AWS Certified Machine Learning – SpecialtyMachine Learning Implementation and OperationsEasy
A financial institution uses a machine learning model for real-time fraud detection. The model is deployed on Amazon SageMaker endpoints. Due to regulatory compliance requirements and the sensitive nature of the data, all inference requests and responses must be encrypted in transit and at rest. Additionally, the solution must minimize operational overhead. Which SageMaker feature should be used to ensure encryption of inference data in transit?
- AConfigure the SageMaker endpoint to use a custom HTTPS certificate.
- BEnsure the SageMaker endpoint is accessed via HTTPS and configure the endpoint for TLS.
- CImplement client-side encryption for all data sent to and received from the SageMaker endpoint.
- DEncrypt the model artifacts stored in Amazon S3 before deploying to SageMaker.
Show answer & explanationAnswer & explanation
Correct answer: B. Ensure the SageMaker endpoint is accessed via HTTPS and configure the endpoint for TLS.
SageMaker endpoints inherently support HTTPS for secure communication. Configuring the endpoint for TLS ensures that all data in transit between the client and the endpoint is encrypted, meeting the requirement for in-transit encryption with minimal operational overhead.
Why the other options are wrong
- A. Custom HTTPS certificates are typically used for custom domains, not standard SageMaker endpoint security.
- C. Client-side encryption adds significant operational overhead and is generally not required for in-transit encryption when HTTPS/TLS is used.
- D. Encrypting model artifacts in S3 addresses at-rest encryption for the model itself, not in-transit encryption for inference data.
SageMaker Endpoint Encryption (In-transit)
Ensuring data exchanged between a client and a SageMaker endpoint is encrypted while it's moving across a network.
- Achieved primarily through HTTPS/TLS.
- Protects sensitive inference requests and responses.
- Standard practice for secure ML deployments.
Memory trick: HTTPS protects the path, TLS secures the trip.