DEA-C01 exam dumps

DEA-C01 practice question 207 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 207

Select 3

A financial company uses AWS to store sensitive customer data, including Personally Identifiable Information (PII), transactional records, and non-sensitive operational logs. To meet compliance requirements, you are tasked with implementing a data classification strategy that ensures the appropriate security controls are applied to each type of data. Which combination of actions is most appropriate for classifying and securing this data?

  1. A

    Use Amazon Macie to automatically identify and classify sensitive data such as PII and apply appropriate security policies.

  2. B

    Store all data in a single Amazon S3 bucket with the same encryption settings to simplify management.

  3. C

    Classify data into categories such as PII, financial transactions, and operational logs, and apply different S3 bucket policies based on sensitivity levels.

  4. D

    Use AWS Key Management Service (KMS) to encrypt sensitive data such as PII and transactional records while using default encryption for operational logs.

  5. E

    Enable public read access on the S3 bucket containing operational logs to reduce overhead for accessing non-sensitive data.

Show answer and explanation

Correct answers: A, C, D

Explanation

To implement a robust data classification strategy, it is essential to identify sensitive data such as PII using tools like Amazon Macie, classify data into categories based on sensitivity, and apply appropriate security measures such as encryption using AWS KMS. Combining these approaches ensures compliance with data protection regulations while maintaining security and cost efficiency.

  • A. Correct.

    Amazon Macie is an AWS service that uses machine learning to automatically discover, classify, and protect sensitive data, making it useful for identifying and securing PII.

  • B. Incorrect.

    Storing all data in a single S3 bucket with the same encryption settings does not align with the principle of least privilege or data classification best practices.

  • C. Correct.

    Classifying data into categories and applying bucket policies based on sensitivity ensures that appropriate security measures, such as access control, are applied to different types of data.

  • D. Correct.

    Using AWS KMS to encrypt sensitive data and default encryption for less sensitive data aligns with best practices for data security and cost efficiency.

  • E. Incorrect.

    Enabling public read access on any bucket containing operational logs is a security risk and violates AWS data security best practices.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam