AWS AI Practitioner — Day 9: Security & Cost Estimation
Learn: encryption-at-rest and in-transit, KMS keys, cost drivers (instance size, uptime, data transfer).
Hands-on: enable SSE on S3 buckets and create a rough monthly cost estimate for a small endpoint.
Practice question:
Q1: Which factor most increases SageMaker real-time endpoint cost?
A) Endpoint instance type and number running 24/7 B) Using serverless inference only when invoked C) Storing data in S3 D) Adding CloudWatch metrics
Answer: A — instance type and uptime are primary cost drivers for endpoints.
Daily Practice Questions (new)
Q1: How do you enable server-side encryption (SSE) on an S3 bucket?
A) Configure bucket encryption with KMS B) Set bucket ACL to public-read C) Disable versioning D) Use aws s3 ls
Answer: A — configure default encryption with KMS for SSE-KMS.
Q2: What is AWS KMS?
A) Key Management Service for encryption keys B) Kubernetes Management Service C) Key Monitoring Service D) Knowledge Management System
Answer: A — KMS manages encryption keys and cryptographic operations.
Q3: How to estimate endpoint cost quickly?
A) Use AWS Pricing Calculator with instance type and uptime B) Guess based on memory C) Use CloudWatch only D) Check Route 53
Answer: A — pricing calculator helps estimate costs by instance and duration.
Q4: What increases data transfer costs?
A) Cross-region transfers and large payloads B) Smaller instances C) IAM policies D) CloudWatch alarms
Answer: A — cross-region and high-volume transfers raise costs.
Q5: How to reduce costs for low-traffic endpoints?
A) Use serverless inference or scale-to-zero patterns B) Always run large instances C) Disable monitoring D) Use public access
Answer: A — serverless or scale-to-zero saves cost at low traffic.
Q6: What is a key security control for S3?
A) Bucket policies and encryption B) Route 53 records C) EC2 AMIs D) CloudFront invalidation
Answer: A — policies and encryption control access and protect data.
Q7: How to audit access to S3 buckets?
A) Enable S3 access logs or CloudTrail B) Use IAM only C) Delete the bucket D) Use Route 53
Answer: A — access logs and CloudTrail provide audit trails.
Q8: What is envelope encryption?
A) Encrypt data keys with KMS then use them to encrypt data B) A way to encrypt emails only C) A storage class D) A logging mode
Answer: A — envelope encryption wraps data keys with KMS-managed keys.
Q9: How to choose instance types cost-effectively?
A) Test with smaller instances and scale up as needed B) Always pick the largest instance C) Ignore resource needs D) Use only spot instances
Answer: A — start smaller for testing, then scale based on metrics.
Q10: What is an S3 lifecycle policy?
A) Rules for automatic tiering and expiration of objects B) A CloudWatch dashboard C) An EC2 user data script D) An IAM group
Answer: A — lifecycle policies transition objects to cheaper storage or expire them.
Review Questions (previous lessons)
Q1: What does SSE stand for in S3 context?
A) Server-Side Encryption B) Simple Storage Endpoint C) Secure S3 Event D) S3 Standard Extra
Answer: A — SSE means server-side encryption of objects.
Q2: Why apply least-privilege IAM practices?
A) To minimize access scope and risk B) To speed up network C) To reduce storage D) To increase costs
Answer: A — least-privilege reduces potential impact from compromises.
Q3: Which metric often indicates cost issues with endpoints?
A) High instance-hours or unexpected instance usage B) DNS lookups C) S3 bucket name length D) IAM password age
Answer: A — instance-hours are a major cost driver.
Q4: How to simulate lower-cost experiments?
A) Limit run duration and use smaller instance types for tests B) Use unlimited resources C) Delete logs immediately D) Increase instance size
Answer: A — shorten runs and use smaller instances to limit cost.
Q5: What is AWS CloudTrail used for?
A) Auditing API calls and account activity B) Storing model artifacts C) Serving endpoints D) DNS routing
Answer: A — CloudTrail records API activity for auditing.
Q6: Why encrypt model artifacts stored in S3?
A) To protect IP and sensitive data at rest B) To increase latency C) To reduce costs D) To change DNS
Answer: A — encryption secures stored artifacts.
Q7: How to get budget alerts on AWS?
A) Use AWS Budgets with notification actions B) Use SSH only C) Use manual billing checks only D) Disable alerts
Answer: A — AWS Budgets can notify when thresholds are exceeded.
Q8: What cost is associated with cross-region replication?
A) Additional storage and inter-region transfer fees B) Free replication always C) Only compute costs D) IAM charges
Answer: A — cross-region replication adds storage and transfer costs.
Q9: How can you measure data transfer usage?
A) Use CloudWatch metrics or billing reports B) Use local OS tools only C) Check DNS logs D) Use IAM simulator
Answer: A — CloudWatch and billing reports show transfer data.
Q10: What reduces long-term storage cost for infrequently accessed data?
A) Lifecycle rules moving objects to Glacier or cheaper tiers B) Keep everything in Standard forever C) Delete metadata only D) Use larger instances
Answer: A — lifecycle policies transition objects to archival storage.