AWS Certified AI Practitioner AIF-C01 Practice Question
A startup is training a computer vision model on AWS. The training images are stored in a dedicated Amazon S3 bucket named "prod-data". To follow the principle of least privilege, the company wants only its Amazon SageMaker training jobs to read objects in this bucket, and no other AWS principals should have access. Which action satisfies this requirement with the least operational effort?
Turn on S3 Block Public Access for the bucket to prevent any unintended access.
Encrypt the bucket with a customer-managed AWS KMS key and require KMS permissions for decryption.
Attach an IAM role to the SageMaker training jobs that includes a policy granting s3:GetObject permission only for the prod-data bucket.
Enable Amazon Macie on the bucket to monitor sensitive data and unauthorized access.
Attaching an IAM role to the SageMaker training jobs and granting that role read-only permissions (such as s3:GetObject) on the specific bucket enforces data access control. SageMaker automatically uses the role when running the job, so no other principals can access the bucket unless explicitly allowed. Amazon Macie provides data discovery, S3 Block Public Access only stops public access, and KMS encryption controls data confidentiality but does not limit which principals can call S3 APIs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege?
Open an interactive chat with Bash
How does an IAM role help control access in AWS?
Open an interactive chat with Bash
How is Amazon SageMaker integrated with IAM roles for secure data access?
Open an interactive chat with Bash
What is the principle of least privilege in AWS?
Open an interactive chat with Bash
How does an IAM role work with Amazon SageMaker?
Open an interactive chat with Bash
Why is encrypting an S3 bucket with AWS KMS insufficient for restricting access?
Open an interactive chat with Bash
AWS Certified AI Practitioner AIF-C01
Security, Compliance, and Governance for AI Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .