AWS Certified Machine Learning – SpecialtyMachine Learning Implementation and OperationsHard

A security team needs to ensure that machine learning models deployed in production adhere to strict compliance requirements, including data access controls and encryption at rest and in transit. For an Amazon SageMaker endpoint, where should the data scientist configure the encryption settings for the model artifacts and the communication channels?

  1. AOnly during model training job configuration.
  2. BWithin the SageMaker Model resource and Endpoint Configuration.
  3. COnly at the S3 bucket policy level where model artifacts are stored.
  4. DThrough IAM policies attached to the SageMaker execution role.
Show answer & explanation

Correct answer: B. Within the SageMaker Model resource and Endpoint Configuration.

Encryption for model artifacts is specified when creating the SageMaker Model resource, and encryption for data in transit (communication channels) and at rest (EBS volumes, S3 buckets) for the endpoint is configured within the SageMaker Endpoint Configuration.

Why the other options are wrong

  • A. Training job encryption is important, but separate from deployed model/endpoint encryption.
  • C. S3 bucket policies cover artifact storage, but not communication channels or endpoint-specific storage.
  • D. IAM policies control permissions, not direct encryption settings for data at rest/in transit within SageMaker services.

SageMaker Endpoint Encryption

Configuring encryption for model artifacts, data in transit, and data at rest (EBS volumes) associated with an Amazon SageMaker real-time endpoint.

  • Model artifacts can be encrypted in S3 using KMS.
  • Endpoint communication uses HTTPS for in-transit encryption.
  • EBS volumes attached to endpoint instances can be encrypted with KMS keys.

Memory trick: Model resource secures artifacts, endpoint config secures the runtime home.

More Machine Learning Implementation and Operations questions