Centralizing SageMaker Notebook Permissions with a Single IAM Role Across the Data Science Team
A company has a team of data scientists who use Amazon SageMaker notebook instances to test ML models. When the data scientists need new permissions, the company attaches the permissions to each individual role that was created during the creation of the SageMaker notebook instance. The company needs to centralize management of the team's permissions. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
SageMaker notebook instances take an IAM execution role, so a single shared role attached to every notebook centralizes permission management: updating the role updates access for all notebooks at once, and role-based delegation is the recommended pattern for SageMaker compute.
A team of data scientists uses SageMaker notebook instances and currently has permissions attached to each individually created role, so the company needs to centralize permission management for the whole team. The requirement is one place to update permissions that all the notebooks inherit.
Attempting to associate an IAM group or an IAM user directly with a notebook instance. Notebook instances accept an IAM role, not a group or a user, so group-based options cannot be attached directly, and granting AdministratorAccess also violates least privilege.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
SageMaker notebook instances are configured with an IAM execution role that supplies their permissions. Creating a single IAM role with the required permissions and attaching it to every notebook instance the team uses centralizes management, because any permission change is made once on the role and every notebook inherits it immediately, and role-based delegation is the recommended way to grant permissions to SageMaker compute. The vote was unanimous at 100 for A, and motk123 explained the centralization benefit directly, noting that updates applied to the role propagate to all notebook instances. GiorgioGss called this a best practice for working with notebooks in SageMaker and cited the SageMaker setup documentation.Why the Other Options Are Wrong
Creating a single IAM group and associating it with each notebook instance (B) is not possible, because a notebook instance takes an IAM role and cannot have a group associated with it; groups are a construct for organizing IAM users, not for attaching to AWS compute resources. Creating a single IAM user with the AdministratorAccess managed policy and configuring each notebook to use it (C) fails twice over: a notebook instance cannot be configured to run as an IAM user, and AdministratorAccess is far broader than the data scientists actually require, violating least privilege. The longer option D combines both defects, associating a group with notebook instances and granting the AdministratorAccess policy on the role, so it is also technically invalid and over-permissive.Community Comment Notes
The community voted 100 for A, though the question is imperfect. ninomfr64 opened by calling it another unclear AWS question and then explained that A is the only applicable option: you cannot associate a group with a notebook instance, and the user option is doubly wrong because AdministratorAccess violates least privilege and an IAM user cannot be assigned to a notebook instance. Despite flagging the question's awkwardness, every substance comment selected A and none defended the group-based or user-based alternatives on technical grounds.Official Reference
Related Analysis
Practice All MLA-C01 Questions
Access 115 questions with complete answers and detailed explanations.
View Full MLA-C01 Practice Test →