easyMultiple Choice
MLA-C01 Practice Question: Refer to the exhibit
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"sagemaker:DescribeEndpoint",
"sagemaker:ListEndpoints"
],
"Resource": "*"
}
]
}Refer to the exhibit. A user is unable to invoke a SageMaker endpoint. The IAM policy shown is attached to the user. Which permission is missing to allow invocation?
⚠ Common exam trap
AWS often tests the distinction between read-only permissions (like `DescribeEndpoint` or `ListEndpoints`) and the specific action required to perform an operation, leading candidates to confuse metadata access with actual invocation capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
sagemaker:InvokeEndpoint
To invoke a SageMaker endpoint, the user needs the `sagemaker:InvokeEndpoint` permission. The IAM policy shown lacks this action, which is required for making real-time inference requests to the endpoint. Without it, any attempt to call the endpoint via the SDK or CLI will fail with an access denied error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
sagemaker:InvokeEndpoint
Why this is correct
The IAM policy lacks the sagemaker:InvokeEndpoint action, which is the specific permission required to call a SageMaker endpoint's inference API. Without it, every InvokeEndpoint request is denied regardless of any resource-level grants, so adding this action to the policy resolves the user's failure.
- ✗
sagemaker:DescribeEndpoint
Why it's wrong here
DescribeEndpoint returns endpoint metadata and is not required to send InvokeEndpoint requests; the missing action is sagemaker:InvokeEndpoint. It is tempting because describing resources is commonly bundled with using them, and would be needed for tooling that inspects endpoint status before invoking.
- ✗
sagemaker:CreateEndpoint
Why it's wrong here
CreateEndpoint provisions a new endpoint and does not permit calling an existing one; sagemaker:InvokeEndpoint is the action the user lacks. It is tempting because endpoint-related permissions sound interchangeable, and would be correct for a deployment role that must stand up endpoints.
- ✗
sagemaker:ListEndpoints
Why it's wrong here
ListEndpoints enumerates endpoints in the account and grants no invocation rights, so adding it leaves InvokeEndpoint absent. It is tempting because listing is often assumed to precede calling a resource, and would be correct for a user who must discover endpoint names rather than invoke them.
Go deeper
Related to this question
About these practice questions
One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.