A SageMaker domain is running in a public subnet and the network is configured correctly, but there is now suspicious traffic originating from a particular IP address. The company needs to block that IP from accessing the domain. Which network configuration change accomplishes this?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a network ACL inbound rule that denies the specific IP and associate that ACL (or rule) with the subnet used by the domain..
Why this is the answer
The correct answer is to create a network ACL inbound rule that denies the specific IP and associate that ACL with the subnet used by the domain. Network ACLs operate at the subnet level and can explicitly deny traffic based on IP addresses, making them effective for blocking suspicious traffic before it reaches the instances within the subnet. Adding a security group inbound rule to deny traffic is incorrect because security groups are stateful and only allow rules; they cannot explicitly deny traffic. Creating a shadow variant and using Inference Recommender is a SageMaker-specific feature for A/B testing or canary deployments, not for network-level IP blocking. Creating a VPC route table entry is incorrect because route tables determine where traffic is directed, not whether it is allowed or denied based on source IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed