Amazon Web Services AWS Certified Machine Learning - Specialty MLS-C01 Question # 24 Topic 3 Discussion

Amazon Web Services AWS Certified Machine Learning - Specialty MLS-C01 Question # 24 Topic 3 Discussion

MLS-C01 Exam Topic 3 Question 24 Discussion:
Question #: 24
Topic #: 3

A machine learning (ML) specialist uploads a dataset to an Amazon S3 bucket that is protected by server-side encryption with AWS KMS keys (SSE-KMS). The ML specialist needs to ensure that an Amazon SageMaker notebook instance can read the dataset that is in Amazon S3.

Which solution will meet these requirements?


A.

Define security groups to allow all HTTP inbound and outbound traffic. Assign the security groups to the SageMaker notebook instance.


B.

Configure the SageMaker notebook instance to have access to the VPC. Grant permission in the AWS Key Management Service (AWS KMS) key policy to the notebook's VPC.


C.

Assign an IAM role that provides S3 read access for the dataset to the SageMaker notebook. Grant permission in the KMS key policy to the 1AM role.


D.

Assign the same KMS key that encrypts the data in Amazon S3 to the SageMaker notebook instance.


Get Premium MLS-C01 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.