AWS Certified Machine Learning – SpecialtyMachine Learning Implementation and OperationsMedium

A healthcare provider is deploying a new diagnostic ML model that processes sensitive patient health information (PHI). Regulatory compliance requires that all inference requests and responses are encrypted both in transit and at rest. The model is deployed to an Amazon SageMaker real-time endpoint. Which combination of SageMaker configurations ensures both in-transit and at-rest encryption for the inference data?

  1. AConfigure the SageMaker endpoint with an HTTPS endpoint and enable server-side encryption for S3 buckets used by SageMaker Data Capture.
  2. BEnable TLS for the SageMaker endpoint and configure SageMaker Data Capture to encrypt captured data using a KMS key.
  3. CUtilize client-side encryption for inference requests and enable KMS encryption for SageMaker model artifacts.
  4. DEnsure the SageMaker endpoint uses a private VPC endpoint and encrypt model artifacts with a customer-managed KMS key.
Show answer & explanation

Correct answer: B. Enable TLS for the SageMaker endpoint and configure SageMaker Data Capture to encrypt captured data using a KMS key.

TLS (Transport Layer Security) ensures encryption of data in transit to and from the SageMaker endpoint. Configuring SageMaker Data Capture to encrypt captured data using a KMS key ensures that the inference requests and responses stored at rest (in S3) are encrypted. This combination directly addresses both in-transit and at-rest encryption requirements for inference data.

Why the other options are wrong

  • A. HTTPS implies TLS, which covers in-transit. Server-side encryption for S3 buckets used by Data Capture covers at-rest. This is a plausible option, but 'TLS' is more specific for the in-transit part as a configuration.
  • C. Client-side encryption for requests is not a standard SageMaker endpoint configuration. KMS encryption for model artifacts covers the *model itself* at rest, not the *inference data* at rest.
  • D. A private VPC endpoint enhances network security but doesn't inherently provide data encryption; it controls network access. KMS encryption for model artifacts covers the *model*, not the *inference data* at rest.

SageMaker Inference Data Encryption

Ensuring the confidentiality of data processed by SageMaker endpoints, covering both data moving over the network (in transit) and data stored (at rest).

  • In-transit encryption typically uses TLS/HTTPS.
  • At-rest encryption often uses KMS keys for S3 storage (e.g., for Data Capture).
  • Crucial for sensitive data and regulatory compliance (e.g., HIPAA, GDPR).

Memory trick: Transit and Rest, both must pass the encryption test!

More Machine Learning Implementation and Operations questions