — it would allow broader internet connectivity, not just the private mirror. Option B is wrong because disabling internet access and relying on SageMaker's default VPC configuration does not provide a path to the private PyPI mirror; the default VPC may not have the necessary endpoints or routing. Option D is wrong because enabling internet access for Studio violates the restriction requirement, even if a VPC endpoint is also used.

30
MCQeasy

An organization needs to ensure that all data used for inference on a SageMaker endpoint is encrypted at rest. The endpoint uses a SageMaker-provided container. Which configuration should be applied?

A.Use a custom container with built-in encryption
B.Specify a KMS key in the endpoint configuration
C.Enable network isolation mode
D.Enable inter-container traffic encryption
AnswerB

A KMS key encrypts the ML storage volume attached to the endpoint, ensuring data at rest is encrypted.

Why this answer

SageMaker endpoints use AWS KMS for encryption at rest. By specifying a KMS key in the endpoint configuration, the data in the attached ML storage volume is encrypted. Inter-container traffic encryption is for encryption in transit.

31
Multi-Selectmedium

A company has a SageMaker real-time endpoint that serves predictions. They want to set up automated monitoring and remediation for when the number of 5XX errors exceeds a threshold. Which TWO steps should they take? (Choose TWO.)

Select 2 answers
A.Use SageMaker Model Monitor to detect 5XX errors
B.Configure the CloudWatch Alarm to publish to an SNS topic
C.Set up a scheduled EventBridge rule to check 5XXError every minute
D.Write a custom script on EC2 to poll the endpoint and check for errors
E.Create a CloudWatch Alarm on the 5XXError metric
AnswersB, E

Remediation requires an action trigger, not just detection. Publishing the CloudWatch Alarm to an SNS topic satisfies the stem's automated remediation requirement by fanning out to subscribers such as Lambda or email, enabling an automated response once the 5XX threshold is breached.

Why this answer

A CloudWatch Alarm on the 5XXError metric can be configured to publish to an SNS topic, enabling automated notifications or remediation actions (e.g., via Lambda) when the alarm state is triggered. This is the standard AWS approach for alerting on endpoint errors without custom polling.

Exam trap

The trap here is that candidates confuse SageMaker Model Monitor (for data quality) with CloudWatch metrics (for operational health), leading them to select option A instead of recognizing that 5XX errors are operational metrics monitored via CloudWatch Alarms.

32
MCQmedium

A data scientist notices that a production model's accuracy has degraded over the past week. The training data distribution remains unchanged, but the relationship between features and the target has shifted. Which type of drift is occurring, and which monitoring approach should be used?

A.Bias drift; use SageMaker Clarify post-deployment bias monitoring
B.Data drift; use SageMaker Model Monitor data quality monitoring
C.Feature attribution drift; use SageMaker Clarify
D.Concept drift; use SageMaker Model Monitor model quality monitoring with ground truth labels
AnswerD

Concept drift is a change in the relationship between features and target while input distribution stays stable, so predictions degrade despite unchanged data. Model quality monitoring with ground truth labels detects this by comparing predicted against actual outcomes.

Why this answer

Concept drift occurs when the underlying relationship between features and target changes. Model quality monitoring (comparing predictions against ground truth) detects this. Data drift monitors feature distribution changes, which are not present here.

33
MCQmedium

A machine learning team deploys a fraud detection model on a SageMaker endpoint. The model's predictions are used in real-time. The team wants to monitor for data drift by comparing incoming data distributions against a baseline created from the training data. Which SageMaker capability should they use?

A.SageMaker Model Monitor - Model Quality Monitor
B.SageMaker Model Monitor - Data Quality Monitor
C.SageMaker Model Monitor - Feature Attribution Drift Monitor
D.SageMaker Model Monitor - Bias Drift Monitor
AnswerB

Data Quality Monitor compares incoming request distributions against a baseline computed from training data, detecting drift in feature values. This directly satisfies the requirement to monitor real-time endpoint traffic for data drift, unlike Model Quality Monitor, which tracks prediction accuracy against ground truth labels.

Why this answer

SageMaker Model Monitor's Data Quality Monitor is specifically designed to detect data drift by comparing the statistical distribution of incoming inference data against a baseline computed from the training dataset. This capability tracks metrics like mean, variance, and quantiles for each feature, alerting when significant deviations occur. For a fraud detection model requiring real-time monitoring of input distributions, this is the correct choice.

Exam trap

The trap here is that candidates often confuse 'data drift' (input distribution changes) with 'model quality drift' (prediction performance changes), leading them to select Model Quality Monitor instead of Data Quality Monitor.

How to eliminate wrong answers

Option A is wrong because Model Quality Monitor focuses on monitoring the model's predictive performance metrics (e.g., accuracy, precision, recall) against a baseline, not the distribution of input features. Option C is wrong because Feature Attribution Drift Monitor uses SHAP-based feature importance to detect shifts in how features contribute to predictions, not the raw data distributions themselves. Option D is wrong because Bias Drift Monitor tracks fairness metrics and bias over time, such as demographic parity or equal opportunity, which is unrelated to general data distribution drift.

34
MCQmedium

A company plans to deploy a large foundation model using SageMaker JumpStart. They are concerned about costs because the model will be used intermittently. Which deployment option is MOST cost-effective for intermittent traffic?

A.Purchase SageMaker Savings Plans for the endpoint
B.Deploy as a serverless endpoint
C.Use a batch transform job for each request
D.Deploy as a real-time endpoint with a multi-model endpoint
AnswerB

Serverless endpoints scale to zero when idle, so you pay only for inference requests rather than continuous instance hours. This directly satisfies the intermittent-traffic constraint, where a real-time endpoint would bill for provisioned capacity around the clock. Cold-start latency is the trade-off, but cost efficiency dominates for sporadic workloads.

Why this answer

Serverless endpoints in SageMaker automatically scale to zero when not in use, so you pay only for the compute time consumed during inference requests. This makes them the most cost-effective option for intermittent traffic, as you avoid paying for idle compute capacity.

Exam trap

The trap here is that candidates often confuse 'multi-model endpoints' with 'serverless' and assume they both scale to zero, but multi-model endpoints still run on provisioned instances that incur hourly costs regardless of traffic.

How to eliminate wrong answers

Option A is wrong because Savings Plans provide a discount on consistent usage but still require you to pay for a minimum baseline of compute, which is wasteful for intermittent traffic. Option C is wrong because batch transform jobs are designed for processing large datasets asynchronously, not for handling individual requests in real time, and they incur startup costs per job. Option D is wrong because a multi-model endpoint still runs on persistent instances that incur costs even when idle, and while it improves utilization across models, it does not eliminate idle costs for intermittent traffic.

35
MCQmedium

A company wants to deploy a foundation model from SageMaker JumpStart with the lowest possible inference cost, given that latency requirements are flexible. They have a mix of traffic volumes. Which approach should they take?

A.Use SageMaker Savings Plans to get a discount on on-demand instances
B.Deploy the model on the largest GPU instance to handle peak load
C.Deploy the model on a serverless inference endpoint
D.Select the smallest instance type that meets throughput requirements and enable automatic scaling
AnswerD

Flexible latency permits the smallest viable instance, and automatic scaling matches capacity to fluctuating traffic volumes. Together these minimise inference cost while meeting throughput, since you pay only for the instances actually needed at each moment.

Why this answer

SageMaker JumpStart provides pre-built models; for cost optimization, choosing the smallest suitable instance type and enabling auto-scaling based on demand reduces cost while handling varying traffic.

36
MCQhard

A machine learning engineer is configuring a SageMaker Processing job that runs a custom container to compute bias metrics on a dataset containing personally identifiable information. The job reads input data from one S3 bucket and writes reports to another, and the security team requires that the container has no outbound internet access and that the input and output buckets are reached without traversing the public internet. Which configuration satisfies these requirements?

A.Attach a VpcConfig with private subnets and a NAT gateway in the route table, and leave network isolation disabled so the container can reach S3.
B.Set NetworkConfig.EnableNetworkIsolation to true, attach a VpcConfig with private subnets, and create S3 gateway VPC endpoints that the subnet route tables reference.
C.Attach a VpcConfig with public subnets and an internet gateway, and set EnableNetworkIsolation to true so the container cannot use the gateway.
D.Set NetworkConfig.EnableNetworkIsolation to true and rely on the default SageMaker service-linked network path to reach S3.
AnswerB

Network isolation blocks the container from making outbound network calls, while the VPC configuration places the processing instances in private subnets. S3 gateway endpoints attached to those subnets' route tables let the job download inputs and upload reports over the AWS private network, so both the no-internet and no-public-traversal requirements are met without opening a NAT path.

Why this answer

Network isolation removes the container's ability to make outbound calls, and the VPC configuration places processing instances in subnets you control. S3 gateway endpoints on those subnets' route tables provide a private path for reading inputs and writing reports, satisfying both the no-internet and no-public-traversal constraints without a NAT gateway.

Exam trap

The trap here is assuming that enabling network isolation by itself secures S3 access, when private bucket reachability requires VPC endpoints on the processing subnets.

37
MCQmedium

A company deploys a model for fraud detection. They want to monitor if the model's predictions become less accurate over time due to changes in the underlying data distribution, but they do not have immediate access to ground truth labels. Which type of drift should they monitor as a proxy?

A.Feature attribution drift
B.Model quality drift
C.Data drift
D.Concept drift
AnswerC

Without ground truth labels, accuracy cannot be measured directly, so data drift is monitored as a proxy: it compares the live input feature distribution against the training baseline. A significant divergence signals that the model is operating on data unlike what it learned from, indicating likely degradation.

Why this answer

Data drift (option C) is the correct proxy to monitor when ground truth labels are unavailable because it detects changes in the input feature distribution over time. If the underlying data distribution shifts, the model's predictions are likely to become less accurate even if the relationship between features and labels remains stable. This allows teams to trigger retraining or investigation before model quality degrades.

Exam trap

AWS often tests the distinction between data drift and concept drift, and the trap here is that candidates confuse 'changes in data distribution' (data drift) with 'changes in the relationship between features and labels' (concept drift), assuming both require labels when only concept drift does.

How to eliminate wrong answers

Option A is wrong because feature attribution drift measures changes in the importance of features to the model's predictions, not shifts in the input data distribution itself, and it still requires some form of baseline comparison that may not directly indicate accuracy loss without labels. Option B is wrong because model quality drift requires access to ground truth labels to compute metrics like accuracy or F1-score, which the scenario explicitly states are unavailable. Option D is wrong because concept drift refers to changes in the underlying relationship between features and the target variable (the function mapping inputs to outputs), which cannot be detected without labels to compare predicted vs. actual outcomes.

38
MCQmedium

A retail company has a SageMaker model that predicts customer churn. The model was trained on data that included a 'customer_zipcode' feature. After deployment, the data science team notices that the model's predictions for certain zip codes have become less accurate over time. They suspect that the relationship between zip code and churn has changed due to a recent relocation of a major employer. Which SageMaker monitoring capability should they use to detect this type of drift?

A.SageMaker Model Monitor bias drift monitoring
B.SageMaker Model Monitor model quality monitoring
C.SageMaker Model Monitor feature attribution drift monitoring
D.SageMaker Model Monitor data quality monitoring
AnswerB

Model quality monitoring evaluates the model's predictive performance against ground truth labels over time. It can detect concept drift by measuring metrics like accuracy or AUC and alerting when they degrade. Since the relationship between zip code and churn has changed, the model's predictions become less accurate, which model quality monitoring will catch.

Why this answer

Model quality monitoring is designed to monitor the performance of a model by comparing predictions to actual labels. When the relationship between a feature and the target changes, the model's accuracy drops, and model quality monitoring will detect this drift. Data quality monitoring only looks at input distributions, bias drift focuses on fairness, and feature attribution drift looks at feature importance, none of which directly measure predictive performance.

Exam trap

The trap here is assuming that any change in feature distribution or importance is equivalent to concept drift, when actually concept drift is a change in the underlying relationship that degrades model performance.

39
Multi-Selectmedium

A team wants to secure SageMaker endpoints for a healthcare application. They must ensure data is encrypted at rest and in transit, and that the endpoint can only be accessed from within a VPC. Which THREE steps should they take? (Select THREE)

Select 3 answers
A.Use AWS KMS to encrypt the model artifacts and endpoint data
B.Store encryption keys in a public S3 bucket
C.Set the endpoint to use network isolation mode
D.Configure the endpoint to use a VPC and disable public access
E.Enable inter-container traffic encryption using TLS
AnswersA, D, E

KMS provides encryption at rest for data and models.

40
MCQeasy

A team deploys a SageMaker real-time endpoint and configures it with an auto scaling policy targeting a variant. During a flash sale, traffic spikes and the team notices that the number of instances increases, but the average model latency still climbs above the target. The team wants the scaling behavior to react faster to sudden bursts without over-provisioning during steady periods. Which change should they make to the scaling policy?

A.Switch the policy from target tracking to a step scaling policy with a larger scale-out cooldown and a smaller scale-in cooldown.
B.Lower the target value of the predefined InvocationsPerInstance metric and shorten the scale-out cooldown so capacity is added sooner.
C.Replace target tracking with a scheduled scaling policy that adds instances at fixed times each day.
D.Increase the target value of the predefined InvocationsPerInstance metric and enable a longer scale-in cooldown to stabilize the fleet.
AnswerB

Target tracking adjusts capacity to keep the metric near the target. Lowering the InvocationsPerInstance target means the policy scales out at a lower request rate per instance, adding capacity earlier, and shortening the scale-out cooldown allows consecutive scale-out actions to occur more quickly. Together they make the endpoint respond faster to bursts while still scaling in during steady, low-traffic periods.

Why this answer

Target tracking keeps a chosen metric near its target. Lowering the InvocationsPerInstance target causes scale-out to trigger at a lower request rate per instance, so additional capacity arrives earlier during a burst. Shortening the scale-out cooldown lets successive scale-out actions fire sooner.

Scaling in still occurs during quiet periods, so steady-state cost is not inflated.

Exam trap

The trap here is assuming a longer cooldown or a higher metric target improves burst handling, when both actually delay scale-out and let latency rise during sudden spikes.

41
MCQhard

A company deploys a real-time inference endpoint with auto-scaling using a target tracking policy based on average Invocations per instance. They notice that during a traffic spike, the endpoint scales out too late, causing increased latency. They want to scale proactively before the spike. Which strategy should they implement?

A.Enable provisioned concurrency on the endpoint
B.Pre-warm the endpoint by sending dummy requests
C.Use a scheduled scaling action to add capacity before the expected spike
D.Switch to a step scaling policy with a higher cooldown period
AnswerC

Scheduled scaling adds capacity at predetermined times, so instances are already running before the expected traffic spike. This proactive approach avoids the lag inherent in target tracking, which reacts only after Invocations per instance rises.

Why this answer

A scheduled scaling action adds capacity at a predetermined time before the expected traffic spike, allowing the endpoint to be ready proactively. Target tracking reacts after metrics breach thresholds, which is inherently reactive and too slow for sharp spikes. Scheduled scaling is the correct strategy when spikes are predictable (e.g., known business hours or events).

Exam trap

MLA-C01 often tests reactive versus proactive scaling, so candidates pick target tracking variants or provisioned concurrency, missing that scheduled scaling is the only truly proactive option for predictable spikes.

How to eliminate wrong answers

Option A is wrong because provisioned concurrency is a Lambda feature that pre-initialises execution environments; it does not apply to SageMaker endpoints and does not address proactive capacity for predictable spikes. Option B is wrong because pre-warming with dummy requests is a hack that does not guarantee capacity at spike time and wastes resources. Option D is wrong because step scaling with a higher cooldown period is still reactive and would delay further scaling, worsening the late-scale problem.

42
Multi-Selectmedium

A machine learning team notices an increase in 5XXError count for a SageMaker endpoint. They want to set up automated remediation. Which THREE actions should they take? (Select THREE)

Select 3 answers
A.Add an SNS topic as the alarm action
B.Increase the endpoint instance count manually
C.Create a CloudWatch Alarm on the 5XXError metric
D.Enable detailed monitoring on the endpoint
E.Configure a Lambda function to restart the endpoint or scale out
AnswersA, C, E

An SNS topic as the alarm action provides the notification and integration channel that downstream automation, such as a Lambda function, subscribes to, enabling the automated remediation workflow the team requires when the 5XXError threshold is breached.

Why this answer

Option C is correct because a CloudWatch Alarm on the SageMaker endpoint's 5XXError metric is the foundational detection mechanism that turns the rising error count into an actionable state change. Option A is correct because attaching an SNS topic as the alarm action provides the notification/event distribution channel that can fan out the alert to subscribers or trigger downstream automation. Option E is correct because a Lambda function invoked by the alarm (directly or via SNS) performs the automated remediation, such as restarting the endpoint or scaling out its instance count to restore availability.

Option B is wrong because manually increasing the instance count is a human intervention, not automated remediation, which is what the team requires. Option D is wrong because enabling detailed monitoring only increases metric granularity (e.g., 1-minute CloudWatch metrics) and does not by itself detect-and-remediate the 5XXError increase.

Exam trap

The trap here is that candidates often confuse enabling detailed monitoring (which only increases metric frequency) with automated remediation, or they mistakenly think manual scaling counts as automated remediation.

43
MCQmedium

A machine learning engineer is monitoring a deployed model for data drift. The input features are a mix of categorical and numerical columns. The baseline is from the training data. Which SageMaker Model Monitor feature should they enable to detect changes in the distribution of each feature over time?

A.Bias drift monitoring
B.Data quality monitoring
C.Model quality monitoring
D.Feature attribution drift monitoring
AnswerB

Data quality monitoring computes distribution metrics per feature against the training baseline, handling numerical and categorical columns separately, and emits violations when distributions shift. This satisfies the requirement to detect per-feature distribution changes over time.

Why this answer

Data quality monitoring in SageMaker Model Monitor compares the statistical distribution of each input feature (both numerical and categorical) against a baseline computed from the training data, detecting drift in feature distributions over time. It supports categorical and numerical columns and is the correct feature for detecting per-feature distribution changes.

Exam trap

MLA-C01 often tests the confusion between data quality monitoring and model quality monitoring — candidates pick C because 'model' sounds right, but model quality needs ground-truth labels and measures accuracy, while data quality measures input feature distributions.

How to eliminate wrong answers

Option A is wrong because bias drift monitoring (SageMaker Clarify integration) detects changes in bias metrics like disparate impact across groups, not general feature distribution drift. Option C is wrong because model quality monitoring compares model predictions against ground-truth labels to detect accuracy/regression degradation, not input feature distribution changes. Option D is wrong because feature attribution drift monitoring (also Clarify-based) tracks changes in feature importance (SHAP values) relative to baseline, not the raw distribution of feature values.

44
MCQmedium

A machine learning team deploys a model for loan approval. They want to monitor data drift on the real-time endpoint using SageMaker Model Monitor. Which set of actions should they take to set up data quality monitoring?

A.Use SageMaker Clarify to detect data drift on the endpoint
B.Enable data capture on the endpoint, generate a baseline from training data, create a data quality monitoring schedule, and set up a CloudWatch Alarm on violations
C.Create a model quality monitoring schedule directly on the endpoint without any baseline
D.Enable data capture and rely on SageMaker Model Monitor to automatically infer drift without a baseline
AnswerB

Data quality monitoring requires capturing endpoint requests and responses, generating a baseline statistics file from the training dataset, scheduling the monitor against that baseline, and alarming on violations. Together these detect drift in real-time inference data and notify the team via CloudWatch.

Why this answer

SageMaker Model Monitor requires a baseline from training data, then schedules monitoring jobs that compare live endpoint captures against that baseline. Alerts are sent via CloudWatch Alarms.

45
Multi-Selecthard

A fraud-detection team runs a SageMaker real-time endpoint in a production account. Their security team requires that the endpoint be reachable only from within a specific Amazon VPC and that access to invoke the endpoint be governed by identity-based policies with least privilege. Which TWO configurations should the ML engineer implement to meet these requirements? (Choose two.)

Select 2 answers
A.Set the endpoint's DataCaptureConfig to capture 100 percent of requests and responses for monitoring.
B.Enable network isolation on the endpoint configuration to block all outbound traffic from the model container.
C.Configure the endpoint to use a customer-managed KMS key for volume encryption and rotate the key annually.
D.Attach an IAM policy to the calling role that allows sagemaker:InvokeEndpoint only for the specific endpoint ARN and denies other SageMaker actions.
E.Create an interface VPC endpoint (AWS PrivateLink) for the SageMaker Runtime service in the VPC and invoke the endpoint through it.
AnswersD, E

An identity-based policy that grants sagemaker:InvokeEndpoint scoped to the specific endpoint ARN enforces least privilege for callers. This restricts which principals can invoke which endpoint and prevents broader SageMaker permissions. It complements the network control by governing authorization independently of the network path.

Why this answer

Private connectivity through an interface VPC endpoint for SageMaker Runtime keeps invocation traffic inside the VPC and off the public internet, while an identity-based IAM policy scoped to the specific endpoint ARN enforces least-privilege authorization. Together they satisfy the network and identity requirements. Network isolation, volume encryption, and data capture address container egress, data-at-rest protection, and observability respectively.

Exam trap

The trap here is assuming that network isolation on the container restricts who can invoke the endpoint, when it only limits the container's outbound traffic.

46
MCQeasy

An ML engineer needs to monitor the operational health of a SageMaker endpoint, specifically the time taken for the container to process an inference request and the overhead added by SageMaker. Which two CloudWatch metrics should they examine?

A.ModelLatency and 4XXError
B.Latency and 5XXError
C.ModelLatency and OverheadLatency
D.Invocations and Latency
AnswerC

ModelLatency captures the time the container spends processing the inference request, while OverheadLatency measures the additional time SageMaker adds for request routing and response handling. Together they decompose total endpoint latency into model and platform components.

Why this answer

ModelLatency is the time taken by the model to respond, and OverheadLatency is the additional time added by SageMaker infrastructure. Invocations is count, not duration; Latency is total latency (ModelLatency + OverheadLatency).

47
MCQmedium

A machine learning team trains a model in SageMaker and wants to track every step — from dataset version to hyperparameters to final model artifact — for reproducibility and audit compliance. Which SageMaker feature should they use?

A.SageMaker Feature Store
B.SageMaker ML Lineage Tracking
C.SageMaker Experiments
D.SageMaker Model Registry
AnswerB

ML Lineage Tracking automatically captures entities and artefacts across the ML workflow, recording dataset versions, hyperparameters and model artefacts as a queryable graph. This satisfies the reproducibility and audit compliance constraint by preserving end-to-end traceability.

Why this answer

SageMaker ML Lineage Tracking is the correct choice because it is specifically designed to create a directed acyclic graph (DAG) of every step in the ML workflow, including dataset versions, hyperparameters, training jobs, and model artifacts. This enables full reproducibility and audit compliance by capturing the provenance of each entity and their relationships, which is exactly what the question requires.

Exam trap

The trap here is that candidates confuse SageMaker Experiments (which tracks trial metrics and parameters) with ML Lineage Tracking (which captures the full end-to-end provenance graph), leading them to pick Experiments when the question explicitly asks for tracking every step from dataset to final artifact for audit compliance.

How to eliminate wrong answers

Option A is wrong because SageMaker Feature Store is a centralized repository for storing, managing, and sharing features (input data) for ML models, but it does not track the lineage of training steps, hyperparameters, or model artifacts. Option C is wrong because SageMaker Experiments focuses on organizing and comparing multiple training runs (trials) with their parameters and metrics, but it does not automatically capture the full lineage graph connecting datasets, models, and endpoints for audit trails. Option D is wrong because SageMaker Model Registry is a catalog for managing model versions, approvals, and deployments, but it does not track the upstream lineage of how a model was trained (e.g., which dataset version and hyperparameters were used).

48
MCQmedium

A team monitors a production endpoint and notices a sudden increase in 5XXError count. Which of the following is the most likely cause?

A.The endpoint is under-provisioned and requests are throttled
B.The input data format has changed
C.The model container is out of memory or crashing
D.The model is returning predictions with high latency
AnswerC

5XX errors are server-side failures returned by the endpoint itself, so the fault lies in the container rather than the client request. Memory exhaustion or a container crash prevents the model server from completing inference, producing exactly this error class, whereas throttling or bad input would surface as 4XX responses.

Why this answer

A sudden increase in 5XX errors, particularly HTTP 503 or 502, typically indicates that the model container is failing to process requests due to resource exhaustion (e.g., OOM kills) or a crash in the inference process. In a production ML endpoint, such errors often stem from the container running out of memory, leading to the container being terminated by the orchestrator (e.g., Kubernetes OOMKill) or the application crashing internally, which directly causes 5XX responses.

Exam trap

In AWS, 5XX errors on a SageMaker endpoint indicate server-side failures (e.g., container crash, out-of-memory). A common trap is to confuse 5XX errors with client-side errors like throttling (HTTP 429) or input format issues (HTTP 400), but only 5XX errors point to a problem within the model container or inference code.

How to eliminate wrong answers

Option A is wrong because under-provisioning leading to throttling typically results in 429 (Too Many Requests) errors, not 5XX errors; 5XX indicates server-side failures, not rate limiting. Option B is wrong because a change in input data format would likely cause 400 (Bad Request) errors or prediction failures, not a sudden spike in 5XX errors, as the server would reject malformed inputs at the request validation layer. Option D is wrong because high latency does not inherently generate 5XX errors; it may cause timeouts (e.g., 504 Gateway Timeout) if the load balancer or API gateway has a timeout setting, but a general increase in latency alone does not produce a broad 5XX error count unless the container crashes under load.

49
MCQeasy

A company has deployed a machine learning model on Amazon SageMaker and wants to automatically detect when the distribution of input features deviates significantly from the training data distribution. Which SageMaker feature should they use?

A.SageMaker Clarify
B.SageMaker Edge Manager
C.SageMaker Model Monitor – Model Quality Monitoring
D.SageMaker Model Monitor – Data Quality Monitoring
AnswerD

SageMaker Model Monitor's data quality monitoring compares live inference traffic against a baseline computed from the training dataset, raising CloudWatch alerts when feature distributions drift beyond configured thresholds. This directly satisfies the requirement to detect input feature deviation from the training distribution automatically, without custom code.

Why this answer

SageMaker Model Monitor – Data Quality Monitoring is the correct choice because it is specifically designed to detect deviations in the distribution of input features compared to the training data distribution. It continuously monitors incoming inference requests and compares statistical properties (e.g., mean, variance, or histogram) against a baseline computed from the training dataset, alerting when drift is detected.

Exam trap

The trap here is that candidates often confuse 'Data Quality Monitoring' with 'Model Quality Monitoring', mistakenly thinking that monitoring prediction accuracy covers input distribution drift, whereas Data Quality Monitoring is explicitly for input features and Model Quality Monitoring is for output predictions.

How to eliminate wrong answers

Option A is wrong because SageMaker Clarify is used for bias detection and explainability of model predictions, not for monitoring input feature distribution drift. Option B is wrong because SageMaker Edge Manager manages and optimizes models on edge devices, focusing on deployment and inference at the edge, not on monitoring input data quality in a cloud-based SageMaker endpoint. Option C is wrong because SageMaker Model Monitor – Model Quality Monitoring tracks prediction quality metrics (e.g., accuracy, precision) against a ground truth, not the distribution of input features.

50
MCQhard

A company deploys a model for fraud detection. They need to monitor for bias after deployment, specifically whether the model's false positive rate changes across demographic groups over time. Which SageMaker feature should they use?

A.SageMaker Model Monitor – Model Quality
B.SageMaker Model Monitor – Feature Attribution Drift
C.SageMaker Clarify (post-deployment bias monitoring)
D.SageMaker Model Monitor – Data Quality
AnswerC

SageMaker Clarify's post-deployment bias monitoring continuously evaluates live endpoint traffic, computing metrics such as false positive rate disparity across demographic groups over time. This directly satisfies the requirement to detect bias drift after deployment, which static pre-training analysis cannot address.

Why this answer

SageMaker Clarify provides post-deployment bias monitoring by analyzing predictions against ground truth labels for defined facets. It can track metrics like false positive rate differences over time.

51
MCQeasy

A company wants to reduce costs for a real-time inference endpoint that experiences predictable traffic spikes during business hours and low traffic at night. Which auto-scaling policy is MOST cost-effective while maintaining performance?

A.Step scaling based on CPU utilization
B.Manual scaling by the operations team
C.Scheduled scaling that increases instances before business hours and decreases after
D.Target tracking with a custom metric for response time
AnswerC

Scheduled scaling provisions capacity ahead of the known business-hours peak and scales down at night, so instances are never idle during predictable low-traffic periods. This matches the predictable spike pattern directly, unlike reactive target-tracking, which lags demand and over-provisions.

Why this answer

Scheduled scaling directly aligns capacity with the predictable traffic pattern (business hours vs. night), allowing you to proactively add instances before demand increases and remove them afterward. This avoids the cost of over-provisioning during low-traffic periods and the latency of reactive scaling, making it the most cost-effective approach for a known, recurring schedule.

Exam trap

The trap here is that candidates often choose reactive scaling options (like step scaling or target tracking) because they seem 'automated,' but they fail to recognize that for predictable, time-based traffic patterns, scheduled scaling is both more cost-effective and more performant than any reactive policy.

How to eliminate wrong answers

Option A is wrong because step scaling based on CPU utilization is reactive—it only adds capacity after a spike begins, which can cause latency or throttling during the initial surge, and it may keep instances running longer than needed due to cooldown periods, increasing cost. Option B is wrong because manual scaling by the operations team is error-prone, requires 24/7 staffing, and cannot react quickly enough to maintain performance during sudden traffic changes, leading to either over-provisioning or under-provisioning. Option D is wrong because target tracking with a custom metric for response time is also reactive and may cause oscillations (hunting) as the system tries to maintain a target, and it does not leverage the known schedule to pre-emptively scale, resulting in higher costs from delayed or excessive scaling actions.

52
MCQmedium

A healthcare analytics team trains models in SageMaker and stores artifacts in an S3 bucket that contains protected health information. An auditor asks how the team can prove which training dataset and container image produced the model currently deployed to production, and wants the evidence retained even if someone deletes the training job. Which SageMaker capability should the team rely on to capture and retain this metadata automatically?

A.SageMaker Model Registry, which stores model versions and their approval status but does not capture dataset or container provenance automatically.
B.SageMaker Experiments, which groups runs and logs metrics and parameters but does not persist a provenance graph after the trial components are deleted.
C.AWS CloudTrail management events, which record API calls such as CreateTrainingJob and CreateModel and can be queried for who performed each action.
D.SageMaker ML Lineage Tracking, which automatically records entities and associations such as datasets, training jobs, and model artifacts as the workflow runs.
AnswerD

ML Lineage Tracking automatically creates entities and associations for data, training jobs, and models, forming a queryable graph that links the deployed model back to its training dataset and container image. Because the lineage graph is retained independently of the training job's lifecycle, it provides durable evidence for the audit even if the job is deleted, satisfying the reproducibility requirement.

Why this answer

ML Lineage Tracking automatically builds a graph of entities and associations across the ML workflow, linking datasets, training jobs, and model artifacts. This graph persists independently of the training job, so the team can trace the deployed model back to its inputs and container image even after the job is deleted, which is exactly the durable provenance an auditor needs.

Exam trap

The trap here is assuming Model Registry or Experiments captures full provenance automatically, when lineage is the service that records dataset-to-model associations and retains them independently of the training job.

53
MCQmedium

A team uses SageMaker ML Lineage Tracking to capture the metadata of their ML workflow. They want to query the lineage to see which model version was trained from a specific dataset. Which Lineage Tracking entity represents the dataset?

A.Association
B.Action
C.Context
D.Artifact
AnswerD

In SageMaker Lineage Tracking, an artifact represents a specific versioned object or data resource, such as an S3 dataset version, produced or consumed by a trial component. Querying the lineage graph for the dataset therefore means locating the artifact entity.

Why this answer

In SageMaker ML Lineage Tracking, an Artifact represents a tangible object or data — datasets, models, model versions, and endpoints are all artifacts. The dataset is therefore represented as an Artifact, and lineage queries traverse associations between artifacts, actions, and contexts to trace which model version was trained from it.

Exam trap

MLA-C01 often tests whether candidates can distinguish the four lineage entity types — the common mistake is picking Association or Action because they appear in the lineage graph, but only Artifact represents the actual dataset object.

How to eliminate wrong answers

Option A is wrong because an Association is the relationship (edge) between two lineage entities — for example, the link between a training action and the dataset artifact — not the dataset itself. Option B is wrong because an Action represents an activity or step in the workflow, such as a training job, processing job, or model deployment, not the data consumed by it. Option C is wrong because a Context is a logical grouping of entities, such as an experiment, project, or model package group, used to organize lineage, not to represent a dataset.

54
MCQhard

A hospital deploys a model to predict patient readmission risk. To comply with regulations, they must ensure that the model's predictions do not show bias against any demographic group over time. Which service should they use for ongoing monitoring?

A.SageMaker Clarify
B.AWS Audit Manager
C.SageMaker Model Monitor
D.Amazon Macie
AnswerA

SageMaker Clarify provides bias detection with configurable metrics such as demographic parity difference, and its monitoring schedules run continuously against live endpoint traffic, satisfying the requirement for ongoing bias monitoring across demographic groups rather than one-off analysis.

Why this answer

SageMaker Clarify is the correct service because it is specifically designed to detect bias in ML model predictions and can be configured for ongoing monitoring. It provides bias metrics (e.g., difference in positive proportion, disparate impact) and can run on a schedule to continuously evaluate predictions against demographic groups, ensuring regulatory compliance over time.

Exam trap

The trap here is confusing SageMaker Model Monitor (which tracks data drift) with SageMaker Clarify (which tracks bias), leading candidates to choose Model Monitor because they think 'monitoring' covers all aspects of model health, but bias detection requires a separate, specialized tool.

How to eliminate wrong answers

Option B (AWS Audit Manager) is wrong because it is designed to audit AWS resource usage and compliance against frameworks (e.g., SOC 2, PCI DSS), not to monitor ML model bias. Option C (SageMaker Model Monitor) is wrong because it focuses on detecting data drift and feature distribution changes, not bias in predictions against demographic groups. Option D (Amazon Macie) is wrong because it is a data security service that discovers and protects sensitive data using machine learning, not a tool for monitoring model bias.

55
MCQeasy

A machine learning engineer wants to deploy a pre-trained foundation model for text summarization using SageMaker JumpStart. Which of the following is a primary cost consideration when deploying such a model?

A.The cost of fine-tuning the model on custom data
B.The cost of GPU instances required for low-latency inference
C.The cost of data transfer for inference requests
D.The cost of storing the model artifacts in S3
AnswerB

JumpStart foundation models are large and require accelerated compute, so GPU instance hours dominate deployment cost. Low-latency inference demands continuously running GPU capacity rather than serverless or CPU options, making the instance type and count the primary cost consideration for this deployment.

Why this answer

When deploying a pre-trained foundation model via SageMaker JumpStart, the model is already trained, so fine-tuning cost is optional and not primary. The main ongoing cost is the compute instance used for inference, especially GPU instances needed for low-latency, high-throughput text summarization. Data transfer for inference requests is typically negligible compared to compute, and S3 storage for model artifacts is a minor one-time cost.

Exam trap

MLA-C01 often tests the misconception that data transfer or storage costs dominate ML deployment, when in fact compute instances, especially GPUs, are the primary cost driver for inference.

How to eliminate wrong answers

Option A is wrong because fine-tuning is not required for deploying a pre-trained model; it's an optional step that incurs separate training costs. Option C is wrong because data transfer for inference requests is usually small and often free within the same region, not a primary cost driver. Option D is wrong because storing model artifacts in S3 is inexpensive and a one-time cost, not the main ongoing expense.

56
MCQmedium

A team wants to use SageMaker Clarify to monitor bias in their production model predictions. They have configured a bias drift monitor. What does SageMaker Clarify compare to detect bias drift?

A.Current input data distribution against the training data distribution
B.Current bias metrics against a baseline bias metrics computed from training data
C.Current SHAP feature attributions against baseline SHAP values
D.Current predictions against ground truth labels collected in real-time
AnswerB

SageMaker Clarify's bias drift monitor compares bias metrics computed on current production data against baseline bias metrics derived from the training dataset. This satisfies the stem's requirement to detect drift by quantifying divergence from the original training distribution, flagging when live predictions deviate from the model's established fairness baseline.

Why this answer

SageMaker Clarify bias drift monitoring compares the current bias metrics (e.g., disparate impact) computed on live data against a baseline bias metric computed from the training data. This detects if bias has drifted over time.

Exam trap

MLA-C01 often tests the difference between data drift, bias drift, and feature attribution drift; candidates may confuse bias drift with data drift.

How to eliminate wrong answers

Option A is wrong because comparing input data distributions is for data drift, not bias drift; bias drift focuses on bias metrics. Option C is wrong because SHAP feature attributions are for explainability, not bias drift; comparing SHAP values is for feature attribution drift. Option D is wrong because comparing predictions against ground truth labels is for model quality drift, not bias drift.

57
MCQeasy

A healthcare analytics team trains models in Amazon SageMaker and needs an immutable, queryable record of which dataset version and training job produced each registered model version, so an auditor can trace a deployed model back to its inputs months later. Which SageMaker capability should they rely on?

A.SageMaker ML Lineage Tracking, which automatically records entities such as datasets, training jobs, and model package versions and their relationships.
B.SageMaker Model Monitor, which schedules jobs that compare production traffic against a baseline and emit violations to CloudWatch.
C.SageMaker Experiments, which groups training runs into experiments and trials so you can compare their metrics side by side.
D.SageMaker Debugger, which captures tensors and system metrics during training and can halt a job when a rule is triggered.
AnswerA

ML Lineage Tracking creates lineage entities and associations for artifacts, trials, and actions as the workflow runs, so an auditor can traverse from a model package version back to the training job and the input dataset. It is queryable through the SageMaker API and integrates with the model registry, matching the traceability requirement without custom bookkeeping.

Why this answer

ML Lineage Tracking is the SageMaker feature that records artifacts, trials, actions, and their associations automatically as training and registration proceed, producing a queryable graph from a model package version back to the training job and dataset. Other SageMaker capabilities address monitoring, training-run observability, or run comparison, none of which yields the end-to-end provenance record the audit requires.

Exam trap

The trap here is confusing experiment tracking, which compares runs, with lineage tracking, which records the provenance relationships an auditor needs.

58
Multi-Selectmedium

A company wants to track the lineage of their ML models for reproducibility and auditability. Which THREE services or features should they use together to achieve this? (Choose THREE.)

Select 3 answers
A.Amazon S3 versioning
B.SageMaker Experiments
C.AWS CloudTrail
D.SageMaker ML Lineage Tracking
E.AWS Config
AnswersA, B, D

Amazon S3 versioning preserves every object revision, so each training dataset and model artefact retains an immutable, retrievable history. This satisfies the lineage and auditability constraint by preventing overwrites, letting auditors trace exactly which data version produced a given model. Combined with SageMaker ML Lineage Tracking and Model Registry, it completes the reproducibility requirement.

Why this answer

Amazon S3 versioning (A) is correct because it preserves every version of the datasets and model artifacts stored in S3, so a given training run can be tied to the exact immutable object version used, which is essential for reproducibility and auditability. SageMaker Experiments (B) is correct because it records experiment runs, trial components, parameters, metrics, and input/output artifacts, giving the structured record of each training attempt needed to reproduce results. SageMaker ML Lineage Tracking (D) is correct because it automatically creates and stores entities and relationships (trials, trial components, artifacts, contexts, actions) forming a queryable lineage graph from data through training to the deployed model.

AWS CloudTrail (C) only logs API activity and control-plane events for auditing who did what, not the data/model lineage relationships, so it does not by itself provide reproducibility lineage. AWS Config (E) evaluates and records resource configuration compliance over time, which is unrelated to tracking ML artifact provenance and experiment history.

Exam trap

The trap here is that candidates confuse AWS CloudTrail or AWS Config with lineage tracking because both deal with 'tracking' and 'auditing,' but they operate at the infrastructure/API level, not at the ML experiment and artifact relationship level required for model lineage.

59
MCQeasy

A company wants to reduce costs for a SageMaker real-time endpoint that has variable traffic. Which feature allows the endpoint to automatically adjust instance count based on demand?

A.SageMaker Savings Plans
B.SageMaker Inference Recommender
C.SageMaker Model Monitor
D.Auto Scaling for SageMaker endpoints
AnswerD

Application Auto Scaling for SageMaker endpoints adjusts the instance count of a production variant in response to CloudWatch metrics such as InvocationsPerInstance, matching capacity to variable demand. This satisfies the requirement to scale automatically while preserving performance during peaks.

Why this answer

Auto Scaling for SageMaker endpoints is the native capability that dynamically adjusts the number of instances behind a real-time endpoint based on CloudWatch metrics such as InvocationsPerInstance or ModelLatency. It uses Application Auto Scaling policies (target tracking or step scaling) to add instances during traffic spikes and remove them during lulls, directly reducing cost for variable workloads. Savings Plans and Inference Recommender do not perform runtime scaling.

Exam trap

MLA-C01 often tests the confusion between cost-optimization features — candidates pick Savings Plans (a billing discount) when the question is actually about dynamic capacity adjustment via autoscaling.

How to eliminate wrong answers

Option A is wrong because SageMaker Savings Plans are a pricing/billing commitment model (1- or 3-year spend commitment) that discounts usage but does not change instance count in response to demand. Option B is wrong because Inference Recommender is a one-time recommendation tool that benchmarks instance types and configurations to suggest the best deployment option — it does not perform ongoing autoscaling. Option C is wrong because Model Monitor detects data drift, bias, and quality issues in production traffic; it has no role in scaling capacity.

60
MCQmedium

A financial services company has a SageMaker real-time endpoint serving a fraud detection model. Compliance requires that all inference requests and responses be logged with the ability to detect anomalous input feature distributions over time. The team wants a managed solution that captures request/response payloads to Amazon S3 and automatically computes statistics and constraints against a baseline. Which combination of SageMaker features should they enable?

A.Configure the endpoint to write inference logs to Amazon CloudWatch Logs and create a custom Lambda function to parse and analyze the logs.
B.Enable SageMaker Model Monitor data capture on the endpoint and schedule a monitoring job using the baseline constraints and statistics.
C.Enable SageMaker Debugger on the endpoint and configure rules to monitor for data drift.
D.Enable AWS CloudTrail data events on the S3 bucket used by the endpoint and configure Amazon CloudWatch Logs metric filters.
AnswerB

SageMaker Model Monitor data capture records request and response payloads to S3, and the monitoring schedule evaluates them against a baseline to detect drift and anomalies. This directly satisfies the compliance need to log inference traffic and detect anomalous feature distributions without custom code.

Why this answer

SageMaker Model Monitor is the managed service for monitoring deployed models. Data capture stores inference request and response data in S3, and monitoring schedules compare that data to a baseline to detect data drift, model quality issues, bias, and feature attribution drift. This provides both the audit trail and the automated anomaly detection required.

Exam trap

The trap here is assuming that CloudWatch Logs or CloudTrail alone can provide managed drift detection, when they only capture logs or API activity and require custom analysis.

61
MCQhard

A machine learning engineer manages a SageMaker Model Monitor schedule for a real-time endpoint. The monitor's baseline was computed from a training dataset with a categorical feature named region. In production, a new category value appears that was never seen in training, and the monitor begins reporting violations. The engineer wants the monitor to flag only the appearance of unknown categories without treating normal distribution shifts in known categories as violations. Which approach should the engineer take?

A.Recreate the baseline with a larger sample that includes the new category, then set the monitor's comparison threshold to zero for all features.
B.Disable the constraint checks for the feature and rely solely on the monitor's distribution comparison to detect the new category.
C.Enable the monitor's constraint on the categorical feature so that only values present in the baseline are allowed, and keep distribution comparison thresholds relaxed for that feature.
D.Increase the monitor's sampling percentage to one hundred percent and lower the KMS key rotation period so the monitor can read all incoming records.
AnswerC

Model Monitor emits constraints from the baseline that list allowed categorical values, so a value absent from the baseline violates the constraint and is flagged as an unknown category. Keeping the distribution comparison threshold relaxed for that feature prevents normal frequency shifts among known categories from generating violations, which is exactly the separation the engineer is asking for.

Why this answer

Model Monitor separates two kinds of checks. Constraints, derived from the baseline statistics, enumerate allowed values for categorical features, so a value never seen in training violates the constraint and is flagged as unknown. Distribution comparison measures frequency drift among values that exist in the baseline.

Keeping constraints enabled while relaxing distribution thresholds isolates unknown-category detection from ordinary frequency shifts.

Exam trap

The trap here is assuming that distribution comparison automatically detects brand-new categorical values, when the explicit allowed-value check that catches them is the constraint check.

62
MCQmedium

A company uses SageMaker JumpStart to deploy a foundation model for a summarization task. They want to minimize costs while still meeting a latency requirement of under 2 seconds. Which option should they consider?

A.Use SageMaker Inference Recommender to select the cheapest instance that meets latency
B.Deploy the model on a serverless endpoint
C.Enable auto-scaling to handle variable traffic
D.Use the largest GPU instance to ensure fast inference
AnswerA

SageMaker Inference Recommender runs automatic load tests across instance types and returns the cheapest instance satisfying the sub-2-second latency constraint, directly optimising the cost-versus-latency trade-off. Manual instance selection risks over-provisioning or breaching latency, so this satisfies both the cost-minimisation and latency requirements in the stem.

Why this answer

SageMaker Inference Recommender runs load tests against your model on various instance types and provides latency and cost metrics. By selecting the cheapest instance that still meets the sub-2-second latency requirement, you directly minimize cost while satisfying the performance constraint. This is the most systematic and cost-effective approach for this scenario.

Exam trap

A common misconception is that serverless endpoints are always the cheapest option, but for latency-sensitive workloads with large models, the cold-start overhead and lack of guaranteed compute resources make them unsuitable. Inference Recommender is the correct tool for cost-latency trade-off analysis.

How to eliminate wrong answers

Option B is wrong because serverless endpoints have a cold-start latency that can exceed 2 seconds, especially for large foundation models, and they do not guarantee consistent sub-2-second inference under variable traffic. Option C is wrong because auto-scaling handles variable traffic but does not reduce per-invocation cost or latency; it only adjusts capacity, and the chosen instance type still determines base latency and cost. Option D is wrong because using the largest GPU instance is unnecessarily expensive and may provide excess compute capacity that is not needed to meet a 2-second latency requirement, violating the cost-minimization goal.

63
Multi-Selecthard

An ML team uses SageMaker to deploy a model for real-time inference. They want to monitor and improve cost efficiency. Which THREE actions should they take? (Select THREE.)

Select 3 answers
A.Use SageMaker Inference Recommender to find the optimal instance type and count
B.Enable auto-scaling to adjust the number of instances based on demand
C.Create a CloudWatch dashboard to monitor endpoint latency
D.Use SageMaker Managed Spot Training for endpoint instances
E.Purchase SageMaker Savings Plans for a discounted rate
AnswersA, B, E

Inference Recommender benchmarks candidate instance types and counts against the model's actual traffic and latency requirements, recommending the most cost-effective configuration. This directly addresses right-sizing, which is the primary lever for reducing real-time inference cost before scaling or commitment discounts.

Why this answer

Option A is correct because SageMaker Inference Recommender runs load tests and benchmarks to recommend the optimal instance type and instance count for a real-time endpoint, directly improving cost efficiency by avoiding over-provisioning. Option B is correct because configuring auto-scaling on a SageMaker endpoint adjusts the number of instances to match traffic demand, so the team pays only for capacity actually needed during peaks and troughs. Option E is correct because SageMaker Savings Plans offer discounted pricing (up to 64% off) in exchange for a committed hourly spend, reducing the cost of steady-state real-time inference workloads.

Option C is not a cost-efficiency action; a CloudWatch dashboard for latency is an observability tool and does not by itself reduce spend. Option D is incorrect because Managed Spot Training applies to training jobs, not to real-time inference endpoint instances, which cannot use spot capacity for persistent endpoints.

Exam trap

The trap here is that candidates confuse monitoring (Option C) with cost optimization, or they mistakenly apply Spot Training (Option D) to inference endpoints, not realizing that Spot instances are only supported for training and not for real-time inference due to interruption risk.

64
Multi-Selecthard

A retail company runs a SageMaker real-time endpoint serving a demand forecasting model. Security policy requires that all inference requests travel over the AWS private network and never traverse the public internet, and that the endpoint cannot be invoked from outside the company VPC. The endpoint already uses a customer-managed KMS key for volume encryption. Which TWO configurations should the engineer apply to meet these requirements? (Choose two.)

Select 2 answers
A.Configure the endpoint with EnableNetworkIsolation set to true so the container cannot make outbound network calls.
B.Enable request and response data capture on the endpoint and store the captures in an S3 bucket with a bucket policy that allows only the VPC endpoint.
C.Set the endpoint's network access type to VPC-only by attaching the appropriate VPC configuration so the endpoint is reachable only from the specified subnets and security groups.
D.Attach an IAM resource policy to the endpoint that denies all principals except the account root, and enable AWS CloudTrail data events on the endpoint.
E.Create an interface VPC endpoint (AWS PrivateLink) for the SageMaker runtime in the VPC and invoke the endpoint through that endpoint.
AnswersC, E

Configuring the endpoint with a VPC configuration and restricting network access to VPC-only ensures the endpoint is accessible only through the specified subnets and security groups inside the VPC. This removes public invocation paths. Together with a PrivateLink interface endpoint for the runtime API, all inference traffic stays private and external invocation is blocked, meeting the stated policy.

Why this answer

Keeping inference traffic on the AWS private network and blocking external invocation requires two complementary controls. An interface VPC endpoint for the SageMaker runtime lets InvokeEndpoint calls resolve to a private IP inside the VPC, and configuring the endpoint for VPC-only network access restricts reachability to the specified subnets and security groups. IAM policies, network isolation, and data capture do not change the request path or prevent public invocation.

Exam trap

The trap here is treating container network isolation or an IAM resource policy as sufficient for private-only invocation, when the request path and endpoint reachability are governed by PrivateLink and the endpoint's VPC network access configuration.

65
MCQmedium

A machine learning engineer observes that model performance on a SageMaker endpoint has degraded over the past week. Ground truth labels are available with a 2-day delay. The engineer wants to automatically trigger a retraining pipeline when prediction quality drops below an acceptable threshold. Which approach is most appropriate?

A.Use SageMaker Model Monitor - Model Quality Monitor with ground truth, create a CloudWatch alarm on the metric, and trigger an AWS Lambda function to start retraining
B.Manually evaluate the model weekly and retrain as needed
C.Use SageMaker Model Monitor - Data Quality Monitor to detect drift, then trigger retraining
D.Use SageMaker Clarify to monitor bias drift and trigger retraining
AnswerA

Model Quality Monitor ingests the delayed ground truth from S3, computes quality metrics, and publishes them to CloudWatch. An alarm on the threshold invokes Lambda, which starts the retraining pipeline, fully automating detection and remediation without manual intervention.

Why this answer

SageMaker Model Monitor's Model Quality Monitor is specifically designed to compare model predictions against ground truth labels (available with a 2-day delay) and track metrics like accuracy, precision, recall, or F1 score. You can configure a CloudWatch alarm on a metric such as 'accuracy' dropping below a threshold, which triggers an AWS Lambda function to start the retraining pipeline. This automates the detection of prediction quality degradation and the retraining response without manual intervention.

Exam trap

The trap here is that candidates confuse Data Quality Monitor (which monitors input data drift) with Model Quality Monitor (which monitors prediction accuracy against ground truth), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option B is wrong because manually evaluating the model weekly is not automated and does not meet the requirement to automatically trigger retraining when prediction quality drops; it introduces latency and human error. Option C is wrong because Data Quality Monitor detects drift in input data distribution (e.g., feature skew), not in prediction quality against ground truth labels, so it cannot directly measure model performance degradation. Option D is wrong because SageMaker Clarify is used for bias detection and explainability, not for monitoring prediction quality or triggering retraining based on performance metrics.

66
MCQeasy

A team wants to monitor the number of requests and latency of their SageMaker endpoint using a unified dashboard. Which AWS service should they use to create a custom dashboard with these metrics?

A.Amazon CloudWatch Dashboards
B.AWS CloudTrail
C.AWS Config
D.SageMaker Studio
AnswerA

CloudWatch Dashboards natively aggregate endpoint metrics such as Invocations and ModelLatency into a single custom view, satisfying the unified dashboard requirement without extra tooling. SageMaker automatically publishes these metrics to CloudWatch, so no custom instrumentation is needed.

Why this answer

Amazon CloudWatch Dashboards is the native AWS service for building custom, unified dashboards from CloudWatch metrics. SageMaker automatically publishes endpoint metrics such as Invocations, ModelLatency, OverheadLatency, and Invocation4XXErrors to CloudWatch, so a CloudWatch dashboard can display requests and latency side by side.

Exam trap

MLA-C01 often tests the confusion between CloudWatch (metrics/monitoring) and CloudTrail (API auditing) — candidates pick CloudTrail when the question asks for a metrics dashboard.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API activity (who called what, when) for auditing — it does not store or visualize performance metrics like latency or request counts. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not runtime performance metrics. Option D is wrong because SageMaker Studio is an IDE/notebook environment for building and training models; it does not provide a metrics dashboard service.

67
MCQmedium

A company wants to automatically trigger a retraining pipeline when concept drift is detected in their deployed model. Which combination of services should they use?

A.SageMaker Model Monitor → Lambda
B.CloudWatch Events → SageMaker Training Job
C.SageMaker Model Monitor → CloudWatch Alarm → SNS → Lambda
D.SageMaker Clarify → SNS → Step Functions
AnswerC

SageMaker Model Monitor detects drift and emits metrics; CloudWatch alarms on those thresholds, SNS fans out the notification, and Lambda invokes the retraining pipeline. This chain satisfies the requirement to trigger retraining automatically upon concept drift detection without manual intervention.

Why this answer

SageMaker Model Monitor detects concept drift by analyzing model predictions against a baseline, then publishes metrics to CloudWatch. A CloudWatch Alarm triggers when drift exceeds a threshold, sending a notification via SNS to invoke a Lambda function, which starts the retraining pipeline. This end-to-end integration ensures automated, event-driven retraining without manual intervention.

Exam trap

A common exam trap is the distinction between monitoring services (Model Monitor for drift vs. Clarify for bias) and the correct event chain (Model Monitor → CloudWatch → SNS → Lambda) versus incomplete chains like direct Lambda invocation or using the wrong service for drift detection.

How to eliminate wrong answers

Option A is wrong because SageMaker Model Monitor alone cannot directly invoke Lambda; it requires CloudWatch Alarms and SNS to bridge the monitoring output to Lambda execution. Option B is wrong because CloudWatch Events (now EventBridge) can trigger SageMaker Training Jobs, but it lacks the concept drift detection capability provided by Model Monitor, so it cannot determine when retraining is needed. Option D is wrong because SageMaker Clarify is designed for bias detection and explainability, not concept drift monitoring; using SNS and Step Functions without drift detection would not trigger retraining based on model performance degradation.

68
Multi-Selectmedium

A machine learning team needs to monitor a deployed model for both data drift and concept drift. Which TWO approaches should they implement? (Select TWO.)

Select 2 answers
A.Set up SageMaker Model Monitor for data quality monitoring
B.Use SageMaker Clarify for bias monitoring
C.Configure CloudWatch Logs Insights to query inference logs
D.Set up SageMaker Model Monitor for model quality monitoring
E.Enable SageMaker Debugger during inference
AnswersA, D

Data quality monitoring compares live inference inputs against the training baseline, computing per-feature distribution statistics to detect data drift — changes in input feature distributions. This directly satisfies the stem's data drift requirement, while concept drift needs the separate model quality monitor.

Why this answer

Option A is correct because SageMaker Model Monitor's data quality monitoring detects data drift by comparing the statistical properties of incoming inference requests against the baseline statistics captured from the training dataset, alerting when feature distributions shift. Option D is correct because Model Monitor's model quality monitoring evaluates concept drift by comparing predicted values against actual ground-truth labels, tracking metrics such as accuracy, precision, and recall over time to detect degradation in the model's real-world performance. Option B is not correct because SageMaker Clarify is used for bias detection and explainability (e.g., SHAP values), not for detecting data or concept drift.

Option C is not correct because CloudWatch Logs Insights merely queries and analyzes log data; it does not provide built-in drift detection statistics or baseline comparisons. Option E is not correct because SageMaker Debugger is designed to debug training jobs by capturing tensors and monitoring training metrics, not to monitor deployed models for drift.

Exam trap

The trap is assuming a single monitoring approach covers both drift types; candidates often pick Clarify or Debugger because they sound like monitoring tools, but only Model Monitor's data quality and model quality modes address data and concept drift respectively.

69
MCQmedium

A data scientist deploys a model and wants to monitor the endpoint's invocation latency. They notice that the CloudWatch metric 'ModelLatency' is high, but 'OverheadLatency' is low. Which statement correctly interprets these metrics?

A.The SageMaker overhead is causing the delay; check endpoint configuration
B.The model inference time is the bottleneck; consider optimizing the model or using a faster instance type
C.The endpoint is overloaded; increase the number of instances
D.The network latency is high; move the endpoint closer to clients
AnswerB

ModelLatency measures time spent inside the model container performing inference, while OverheadLatency covers SageMaker platform overhead. High ModelLatency with low OverheadLatency isolates the model itself as the bottleneck, so optimising the model or using a faster instance helps.

Why this answer

The 'ModelLatency' metric measures the time taken by the SageMaker model container to process a single request, including inference and any preprocessing/postprocessing within the container. 'OverheadLatency' measures the time spent on SageMaker infrastructure (e.g., network I/O, request queuing, and response handling). When ModelLatency is high and OverheadLatency is low, the bottleneck is clearly the model inference time itself, not the infrastructure overhead. Therefore, optimizing the model (e.g., quantization, pruning) or upgrading to a faster instance type (e.g., GPU vs.

CPU) is the correct remediation.

Exam trap

The trap here is that candidates confuse 'ModelLatency' with overall endpoint latency and assume any high latency is due to infrastructure or scaling issues, when in fact the metric explicitly isolates the model's own inference time from overhead.

How to eliminate wrong answers

Option A is wrong because high ModelLatency with low OverheadLatency indicates the delay is inside the model container, not in SageMaker's infrastructure overhead; checking endpoint configuration would not address the model's own inference time. Option C is wrong because endpoint overload typically manifests as increased OverheadLatency (due to request queuing) or increased Invocations and 5xx errors, not as isolated high ModelLatency with low OverheadLatency. Option D is wrong because network latency is captured within OverheadLatency, not ModelLatency; moving the endpoint closer to clients would reduce OverheadLatency but would not affect the model's inference computation time.

70
MCQeasy

A small team runs a SageMaker real-time endpoint in production. They want a low-effort way to know when the endpoint's invocations are failing so they can react quickly, and they want the alert delivered to their on-call channel. Which approach requires the least custom code?

A.Use AWS CloudTrail to capture InvokeEndpoint API calls and create an Amazon EventBridge rule that notifies the on-call channel when errors occur.
B.Create an Amazon CloudWatch alarm on the endpoint's ModelLatency and Invocation4XXErrors metrics, and route the alarm to Amazon SNS with an email or chat subscription.
C.Enable SageMaker Model Monitor on the endpoint and configure the monitor to raise an alarm when constraint violations are detected.
D.Subscribe an AWS Lambda function to the endpoint's CloudWatch log group and have the function parse logs and publish to Amazon SNS when errors appear.
AnswerB

SageMaker automatically publishes endpoint metrics such as Invocations, Invocation4XXErrors, Invocation5XXErrors, and ModelLatency to CloudWatch without any instrumentation. Alarms on those metrics publish to an SNS topic that the on-call channel subscribes to, giving failure notification with essentially no custom code or additional services.

Why this answer

SageMaker endpoints emit CloudWatch metrics automatically, including invocation counts and 4XX and 5XX error metrics, so a CloudWatch alarm wired to an SNS topic gives failure notification without any custom instrumentation. Model Monitor and log-parsing pipelines solve different problems and require substantially more configuration.

Exam trap

The trap here is reaching for CloudTrail or Model Monitor to detect invocation failures, when the endpoint's built-in CloudWatch error metrics already expose them directly.

71
MCQmedium

A machine learning engineer notices that the latency of a SageMaker endpoint has increased over time. They need to identify which component (model inference vs. pre/post-processing) contributes most to the latency. Which CloudWatch metrics should they examine?

A.Latency and ModelLatency
B.Invocations and 4XXError
C.5XXError and MemoryUtilization
D.ModelLatency and OverheadLatency
AnswerD

ModelLatency isolates time spent in model inference, while OverheadLatency captures pre- and post-processing plus queueing outside the model. Comparing both CloudWatch metrics attributes the latency increase to the correct component, satisfying the stem's diagnostic requirement.

Why this answer

SageMaker endpoints emit CloudWatch metrics that break down total latency into model inference time (ModelLatency) and the time spent in pre/post-processing (OverheadLatency). By comparing these two metrics, the engineer can pinpoint whether the bottleneck is in the inference code or in the custom preprocessing/postprocessing logic. Option D directly provides both metrics needed for this root-cause analysis.

Exam trap

The trap here is that candidates confuse the total Latency metric with a breakdown metric, assuming it alone can identify the bottleneck, when in fact only the pair of ModelLatency and OverheadLatency provides the necessary decomposition.

How to eliminate wrong answers

Option A is wrong because Latency is the total end-to-end response time, and ModelLatency alone only covers inference; together they do not isolate the pre/post-processing component. Option B is wrong because Invocations and 4XXError track request count and client-side errors, not latency breakdown. Option C is wrong because 5XXError indicates server-side failures and MemoryUtilization shows resource pressure, but neither metric decomposes latency into inference vs. overhead.

72
MCQmedium

A company uses SageMaker endpoints for real-time inference. They want to automatically scale the number of instances based on the number of outstanding requests. Which auto-scaling policy type should they choose?

A.Scheduled scaling
B.Step scaling
C.Target tracking scaling
D.Simple scaling
AnswerC

Target tracking scaling adjusts instance count to hold a chosen metric, such as SageMakerVariantInvocationsPerInstance, at a target value, which directly reflects outstanding request load. Step and scheduled policies react to fixed thresholds or times rather than demand.

Why this answer

Target tracking scaling is the correct choice because it lets you specify a target value for a metric — such as a custom metric for outstanding requests per instance — and SageMaker automatically adjusts instance count to keep that metric at the target. This is the recommended policy for metrics that correlate directly with capacity needs, like request backlog or invocations per instance. It handles both scale-out and scale-in automatically without manual threshold tuning.

Exam trap

MLA-C01 often tests the confusion between metric-driven and schedule-driven scaling — candidates who see 'outstanding requests' and pick scheduled or step scaling miss that target tracking is the AWS-recommended default for utilization metrics.

How to eliminate wrong answers

Option A is wrong because scheduled scaling is time-based (e.g., scale up at 9 AM), not metric-driven, so it cannot respond to fluctuating outstanding requests. Option B is wrong because step scaling requires you to define explicit CloudWatch alarm thresholds and step adjustments manually — it works but is more complex and less adaptive than target tracking. Option D is wrong because simple scaling is the older policy type that requires a cooldown period and manual alarm configuration; it is less responsive and not recommended for dynamic request-based scaling.

73
MCQeasy

A machine learning engineer needs to give a data scientist read-only access to the model artifacts, training metrics, and monitoring reports stored in a single Amazon S3 bucket used by a SageMaker project, while ensuring the data scientist cannot delete or overwrite any object. Which approach follows least-privilege practice?

A.Apply an S3 bucket policy that allows the data scientist's role s3:* on the bucket, and rely on S3 versioning to recover any deleted objects.
B.Attach the AmazonS3ReadOnlyAccess AWS managed policy to the data scientist's role so they can read any bucket in the account.
C.Attach an IAM policy to the data scientist's role granting s3:GetObject and s3:ListBucket scoped to the project bucket and its prefix, and deny s3:DeleteObject and s3:PutObject on the same resources.
D.Create a presigned URL for each object and distribute the URLs to the data scientist as needed.
AnswerC

Granting only GetObject and ListBucket on the specific bucket and prefix provides the required read access for artifacts, metrics, and monitoring reports. Explicitly denying delete and put operations removes any write capability that a broader managed policy might have granted, which aligns with least privilege and prevents accidental or deliberate modification of project data.

Why this answer

Least privilege for this scenario means a scoped identity policy that allows only object reads and bucket listing on the project bucket and prefix, with write and delete actions denied. Managed read-only policies are too broad across the account, wildcard bucket policies grant write access, and presigned URLs are transient and cannot support ongoing browsing of project outputs.

Exam trap

The trap here is reaching for a broad AWS managed read-only policy, which satisfies read access but violates least privilege by covering every bucket in the account.

74
MCQmedium

A company uses SageMaker Inference Recommender to select the optimal endpoint configuration. After running the recommender, they receive a recommendation for a specific instance type and initial instance count. What should they do next to optimize costs over time?

A.Use the recommended configuration without changes, as it is already optimal
B.Purchase a Savings Plan for the recommended instance type to reduce hourly cost
C.Set up auto-scaling with a target tracking policy based on the recommended metric
D.Manually adjust the instance count daily based on observed traffic
AnswerC

Inference Recommender only supplies a static instance type and count, so costs stay fixed regardless of traffic. A target tracking auto-scaling policy adjusts instance count dynamically against the recommended metric, matching capacity to actual load and eliminating idle spend over time.

Why this answer

Inference Recommender provides an initial right-sized instance type and count based on load testing, but traffic varies over time. Setting up auto-scaling with a target tracking policy (e.g., on InvocationsPerInstance or CPU utilization) lets the endpoint scale in during low traffic and out during peaks, optimizing cost continuously rather than paying for a static over-provisioned fleet.

Exam trap

The trap is treating the Inference Recommender output as a final, optimal configuration — candidates forget it is a starting point and that ongoing cost optimization requires auto-scaling to match actual traffic.

How to eliminate wrong answers

Option A is wrong because the recommendation is a starting point based on a specific load test — it does not adapt to changing traffic, so costs remain fixed even during idle periods. Option B is wrong because Savings Plans reduce the hourly rate but do not address over-provisioning; you still pay for instances you don't need. Option D is wrong because manual daily adjustment is operationally fragile, reactive, and not a scalable cost-optimization strategy compared to automated target tracking.

75
MCQeasy

A company uses SageMaker Studio for collaborative ML development. The security team requires that all SageMaker Studio notebooks run within a VPC and cannot access the public internet. Which configuration should the administrator set?

A.Enable VPC-only mode for the SageMaker Studio domain
B.Use SageMaker notebook instances instead of Studio
C.Apply an SCP that denies internet access for all IAM users
D.Set the SageMaker Studio domain to use a public subnet with a NAT Gateway
AnswerA

VPC-only mode removes direct internet access from the Studio domain, forcing all notebook traffic through the specified subnets and security groups. This satisfies the constraint that notebooks run within a VPC and cannot reach the public internet.

Why this answer

Enabling VPC-only mode for the SageMaker Studio domain ensures that all Studio notebooks and apps are launched within the specified VPC and cannot access the public internet. This mode enforces that all network traffic, including internet-bound traffic, is routed through the VPC, and it blocks direct internet access by default, meeting the security team's requirement.

Exam trap

The trap here is that candidates may confuse VPC-only mode with simply using a private subnet, but VPC-only mode is a specific SageMaker Studio domain setting that explicitly blocks all internet access, whereas a private subnet alone could still allow outbound traffic via a NAT Gateway or VPC endpoint.

How to eliminate wrong answers

Option B is wrong because using SageMaker notebook instances instead of Studio does not inherently enforce VPC-only internet restrictions; notebook instances can still be configured with public internet access unless explicitly blocked via VPC settings. Option C is wrong because an SCP that denies internet access for all IAM users is an organization-level policy that does not directly control the network configuration of SageMaker Studio notebooks; it would affect user permissions but not the VPC routing or internet access of the Studio environment. Option D is wrong because setting the SageMaker Studio domain to use a public subnet with a NAT Gateway would actually provide outbound internet access to the notebooks, which violates the requirement that notebooks cannot access the public internet.

Page 1 of 2 · 94 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ML Solution Monitoring, Maintenance, and Security questions.