AWS Certified AI Practitioner AIF-C01 Practice Question
A team runs Amazon SageMaker training jobs that must read data only from a single Amazon S3 bucket. To limit the SageMaker execution role so it can access only that bucket and no other AWS resources, which IAM feature should they use?
Attach an inline policy to the SageMaker execution role that allows only s3:GetObject on the specified bucket
Create a service control policy in AWS Organizations that limits S3 access
Enable Amazon Macie in the account and add the SageMaker role to it
Attach the AWS managed policy AmazonS3ReadOnlyAccess to the role
Attaching a custom inline policy to the SageMaker execution role lets the team explicitly allow s3:GetObject (and any other required actions) only on the chosen bucket ARN while leaving all other actions implicitly denied. The AWS managed policy AmazonS3ReadOnlyAccess permits reads from every bucket, defeating the requirement. Service control policies govern entire AWS accounts, not individual roles, and could still allow unintended access through other permissions in the role. Enabling Amazon Macie helps discover sensitive data but does not enforce access restrictions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an inline policy in AWS IAM?
Open an interactive chat with Bash
What does s3:GetObject permission allow in AWS?
Open an interactive chat with Bash
How do service control policies differ from IAM policies?
Open an interactive chat with Bash
AWS Certified AI Practitioner AIF-C01
Security, Compliance, and Governance for AI Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .