AWS Certified Machine Learning – SpecialtyMachine Learning Implementation and OperationsMedium

A healthcare provider is deploying a new diagnostic ML model. Due to strict data privacy regulations, all model artifacts, inference code, and any temporary data generated during inference must be encrypted at rest. The SageMaker endpoint serving the model must also use encrypted storage. Which AWS service is primarily used to manage the encryption keys for these resources within SageMaker?

  1. AAWS Identity and Access Management (IAM)
  2. BAWS Key Management Service (KMS)
  3. CAWS Secrets Manager
  4. DAWS Certificate Manager (ACM)
Show answer & explanation

Correct answer: B. AWS Key Management Service (KMS)

AWS Key Management Service (KMS) is the primary service for creating and managing encryption keys used to encrypt data at rest across various AWS services, including SageMaker model artifacts in S3 and SageMaker endpoint storage volumes. It provides centralized control over encryption keys.

Why the other options are wrong

  • A. AWS Identity and Access Management (IAM) controls access to AWS resources, but not the encryption keys themselves.
  • C. AWS Secrets Manager is for managing secrets like database credentials, API keys, etc., not general-purpose encryption keys for data at rest.
  • D. AWS Certificate Manager (ACM) is for managing SSL/TLS certificates, not for data encryption keys.

SageMaker Endpoint Encryption

The practice of encrypting data at rest associated with a SageMaker endpoint, including model artifacts, inference code, and storage volumes, typically using AWS KMS.

  • Protects sensitive data from unauthorized access
  • Uses customer-managed keys (CMKs) from KMS
  • Applies to model artifacts in S3
  • Applies to EBS volumes attached to endpoint instances

Memory trick: KMS Keys Keep Data Safe.

More Machine Learning Implementation and Operations questions