A financial services company must deploy a SageMaker endpoint that processes sensitive customer data. They require that all traffic between the endpoint and the model containers be encrypted, and that the endpoint cannot be accessed from outside a specific VPC. Which combination of settings should they use?
Trap 1: Use a private VPC and enable data encryption at rest using KMS
Encryption at rest does not encrypt inter-container traffic nor restrict access to the VPC.
Trap 2: Enable network isolation mode and inter-container traffic encryption
Network isolation prevents internet access but does not restrict endpoint access to the VPC; also, it does not encrypt inter-container traffic by itself.
Trap 3: Deploy the endpoint in a private subnet and use a VPC endpoint for…
A private subnet and VPC endpoint restrict API calls but do not encrypt inter-container traffic.
- A
Use a private VPC and enable data encryption at rest using KMS
Why it fails: Encryption at rest does not encrypt inter-container traffic nor restrict access to the VPC.
- B
Enable inter-container traffic encryption and configure the endpoint with VPC-only mode
Enabling inter-container traffic encryption satisfies the requirement that traffic between the endpoint and model containers be encrypted, while VPC-only mode ensures the endpoint cannot be accessed from outside the specified VPC. Together these settings meet both constraints: encryption in transit and network isolation.
- C
Enable network isolation mode and inter-container traffic encryption
Why it fails: Network isolation prevents internet access but does not restrict endpoint access to the VPC; also, it does not encrypt inter-container traffic by itself.
- D
Deploy the endpoint in a private subnet and use a VPC endpoint for SageMaker API
Why it fails: A private subnet and VPC endpoint restrict API calls but do not encrypt inter-container traffic.