DEA-C01 exam dumps

DEA-C01 practice question 375 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 375

Select 2

Your company stores sensitive data in Amazon S3 buckets and needs to ensure that any unauthorized access attempts to this data are automatically detected and logged. You also want to analyze access patterns for compliance purposes. Which combination of AWS services should you use to achieve this?

  1. A

    Enable Amazon Macie to classify and monitor sensitive data in S3 buckets.

  2. B

    Use AWS CloudTrail to log all API calls made to access the S3 buckets.

  3. C

    Set up Amazon CloudWatch Logs to track and store S3 access logs for long-term analysis.

  4. D

    Configure Amazon S3 bucket policies to automatically block unauthorized access.

  5. E

    Use Amazon GuardDuty to monitor and block unauthorized access to S3 buckets.

Show answer and explanation

Correct answers: A, B

Explanation

To detect and log unauthorized access attempts to sensitive data in S3 buckets, you should use Amazon Macie for sensitive data discovery and monitoring, and AWS CloudTrail for logging API calls. Amazon CloudWatch Logs and S3 bucket policies, while useful in other contexts, do not fulfill the requirements of this scenario. GuardDuty, although a threat detection service, is not specifically tailored for S3-sensitive data monitoring.

  • A. Correct.

    Amazon Macie is specifically designed to classify and monitor sensitive data in S3 buckets, making it an essential service for detecting unauthorized access to sensitive data.

  • B. Correct.

    AWS CloudTrail provides detailed logging of API calls, including who accessed the S3 bucket, what actions were performed, and from where. This is critical for auditing and compliance.

  • C. Incorrect.

    While Amazon CloudWatch Logs can store log data, it is not specifically designed for monitoring unauthorized access to sensitive data in S3 buckets. It is more suited for operational monitoring and troubleshooting.

  • D. Incorrect.

    Amazon S3 bucket policies can block unauthorized access, but they do not provide detection or logging of access attempts, which are required in this scenario.

  • E. Incorrect.

    Amazon GuardDuty is a threat detection service, but it is not specifically used for monitoring and detecting unauthorized access to sensitive data in S3 buckets. It focuses on broader threat detection across your AWS environment.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam