ETExamTower
Q16Deployment and Orchestration of ML Workflows

A company has a team of data scientists who use Amazon SageMaker notebook instances to test ML models. When the data scientists need new permissions, the company attaches the permissions to each individual role that was created during the creation of the SageMaker notebook instance. The company needs to centralize management of the team's permissions. Which solution will meet this requirement?

← → navigate · a answer
Community votes
A
100% (4)
B
0% (0)
C
0% (0)
D
0% (0)
Discussion · 3
A 6
Selected Answer: A Yet another unclear question from AWS ... anyway, I am basically choosing A since all the other options are not applicable or are unclear. A. Yes, this makes sense B. No, you cannot assign (aka associate) group to notebook instances C. No, for two reason: AdministratorAccess policy is overly broad (violate least privilege principle) and you cannot assign IAM user to notebook instance D. No, for many reasons: AdministratorAccess policy is overly broad, not clear what associating a role to a group means (maybe a group has permissions to assume a role ...) and you cannot assign a group to a notebook
A 3
Selected Answer: A Actually, this is a best practice when working with notebooks in SageMaker. https://docs.aws.amazon.com/sagemaker/latest/dg/gs-setup-working-env.html
A 3
Selected Answer: A Using one IAM role lets you manage permissions centrally for all SageMaker notebook instances. When permissions need to be changed, you update the role, and all notebook instances automatically inherit the new permissions. Why IAM Roles? IAM roles are the recommended way to give permissions to AWS services like SageMaker because they securely delegate permissions without needing long-term credentials. Why Not the Other Options? B. IAM groups manage permissions for users, not for AWS services or resources like SageMaker notebook instances. Groups cannot be attached directly to notebook instances. C. Using an IAM user with AdministratorAccess violates the principle of least privilege, granting unnecessary permissions. Also, IAM users are not meant to be attached to resources like notebook instances. D. This option mixes unnecessary complexity (group and role association) and gives excessive permissions (AdministratorAccess), which is not secure or efficient.