exam questions

Exam AWS Certified Machine Learning Engineer - Associate MLA-C01 All Questions

View all questions & answers for the AWS Certified Machine Learning Engineer - Associate MLA-C01 exam

Exam AWS Certified Machine Learning Engineer - Associate MLA-C01 topic 1 question 108 discussion

A company shares Amazon SageMaker Studio notebooks that are accessible through a VPN. The company must enforce access controls to prevent malicious actors from exploiting presigned URLs to access the notebooks.

Which solution will meet these requirements?

  • A. Set up Studio client IP validation by using the aws:sourceIp IAM policy condition.
  • B. Set up Studio client VPC validation by using the aws:sourceVpc IAM policy condition.
  • C. Set up Studio client role endpoint validation by using the aws:PrimaryTag IAM policy condition.
  • D. Set up Studio client user endpoint validation by using the aws:PrincipalTag IAM policy condition.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
chris_spencer
1 week ago
Selected Answer: A
A is correct. https://aws.amazon.com/blogs/machine-learning/secure-amazon-sagemaker-studio-presigned-urls-part-1-foundational-infrastructure/ Studio supports a few methods for enforcing access controls against presigned URL data exfiltration: Client IP validation using the IAM policy condition aws:sourceIp Client VPC validation using the IAM condition aws:sourceVpc Client VPC endpoint validation using the IAM policy condition aws:sourceVpce
upvoted 1 times
...
ryuhei
1 week, 6 days ago
Selected Answer: B
If you apply IP restrictions, it may not be possible to properly control access via dynamic IP addresses or proxies, so the correct answer is probably B.
upvoted 2 times
chris_spencer
1 week ago
B is incorrect, IAM condition aws:sourceVpc is use for validating Client VPC. Client VPC validation using the IAM condition aws:sourceVpc
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago