Centralizing SageMaker Notebook Permissions with a Single IAM Role Across the Data Science Team

Secure AWS resources.
Answer Correct answer: A — A single IAM role attached to each notebook centralizes team permissions; instances take a role, not a group or user.

A company has a team of data scientists who use Amazon SageMaker notebook instances to test ML models. When the data scientists need new permissions, the company attaches the permissions to each individual role that was created during the creation of the SageMaker notebook instance. The company needs to centralize management of the team's permissions. Which solution will meet this requirement?

  1. Create a single IAM role that has the necessary permissions. Attach the role to each notebook instance that the team uses. Correct Answer
  2. Create a single IAM group. Add the data scientists to the group. Associate the group with each notebook instance that the team uses.
  3. Create a single IAM user. Attach the AdministratorAccess AWS managed IAM policy to the user. Configure each notebook instance to use the IAM user.
  4. Create a single IAM group. Add the data scientists to the group. Create an IAM role. Attach the AdministratorAccess AWS managed IAM policy to the role. Associate the role with the group. Associate the group with each notebook instance that the team uses.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

SageMaker notebook instances take an IAM execution role, so a single shared role attached to every notebook centralizes permission management: updating the role updates access for all notebooks at once, and role-based delegation is the recommended pattern for SageMaker compute.

A team of data scientists uses SageMaker notebook instances and currently has permissions attached to each individually created role, so the company needs to centralize permission management for the whole team. The requirement is one place to update permissions that all the notebooks inherit.

Attempting to associate an IAM group or an IAM user directly with a notebook instance. Notebook instances accept an IAM role, not a group or a user, so group-based options cannot be attached directly, and granting AdministratorAccess also violates least privilege.

Community Discussion (3 comments)

ninomfr64 👍 4 Selected: A
Yet another unclear question from AWS ... anyway, I am basically picking A as all the other options are not applicable or are unclear. A. Yes, this make sense B. No, you cannot assign (aka associate) group to notebook instances C. No, for two reason: AdministratorAccess policy is overly broad (violate least privilege principle) and you cannot assign IAM user to notebook instance D. No, for many reasons: AdministratorAccess policy is overly broad, not clear what associating a role to a group means (maybe a group has permissions to assume a role ...) and you cannot assign a group to a notebook
motk123 👍 3 Selected: A
Creating a single IAM role allows centralized management of permissions for all SageMaker notebook instances. When permissions need to be updated, the changes are applied to the role, and all notebook instances automatically inherit the updated permissions. Why IAM Roles? IAM roles are the recommended way to provide permissions to AWS services like SageMaker because they securely delegate permissions without requiring long-term credentials. Why Not the Other Options? B. IAM groups manage permissions for users, not for AWS services or resources like SageMaker notebook instances. Groups cannot be attached directly to notebook instances. C. Using an IAM user with AdministratorAccess violates the principle of least privilege, granting unnecessary permissions. Additionally, IAM users are not intended to be attached to resources like notebook instances. D. This option combines unnecessary complexity (group and role association) and grants excessive permissions (AdministratorAccess), which is not secure or efficient.
GiorgioGss 👍 3 Selected: A
Actually this is a best practice when working with notebooks in SageMaker. https://docs.aws.amazon.com/sagemaker/latest/dg/gs-setup-working-env.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

SageMaker notebook instances are configured with an IAM execution role that supplies their permissions. Creating a single IAM role with the required permissions and attaching it to every notebook instance the team uses centralizes management, because any permission change is made once on the role and every notebook inherits it immediately, and role-based delegation is the recommended way to grant permissions to SageMaker compute. The vote was unanimous at 100 for A, and motk123 explained the centralization benefit directly, noting that updates applied to the role propagate to all notebook instances. GiorgioGss called this a best practice for working with notebooks in SageMaker and cited the SageMaker setup documentation.

Why the Other Options Are Wrong

Creating a single IAM group and associating it with each notebook instance (B) is not possible, because a notebook instance takes an IAM role and cannot have a group associated with it; groups are a construct for organizing IAM users, not for attaching to AWS compute resources. Creating a single IAM user with the AdministratorAccess managed policy and configuring each notebook to use it (C) fails twice over: a notebook instance cannot be configured to run as an IAM user, and AdministratorAccess is far broader than the data scientists actually require, violating least privilege. The longer option D combines both defects, associating a group with notebook instances and granting the AdministratorAccess policy on the role, so it is also technically invalid and over-permissive.

Community Comment Notes

The community voted 100 for A, though the question is imperfect. ninomfr64 opened by calling it another unclear AWS question and then explained that A is the only applicable option: you cannot associate a group with a notebook instance, and the user option is doubly wrong because AdministratorAccess violates least privilege and an IAM user cannot be assigned to a notebook instance. Despite flagging the question's awkwardness, every substance comment selected A and none defended the group-based or user-based alternatives on technical grounds.

Official Reference

Related Analysis

Practice All MLA-C01 Questions

Access 115 questions with complete answers and detailed explanations.

View Full MLA-C01 Practice Test →

← Back to MLA-C01 Study Guide