Courseiva
easyMultiple Choice

MLA-C01 Practice Question: Refer to the exhibit

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "sagemaker:DescribeEndpoint",
        "sagemaker:ListEndpoints"
      ],
      "Resource": "*"
    }
  ]
}

Refer to the exhibit. A user is unable to invoke a SageMaker endpoint. The IAM policy shown is attached to the user. Which permission is missing to allow invocation?

⚠ Common exam trap

AWS often tests the distinction between read-only permissions (like `DescribeEndpoint` or `ListEndpoints`) and the specific action required to perform an operation, leading candidates to confuse metadata access with actual invocation capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sagemaker:InvokeEndpoint

To invoke a SageMaker endpoint, the user needs the `sagemaker:InvokeEndpoint` permission. The IAM policy shown lacks this action, which is required for making real-time inference requests to the endpoint. Without it, any attempt to call the endpoint via the SDK or CLI will fail with an access denied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    sagemaker:InvokeEndpoint

    Why this is correct

    The IAM policy lacks the sagemaker:InvokeEndpoint action, which is the specific permission required to call a SageMaker endpoint's inference API. Without it, every InvokeEndpoint request is denied regardless of any resource-level grants, so adding this action to the policy resolves the user's failure.

  • ✗

    sagemaker:DescribeEndpoint

    Why it's wrong here

    DescribeEndpoint returns endpoint metadata and is not required to send InvokeEndpoint requests; the missing action is sagemaker:InvokeEndpoint. It is tempting because describing resources is commonly bundled with using them, and would be needed for tooling that inspects endpoint status before invoking.

  • ✗

    sagemaker:CreateEndpoint

    Why it's wrong here

    CreateEndpoint provisions a new endpoint and does not permit calling an existing one; sagemaker:InvokeEndpoint is the action the user lacks. It is tempting because endpoint-related permissions sound interchangeable, and would be correct for a deployment role that must stand up endpoints.

  • ✗

    sagemaker:ListEndpoints

    Why it's wrong here

    ListEndpoints enumerates endpoints in the account and grants no invocation rights, so adding it leaves InvokeEndpoint absent. It is tempting because listing is often assumed to precede calling a resource, and would be correct for a user who must discover endpoint names rather than invoke them.

About these practice questions

One of 665 original MLA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MLA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MLA-C01 exam.