AWS Certified Machine Learning – SpecialtyMachine Learning Implementation and OperationsEasy
A financial institution is deploying a new machine learning model to predict fraudulent transactions in real-time. Due to strict compliance requirements, all data exchanged with the SageMaker inference endpoint, including requests and responses, must be encrypted in transit. Which security measure should be implemented to meet this requirement?
- AUtilize client-side encryption before sending requests to the endpoint.
- BEnable data capture on the SageMaker endpoint to log encrypted payloads.
- CEnsure the SageMaker endpoint is deployed within a private VPC.
- DConfigure the SageMaker endpoint to use HTTPS with a custom SSL certificate.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the SageMaker endpoint to use HTTPS with a custom SSL certificate.
Amazon SageMaker endpoints automatically enforce HTTPS for all communications. This ensures that data exchanged between clients and the endpoint is encrypted in transit using Transport Layer Security (TLS), which is the standard for securing web traffic and satisfies the requirement for encrypted communication.
Why the other options are wrong
- A. Client-side encryption can add another layer, but the fundamental requirement for 'data exchanged with the endpoint' to be encrypted in transit is met by HTTPS.
- B. Data capture logs payloads, but doesn't encrypt the communication channel itself.
- C. Deploying in a private VPC enhances network isolation but does not inherently encrypt the traffic traveling over the network protocols within or outside the VPC.
SageMaker Endpoint In-transit Encryption
Ensuring that all data exchanged with an Amazon SageMaker inference endpoint is encrypted while it is moving across a network.
- Achieved primarily through HTTPS/TLS.
- Protects sensitive data from eavesdropping.
- A fundamental security requirement for many compliance standards.
Memory trick: Secure SageMaker, Encrypted Path, Trust the HTTPS Heart.