← Back to all posts
Build in Public

AWS AI Practitioner — Day 2: Data Handling & IAM

Learn: data hygiene, partitioning, simple versioning (prefixes), and IAM policies for access control.

Hands-on: create a least-privilege role for SageMaker and test reading the CSV from S3.

Practice question:

Q1: Which S3 feature helps organize evolving datasets by time?

A) Object tagging B) Bucket versioning C) Prefix-based folders (date-based prefixes) D) Server-side encryption

Answer: C — using prefixes (or partition keys) is a common simple pattern to organize by date.

Daily Practice Questions (new)

Q1: How do you upload a file to S3 using the CLI?

A) aws s3 cp file.csv s3://bucket/ B) aws s3 rm file.csv C) aws ec2 start-instances D) aws iam create-user

Answer: A — aws s3 cp copies files to S3.

Q2: Which S3 storage class is cheaper for infrequent access?

A) Standard-IA B) S3 Glacier Deep Archive C) S3 One Zone-IA D) S3 Standard

Answer: A — Standard-Infrequent Access balances cost and retrieval time for infrequent reads.

Q3: How do you enable server-side encryption for S3 objects via CLI?

A) Use --sse or configure bucket default encryption B) Use --no-encrypt flag C) Upload to unencrypted region D) Use aws kms disable

Answer: A — --sse or bucket default encryption enables server-side encryption.

Q4: What is an IAM policy?

A) JSON document defining permissions B) A physical security badge C) A billing invoice D) A network ACL

Answer: A — IAM policies are JSON permission documents.

Q5: How can you test an IAM role’s permissions?

A) Assume the role and attempt actions or use IAM Policy Simulator B) Restart the role C) Use S3 website D) Run aws ec2 describe-instances

Answer: A — assume-role or Policy Simulator help validate permissions.

Q6: Why avoid wildcard permissions like “*”?

A) They increase security risk B) They cost extra money C) They improve performance D) They are required for S3

Answer: A — wildcards grant broad access and increase risk.

Q7: How do you version data simply in S3?

A) Use object versioning or date-based prefixes B) Use Route 53 C) Use CloudWatch alarms D) Store on local disk

Answer: A — enable versioning or use structured prefixes for organization.

Q8: Where can object metadata be stored in S3?

A) In object headers (x-amz-meta-) B) In CloudWatch C) In IAM policies D) In EC2 tags

Answer: A — S3 object metadata is stored in headers like x-amz-meta-.

Q9: What is the effect of enabling bucket versioning?

A) Stores multiple versions of objects B) Increases latency C) Deletes objects automatically D) Disables SSE

Answer: A — versioning preserves previous object versions.

Q10: How to list objects in a prefix?

A) aws s3 ls s3://bucket/prefix/ B) aws ec2 describe-instances C) aws iam list-users D) aws s3 rm s3://bucket/prefix/

Answer: A — aws s3 ls with the prefix lists objects.

Review Questions (previous lessons)

Q1: Which CLI command lists S3 buckets?

A) aws s3 ls B) aws ec2 run-instances C) aws iam list-roles D) aws lambda invoke

Answer: A — aws s3 ls lists buckets and objects.

Q2: Where are AWS CLI credentials commonly stored locally?

A) ~/.aws/credentials B) /etc/passwd C) ~/.ssh/id_rsa D) /var/log

Answer: A — credentials are stored in ~/.aws/credentials for profiles.

Q3: Why follow least-privilege for SageMaker roles?

A) Reduce blast radius of compromised credentials B) Improve network latency C) Reduce storage size D) Increase costs

Answer: A — limiting permissions reduces potential impact.

Q4: What is SageMaker Studio used for?

A) Managed notebooks and ML tooling B) DNS management C) File backups only D) IAM user creation

Answer: A — Studio provides managed notebooks and tooling.

Q5: How do you confirm a notebook can access S3?

A) Attempt a boto3 read from the notebook B) Ping S3 URL via ping command C) Check DNS records D) List IAM users

Answer: A — reading via boto3 confirms access and permissions.

Q6: Why use per-project S3 buckets?

A) Isolation and easier permissions management B) To increase latency C) To disable encryption D) To avoid billing

Answer: A — separate buckets simplify access control.

Q7: What permissions should be checked before training?

A) Role S3 read/write and SageMaker actions B) Route53 write access C) EC2 keypair only D) CloudFront invalidation

Answer: A — ensure the role can access required S3 and SageMaker APIs.

Q8: Which service provides observability on AWS?

A) CloudWatch B) S3 Glacier C) Route 53 D) IAM

Answer: A — CloudWatch for logs and metrics.

Q9: Why organize datasets by date/prefix?

A) Easier ingestion, partitioning, and cleanup B) To increase costs C) To hide data D) To reduce availability

Answer: A — date prefixes make ingestion and retention simpler.

Q10: Which command shows AWS CLI profile settings?

A) aws configure list B) aws iam list-users C) aws s3 mb D) aws sts get-caller-identity

Answer: A — aws configure list displays active profiles and config.