To protect sensitive training data from being exfiltrated by malicious code running in a training container, which action provides the strongest protection?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable network isolation for the training jobs so containers cannot access external network endpoints..
Why this is the answer
Enabling network isolation for training jobs prevents the container from making outbound network calls, effectively blocking any attempt by malicious code to exfiltrate data to an external destination. This provides the strongest protection against data exfiltration. Removing S3 access permissions would prevent the job from accessing necessary training data, making it non-functional. Encrypting model weights protects the model itself but not the raw training data from exfiltration. Encrypting training and validation datasets protects data at rest and in transit but doesn't prevent a compromised container from decrypting and exfiltrating the data if it has the necessary permissions and network access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed