AWS Certified AI Practitioner AIF-C01 Practice Question

A machine learning team stores its training data in an Amazon S3 bucket. The security team mandates that the data must be encrypted at rest with the company's own key and that only the Amazon SageMaker training job can read the objects. Which solution meets these secure-data-engineering requirements?

  • Turn on S3 Transfer Acceleration and sign each request with CloudFront key pairs for download.

  • Generate a public presigned URL for each object and require clients to use HTTPS to download the data.

  • Enable default encryption with SSE-S3 and add a bucket policy that allows any authenticated AWS user to read the objects.

  • Apply server-side encryption with AWS KMS (SSE-KMS) using a customer managed key and grant decrypt permission only to the SageMaker execution IAM role.

AWS Certified AI Practitioner AIF-C01
Security, Compliance, and Governance for AI Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot