hardMultiple Choice
Model Governance Across AWS Accounts with SageMaker
A company's ML pipeline runs in multiple AWS accounts (dev, test, prod). They want to enforce that only approved models from a central Model Registry can be deployed to the production account. Which combination of services is MOST appropriate to implement this governance?
Quick Answer
The answer is AWS Organizations with SCPs, AWS CodePipeline with cross-account actions, and SageMaker Model Registry with approval status. This combination enforces multi-account governance for SageMaker models by using SCPs to block unauthorized deployment actions in the production account, CodePipeline to orchestrate the cross-account promotion of only approved model versions, and the Model Registry’s approval gate to ensure that only validated models proceed. On the AWS Certified Machine Learning Engineer Associate MLA-C01 exam, this scenario tests your understanding of how to combine identity-based policies with service-level approval workflows to separate duties across environments. A common trap is to suggest IAM roles alone, which lack the centralized enforcement that SCPs provide at the organization level. Remember the mnemonic “OSCAR” — Organizations, SCPs, CodePipeline, Approval, Registry — to recall the key services for governing model deployments across accounts.
⚠ Common exam trap
Test-takers frequently choose monitoring-focused options like A or C, mistakenly thinking that detecting non-approved deployments is sufficient, when the question explicitly requires enforcement (prevention), which demands a combination of policy-based controls (SCPs) and approval-gated pipelines (CodePipeline + Model Registry).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations with SCPs, AWS CodePipeline with cross-account actions, and SageMaker Model Registry with approval status.
It combines AWS Organizations with SCPs to enforce cross-account deployment policies, AWS CodePipeline with cross-account actions to orchestrate the pipeline across dev/test/prod accounts, and SageMaker Model Registry with approval status to gate deployments to only approved models. This ensures that only models with an 'Approved' status in the central registry can be deployed to the production account, meeting the governance requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config, Amazon GuardDuty, and AWS Security Hub.
Why it's wrong here
Config, GuardDuty and Security Hub detect and report drift, threats and findings; none blocks a deploy call. Enforcement needs an IAM/SCP condition keyed to the Model Registry approval state. These services suit continuous compliance auditing and threat detection, not pre-deployment authorisation gates.
- ✗
Amazon API Gateway, AWS Step Functions, and Amazon DynamoDB.
Why it's wrong here
API Gateway, Step Functions and DynamoDB can orchestrate an approval workflow and store state, but they sit outside the deployment path, so a direct SageMaker CreateModel call bypasses them. They fit building a custom approval portal, not enforcing cross-account deployment authorisation.
- ✗
AWS Service Catalog, AWS KMS, and AWS CloudTrail.
Why it's wrong here
Service Catalog governs provisioned products, KMS encrypts artefacts and CloudTrail records API activity after the fact. None evaluates Model Registry approval status at CreateModel time. This combination suits portfolio-level provisioning control and audit trails, not blocking unapproved model deployment.
- ✓
AWS Organizations with SCPs, AWS CodePipeline with cross-account actions, and SageMaker Model Registry with approval status.
Why this is correct
SCPs in AWS Organizations enforce that only approved registry models deploy to production, while CodePipeline cross-account actions move artefacts between accounts. The Model Registry approval status gates deployment, satisfying the central governance constraint across dev, test and prod accounts.
- ✗
AWS CloudFormation StackSets, Amazon EventBridge, and AWS Lambda.
Why it's wrong here
StackSets, EventBridge and Lambda can react to events and deploy templates, but they act after or alongside deployment rather than denying it. A principal can still call CreateModel directly. This suits automated cross-account infrastructure rollout, not authorisation enforcement tied to registry approval.
Go deeper
Related to this question
About these practice questions
This MLA-C01 question is part of Courseiva's 665-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MLA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company operates multiple AWS accounts with SageMaker workloads. They need to implement governance and security controls for model monitoring and maintenance. Which THREE actions should they take to meet compliance requirements?
hard- ✓ A.Deploy a SageMaker model registry in a centralized account.
- ✓ B.Use AWS CloudTrail to log all API calls to SageMaker and S3.
- C.Enable VPC Flow Logs for SageMaker notebooks.
- D.Use IAM roles with cross-account trust policies for all SageMaker endpoints.
- ✓ E.Use AWS Config rules to enforce encryption of model artifacts.
Why A: Option A is correct because a SageMaker Model Registry deployed in a centralized account provides a single governance point for cataloging, versioning, and approving models across multiple AWS accounts, which is essential for compliance and maintenance oversight. Option B is correct because AWS CloudTrail records all API activity, including calls to SageMaker and S3, giving the audit trail required to demonstrate who accessed or modified models and data. Option E is correct because AWS Config rules can continuously evaluate model artifacts in S3 for required encryption settings and flag or remediate noncompliant resources, directly enforcing a compliance control. Option C is not required because VPC Flow Logs capture network traffic metadata for notebooks, which is useful for network troubleshooting but does not address model monitoring or maintenance governance. Option D is not required because cross-account IAM trust policies for endpoints are an access mechanism, not a governance or compliance control, and the question asks for monitoring and maintenance actions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.