You created a VPC with a VPC interface endpoint for the SageMaker Service API. You want to restrict access so only certain EC2 instances and IAM users can call the SageMaker API. The VPC has a single public subnet. Which two actions will secure access to the endpoint? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Attach a VPC endpoint policy that restricts which IAM users can access the endpoint., Restrict access to the endpoint by adjusting the security group on the endpoint network interface..
Why this is the answer
Attaching a VPC endpoint policy is correct because endpoint policies allow you to control which IAM principals (users or roles) can access the SageMaker API through the interface endpoint. This directly addresses the requirement to restrict access for certain IAM users. Restricting access by adjusting the security group on the endpoint network interface is also correct. Security groups act as virtual firewalls that control inbound and outbound traffic to the network interfaces associated with the endpoint, allowing you to specify which EC2 instances (based on their security groups) can communicate with the endpoint. Restricting SageMaker API access solely by modifying IAM policies is insufficient because it doesn't control access through the VPC endpoint. Modifying the network ACL on the endpoint network interface is less granular and typically used for subnet-level traffic control, not specific endpoint access. Creating a SageMaker Runtime VPC interface endpoint is for inference, not for controlling access to the SageMaker Service API.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed