Skip to content
BytePatterns

MLA-C02 · Domain 4: Operating, Monitoring, and Securing ML and AI Solutions · 24% of the exam

Task 4.3: Secure ML and AI workloads and model endpoints.

Least privilege IAM for people, pipelines and endpoints, network isolation in a VPC, encryption, audit with CloudTrail and Config, scanning code and images, the credentials used to call foundation models, and protecting sensitive data with Amazon Bedrock Guardrails.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A production web service will call Amazon Bedrock using a Bedrock API key as a bearer token. Security requires that the key expire within hours and carry no more permissions than the service's existing IAM role. Which credential should the ML engineer use?

  1. AA short-term Bedrock API key from the service's IAM role
  2. BA long-term Bedrock API key with a one-year expiration
  3. CThe access keys of the account root user
  4. DAn IAM user access key shared by all services
Show the answer and why
  • AA short-term Bedrock API key from the service's IAM role

    Correct

    Short-term API keys last up to 12 hours or the session duration, inherit the permissions of the IAM principal that generated them, and are recommended for production.

  • BA long-term Bedrock API key with a one-year expiration

    Incorrect

    Long-term keys last until their configured expiration and create an IAM user with attached policies. AWS recommends them only for exploration.

  • CThe access keys of the account root user

    Incorrect

    Root user credentials have full access to the account and should not be used for everyday work, let alone embedded in an application.

  • DAn IAM user access key shared by all services

    Incorrect

    Long-lived shared keys break least privilege and are hard to rotate. Temporary credentials tied to a role are the recommended practice.

Bedrock API keys come in two kinds. Short-term keys inherit the caller's IAM permissions and expire within hours, which fits production. Long-term keys are for exploration.

Question 2 · choose 1

A SageMaker AI training job for one project must read data only from s3://ml-data/fraud/train/ and write its model artifacts only to s3://ml-data/fraud/models/. Today the job's execution role has the AmazonS3FullAccess managed policy. What is the most appropriate change?

  1. AKeep AmazonS3FullAccess but tag the job with the project name
  2. BAttach the AmazonSageMakerFullAccess managed policy as well
  3. CA policy allowing only reads on the train prefix and writes on models
  4. DMake the train prefix public so the job needs no S3 permissions
Show the answer and why
  • AKeep AmazonS3FullAccess but tag the job with the project name

    Incorrect

    Tags do not limit what an attached policy allows. The role could still read and write every bucket in the account.

  • BAttach the AmazonSageMakerFullAccess managed policy as well

    Incorrect

    Adding a broad managed policy grants even more access instead of less.

  • CA policy allowing only reads on the train prefix and writes on models

    Correct

    IAM best practice is to grant least privilege: only the actions the job needs, only on the resources it needs. Scoping the execution role's S3 permissions to the two prefixes does exactly that.

  • DMake the train prefix public so the job needs no S3 permissions

    Incorrect

    Public data access exposes training data to anyone and removes control instead of adding it.

The execution role is what a SageMaker AI job uses to reach other AWS resources. Give it exactly the S3 actions and prefixes the job needs.

Question 3 · choose 1

An MLOps pipeline builds custom inference container images, pushes them to Amazon ECR, and keeps its training and inference code in a Git repository. The security team wants both the images and the source code scanned automatically for known vulnerabilities, with findings in one place. What should the ML engineer turn on?

  1. AAmazon Macie automated discovery on the artifact bucket
  2. BAWS Config rules evaluated against the ECR repositories
  3. CA CloudTrail trail that records every ECR push and pull
  4. DAmazon Inspector, with ECR image scanning and Code Security
Show the answer and why
  • AAmazon Macie automated discovery on the artifact bucket

    Incorrect

    Macie discovers sensitive data such as PII in S3 objects. It does not find software vulnerabilities in images or code.

  • BAWS Config rules evaluated against the ECR repositories

    Incorrect

    Config checks how resources are configured, not whether the packages inside an image or the code have known vulnerabilities.

  • CA CloudTrail trail that records every ECR push and pull

    Incorrect

    CloudTrail records who pushed or pulled images. It does not inspect what is inside them.

  • DAmazon Inspector, with ECR image scanning and Code Security

    Correct

    Amazon Inspector scans container images in Amazon ECR for operating system and programming language package vulnerabilities, and its Code Security feature scans first-party code, third-party dependencies and infrastructure as code in your repositories.

Vulnerability scanning in ML pipelines covers both images and code, and Amazon Inspector does both. Macie, Config and CloudTrail answer different security questions.

Question 4 · choose 1

A compliance rule says every SageMaker AI endpoint configuration must specify an AWS KMS key. The security team wants continuous, account-wide reporting of any endpoint configuration that does not, without writing custom code. What should the ML engineer use?

  1. AA CloudTrail trail that records CreateEndpointConfig calls
  2. BThe AWS Config managed rule for endpoint configuration KMS keys
  3. CAmazon Inspector scans of the endpoint's model containers
  4. DAmazon Macie automated sensitive data discovery on the model bucket
Show the answer and why
  • AA CloudTrail trail that records CreateEndpointConfig calls

    Incorrect

    CloudTrail records the calls, but it does not evaluate them against a rule or report compliance.

  • BThe AWS Config managed rule for endpoint configuration KMS keys

    Correct

    This managed rule checks whether a KMS key is configured for SageMaker AI endpoint configurations and marks them NON_COMPLIANT when KmsKeyId is not specified.

  • CAmazon Inspector scans of the endpoint's model containers

    Incorrect

    Inspector looks for software vulnerabilities, not for missing encryption settings in a configuration.

  • DAmazon Macie automated sensitive data discovery on the model bucket

    Incorrect

    Macie finds sensitive data in S3. It does not check SageMaker AI endpoint settings.

AWS Config evaluates resource configurations continuously against rules. Managed rules exist for common SageMaker AI controls such as encryption and notebook internet access.

Question 5 · choose 1

A contact center uses a foundation model in Amazon Bedrock to summarize calls between customers and agents. The summaries are useful, but they must not show customers' names, email addresses or phone numbers. Summaries should still be produced, with the personal details replaced by labels. How should the ML engineer configure Amazon Bedrock Guardrails?

  1. AA sensitive information filter that masks those PII types
  2. BA sensitive information filter that blocks those PII types
  3. CA denied topic that describes personal information
  4. DA contextual grounding check with a high threshold
Show the answer and why
  • AA sensitive information filter that masks those PII types

    Correct

    With the mask action, a sensitive information filter anonymizes PII in requests or responses and replaces it with the PII type, such as {NAME} or {EMAIL}, so the summary is still returned.

  • BA sensitive information filter that blocks those PII types

    Incorrect

    The block action blocks all of the content when sensitive information is detected and returns a configured message, so no summary would be produced.

  • CA denied topic that describes personal information

    Incorrect

    Denied topics stop conversations about a subject. They do not find and replace individual PII values inside an otherwise allowed summary.

  • DA contextual grounding check with a high threshold

    Incorrect

    Grounding checks test whether a response is supported by the source and relevant to the query. They do not remove personal data.

Sensitive information filters can block or mask. Choose mask when the output is still wanted without the personal details, and block when any PII should stop the response entirely.

Question 6 · choose 2

A healthcare company must encrypt the data of its SageMaker AI training jobs at rest with its own customer managed KMS key, including the ML storage volume attached during training and the model artifacts written to S3. The instance type uses EBS storage. Which CreateTrainingJob settings should the ML engineer specify? (Choose TWO.)

  1. AVolumeKmsKeyId in the resource configuration
  2. BEnableNetworkIsolation set to true
  3. CEnableInterContainerTrafficEncryption
  4. DKmsKeyId in the output data configuration
  5. EA bucket policy that denies HTTP requests
Show the answer and why
  • AVolumeKmsKeyId in the resource configuration

    Correct

    VolumeKmsKeyId is the KMS key SageMaker AI uses to encrypt data on the storage volume attached to the training instances.

  • BEnableNetworkIsolation set to true

    Incorrect

    Network isolation blocks inbound and outbound network calls from the training container; it does not encrypt data at rest.

  • CEnableInterContainerTrafficEncryption

    Incorrect

    This encrypts communication between instances in distributed training, which is data in transit, not at rest.

  • DKmsKeyId in the output data configuration

    Correct

    KmsKeyId in OutputDataConfig is the key used to encrypt the model artifacts at rest with S3 server-side encryption.

  • EA bucket policy that denies HTTP requests

    Incorrect

    Denying requests without aws:SecureTransport enforces encryption in transit, not at rest.

Map each control to its data state: KMS keys on volumes and outputs protect data at rest; TLS and inter-container encryption protect it in transit.

Question 7 · choose 1

Before a new fine-tuning project, a team must find which of 300 S3 buckets contain personally identifiable information, such as names and passport numbers, and keep watching for new sensitive data. Which approach needs the least effort?

  1. AAmazon Inspector scans of the S3 buckets
  2. BAmazon Macie automated discovery
  3. CAWS Config rules for each bucket's settings
  4. DA Glue job with custom regular expressions
Show the answer and why
  • AAmazon Inspector scans of the S3 buckets

    Incorrect

    Inspector scans workloads such as EC2 instances, container images and Lambda functions for vulnerabilities, not S3 objects for PII.

  • BAmazon Macie automated discovery

    Correct

    Macie discovers sensitive data, including many types of PII, using machine learning and pattern matching; automated sensitive data discovery continually evaluates the S3 bucket inventory.

  • CAWS Config rules for each bucket's settings

    Incorrect

    Config evaluates resource configurations; it does not inspect object contents for PII.

  • DA Glue job with custom regular expressions

    Incorrect

    A custom job means building and maintaining detection logic that Macie already provides with managed data identifiers.

Find sensitive data before it reaches training sets; Macie does this for S3 at scale.

Question 8 · choose 1

An application's IAM role must be able to run inference on only one approved foundation model in Amazon Bedrock, which the application calls through a cross-Region inference profile. Which approach meets this with least privilege?

  1. AGrant the AmazonBedrockFullAccess managed policy
  2. BAttach a guardrail to the application's calls
  3. CScope InvokeModel to that model and profile ARNs
  4. DAdd an interface VPC endpoint for Bedrock
Show the answer and why
  • AGrant the AmazonBedrockFullAccess managed policy

    Incorrect

    This managed policy grants broad administrative permissions, the opposite of least privilege.

  • BAttach a guardrail to the application's calls

    Incorrect

    Guardrails filter content in prompts and responses; they do not limit which model a role can call.

  • CScope InvokeModel to that model and profile ARNs

    Correct

    To restrict access to a specific model, set the Resource of the InvokeModel statement to the specific model and inference profile ARNs.

  • DAdd an interface VPC endpoint for Bedrock

    Incorrect

    An interface endpoint keeps traffic private; it does not limit which models a role can invoke.

Least privilege for models means naming model and inference profile ARNs in the policy resources.

Question 9 · choose 1

Training data in an S3 bucket must be readable only through the S3 gateway VPC endpoint that SageMaker AI training jobs use, even for principals that have IAM permissions to the bucket. What should the ML engineer add?

  1. ABlock Public Access settings on the bucket
  2. BSSE-KMS default encryption on the bucket
  3. CA security group rule on the training instances
  4. DA bucket policy using aws:SourceVpce
Show the answer and why
  • ABlock Public Access settings on the bucket

    Incorrect

    Block Public Access stops public access; it does not stop authorized principals from reaching the bucket through other paths.

  • BSSE-KMS default encryption on the bucket

    Incorrect

    Encryption protects data at rest; it does not restrict the network path used to read it.

  • CA security group rule on the training instances

    Incorrect

    Security groups filter traffic for the instances they are attached to; they cannot stop other principals from reading the bucket through other paths.

  • DA bucket policy using aws:SourceVpce

    Correct

    A bucket policy that denies access when aws:SourceVpce does not match the endpoint ID restricts the bucket to that VPC endpoint, whatever IAM permissions a principal has.

Resource policies with VPC endpoint conditions enforce a network path for data, on top of identity permissions.

Question 10 · choose 1

A compliance officer asks whether the third-party provider of a foundation model used through Amazon Bedrock can see the company's prompts and completions. What is the accurate answer?

  1. ANo; providers can't see prompts or completions
  2. BYes; the provider receives every prompt you send
  3. COnly when model invocation logging is turned on
  4. DOnly for models served in another Region
Show the answer and why
  • ANo; providers can't see prompts or completions

    Correct

    Models run in Model Deployment Accounts owned and operated by the Bedrock service team; providers have no access to those accounts, so they cannot see Bedrock logs or customer prompts and completions.

  • BYes; the provider receives every prompt you send

    Incorrect

    Providers have no access to the accounts where their models run, so prompts are not passed to them.

  • COnly when model invocation logging is turned on

    Incorrect

    Invocation logging writes to your own CloudWatch Logs or S3 destinations, not to the model provider.

  • DOnly for models served in another Region

    Incorrect

    Region does not change this; model providers do not have access to the deployment accounts.

Bedrock isolates model providers from customer data: they never see prompts, completions or logs.

Practise domain 4 →Practise all domains →