The data lake is already encrypted. The production endpoint’s EBS volumes and the Model Monitor output prefix still use the AWS-managed default, which agency policy forbids for live scoring data. What should they apply?
Select an answer to reveal the explanation.
Short Explanation
The lake is already encrypted, but endpoint volumes and monitor output still use the AWS-managed default. Apply customer-managed KMS keys on endpoints, jobs, notebooks, and monitor outputs. Lake-object encryption does not cover those volumes.
Full Explanation
Customer-managed KMS keys must be applied to SageMaker endpoints, jobs, notebooks, and Model Monitor outputs when policy forbids the AWS-managed default on live scoring data. Lake-object encryption from data prep does not cover those volumes and prefixes. Textract is not that key, and leaving the default fails the policy.