← Back to all posts
Build in Public

AWS AI Practitioner — Day 9: Security & Cost Estimation

Learn: encryption-at-rest and in-transit, KMS keys, cost drivers (instance size, uptime, data transfer).

Hands-on: enable SSE on S3 buckets and create a rough monthly cost estimate for a small endpoint.

Practice question:

Q1: Which factor most increases SageMaker real-time endpoint cost?

A) Endpoint instance type and number running 24/7 B) Using serverless inference only when invoked C) Storing data in S3 D) Adding CloudWatch metrics

Answer: A — instance type and uptime are primary cost drivers for endpoints.

Daily Practice Questions (new)

Q1: How do you enable server-side encryption (SSE) on an S3 bucket?

A) Configure bucket encryption with KMS B) Set bucket ACL to public-read C) Disable versioning D) Use aws s3 ls

Answer: A — configure default encryption with KMS for SSE-KMS.

Q2: What is AWS KMS?

A) Key Management Service for encryption keys B) Kubernetes Management Service C) Key Monitoring Service D) Knowledge Management System

Answer: A — KMS manages encryption keys and cryptographic operations.

Q3: How to estimate endpoint cost quickly?

A) Use AWS Pricing Calculator with instance type and uptime B) Guess based on memory C) Use CloudWatch only D) Check Route 53

Answer: A — pricing calculator helps estimate costs by instance and duration.

Q4: What increases data transfer costs?

A) Cross-region transfers and large payloads B) Smaller instances C) IAM policies D) CloudWatch alarms

Answer: A — cross-region and high-volume transfers raise costs.

Q5: How to reduce costs for low-traffic endpoints?

A) Use serverless inference or scale-to-zero patterns B) Always run large instances C) Disable monitoring D) Use public access

Answer: A — serverless or scale-to-zero saves cost at low traffic.

Q6: What is a key security control for S3?

A) Bucket policies and encryption B) Route 53 records C) EC2 AMIs D) CloudFront invalidation

Answer: A — policies and encryption control access and protect data.

Q7: How to audit access to S3 buckets?

A) Enable S3 access logs or CloudTrail B) Use IAM only C) Delete the bucket D) Use Route 53

Answer: A — access logs and CloudTrail provide audit trails.

Q8: What is envelope encryption?

A) Encrypt data keys with KMS then use them to encrypt data B) A way to encrypt emails only C) A storage class D) A logging mode

Answer: A — envelope encryption wraps data keys with KMS-managed keys.

Q9: How to choose instance types cost-effectively?

A) Test with smaller instances and scale up as needed B) Always pick the largest instance C) Ignore resource needs D) Use only spot instances

Answer: A — start smaller for testing, then scale based on metrics.

Q10: What is an S3 lifecycle policy?

A) Rules for automatic tiering and expiration of objects B) A CloudWatch dashboard C) An EC2 user data script D) An IAM group

Answer: A — lifecycle policies transition objects to cheaper storage or expire them.

Review Questions (previous lessons)

Q1: What does SSE stand for in S3 context?

A) Server-Side Encryption B) Simple Storage Endpoint C) Secure S3 Event D) S3 Standard Extra

Answer: A — SSE means server-side encryption of objects.

Q2: Why apply least-privilege IAM practices?

A) To minimize access scope and risk B) To speed up network C) To reduce storage D) To increase costs

Answer: A — least-privilege reduces potential impact from compromises.

Q3: Which metric often indicates cost issues with endpoints?

A) High instance-hours or unexpected instance usage B) DNS lookups C) S3 bucket name length D) IAM password age

Answer: A — instance-hours are a major cost driver.

Q4: How to simulate lower-cost experiments?

A) Limit run duration and use smaller instance types for tests B) Use unlimited resources C) Delete logs immediately D) Increase instance size

Answer: A — shorten runs and use smaller instances to limit cost.

Q5: What is AWS CloudTrail used for?

A) Auditing API calls and account activity B) Storing model artifacts C) Serving endpoints D) DNS routing

Answer: A — CloudTrail records API activity for auditing.

Q6: Why encrypt model artifacts stored in S3?

A) To protect IP and sensitive data at rest B) To increase latency C) To reduce costs D) To change DNS

Answer: A — encryption secures stored artifacts.

Q7: How to get budget alerts on AWS?

A) Use AWS Budgets with notification actions B) Use SSH only C) Use manual billing checks only D) Disable alerts

Answer: A — AWS Budgets can notify when thresholds are exceeded.

Q8: What cost is associated with cross-region replication?

A) Additional storage and inter-region transfer fees B) Free replication always C) Only compute costs D) IAM charges

Answer: A — cross-region replication adds storage and transfer costs.

Q9: How can you measure data transfer usage?

A) Use CloudWatch metrics or billing reports B) Use local OS tools only C) Check DNS logs D) Use IAM simulator

Answer: A — CloudWatch and billing reports show transfer data.

Q10: What reduces long-term storage cost for infrequently accessed data?

A) Lifecycle rules moving objects to Glacier or cheaper tiers B) Keep everything in Standard forever C) Delete metadata only D) Use larger instances

Answer: A — lifecycle policies transition objects to archival storage.