AWS Certified AI Practitioner AIF-C01 Practice Question
A machine learning team stores its training data in an Amazon S3 bucket. The security team mandates that the data must be encrypted at rest with the company's own key and that only the Amazon SageMaker training job can read the objects. Which solution meets these secure-data-engineering requirements?
Apply server-side encryption with AWS KMS (SSE-KMS) using a customer managed key and grant decrypt permission only to the SageMaker execution IAM role.
Enable default encryption with SSE-S3 and add a bucket policy that allows any authenticated AWS user to read the objects.
Turn on S3 Transfer Acceleration and sign each request with CloudFront key pairs for download.
Generate a public presigned URL for each object and require clients to use HTTPS to download the data.
Server-side encryption with AWS KMS (SSE-KMS) lets you encrypt S3 objects with a customer managed key (CMK). You can then use an IAM policy that grants the SageMaker execution role permission to call kms:Decrypt on that CMK and s3:GetObject on the bucket while denying all other principals. SSE-S3 does not use a customer key, S3 Transfer Acceleration addresses performance rather than access control, and presigned URLs do not restrict decryption or guarantee at-rest encryption with a customer key. Therefore, SSE-KMS with a CMK and a least-privilege policy for the SageMaker role is the only option that satisfies both encryption and access-control requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is server-side encryption with AWS KMS (SSE-KMS)?
Open an interactive chat with Bash
What is the role of an IAM policy in securing S3 objects with SSE-KMS?
Open an interactive chat with Bash
How does Amazon SageMaker interact with encrypted data in an S3 bucket?
Open an interactive chat with Bash
What is AWS KMS and how is it used in SSE-KMS?
Open an interactive chat with Bash
Why is a customer managed key (CMK) more secure than SSE-S3?
Open an interactive chat with Bash
How does an IAM policy ensure least-privilege access for SageMaker?
Open an interactive chat with Bash
AWS Certified AI Practitioner AIF-C01
Security, Compliance, and Governance for AI Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .