Q15
Single choice
A company employs Amazon SageMaker for its machine learning processes. During a compliance audit, it is discovered that an Amazon S3 bucket containing training data is encrypted using server-side encryption with S3 managed keys (SSE-S3). The company requires the use of customer managed keys instead.
In response, an ML engineer updates the S3 bucket to use server-side encryption with AWS KMS keys (SSE-KMS) without making any other configuration changes. However, following this update, SageMaker training jobs begin to fail with AccessDenied errors.
What steps should the ML engineer take to resolve this issue?