mediumMultiple Choice
MLA-C01 SageMaker Endpoint VPC Configuration Practice Question
Exhibit
[ERROR] 2024-03-15 10:23:45,234 - botocore.exception.ConnectTimeoutError: Connect timeout on endpoint URL: "https://database.example.com:5432"
A SageMaker endpoint is logging an error when processing inference requests that require database access. What is the most likely cause?
⚠ Common exam trap
Some candidates might think that database connectivity issues are due to endpoint instance size or missing data capture configuration. However, the key for accessing external resources from SageMaker is VPC configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The endpoint lacks a VPC configuration with proper security groups
When a SageMaker endpoint needs to access an external database (e.g., Amazon RDS) during inference, it must be launched within a VPC that has proper security group and subnet configurations. If the endpoint is not in a VPC or the security groups do not allow outbound traffic to the database, the endpoint will be unable to connect, resulting in errors. The other options are less likely: data capture is for logging requests (A), instance size affects performance not connectivity (B), model compatibility affects deployment but not specifically database access (C).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data capture is not enabled
Why it's wrong here
Data capture records request and response payloads to Amazon S3; it does not grant network egress. The endpoint's failure stems from its VPC configuration, such as a missing NAT gateway or security group rule. Enabling data capture would be right when auditing model inputs and outputs for drift or bias.
- ✗
The endpoint instance type is too small
Why it's wrong here
Instance sizing affects compute capacity and latency, not the endpoint's ability to reach a database; the failure is network or permission related, such as missing VPC configuration or security group rules. It is tempting because undersized instances do cause timeouts, and would be correct if the error were resource exhaustion during inference.
- ✗
The model is not compatible with the instance
Why it's wrong here
Model–instance compatibility governs whether the container can load and run the artefact, not whether the endpoint can reach a database. The logged error concerns database access during inference, so the fault lies in network or credential configuration. Compatibility checks matter when selecting an instance type for a framework version or GPU requirement before deployment.
- ✓
The endpoint lacks a VPC configuration with proper security groups
Why this is correct
SageMaker endpoints run outside your VPC by default, so they cannot reach private database resources. Attaching a VPC configuration with appropriate security groups and subnets grants the endpoint network access, directly resolving the database connectivity failure during inference.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.