DEA-C01 exam dumps

DEA-C01 practice question 377 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 377

Select 3

Your organization stores sensitive customer information in Amazon S3 buckets. To comply with security and compliance requirements, you need to monitor and detect unauthorized access to this data, identify sensitive data in the buckets, and set up alerts for anomalous activity. Which combination of AWS services can help you achieve this?

  1. A

    Amazon Macie to classify and monitor sensitive data in S3 buckets

  2. B

    AWS CloudTrail to log and monitor API activity related to S3

  3. C

    Amazon CloudWatch to set up alerts for unauthorized access patterns

  4. D

    AWS Config to automatically block unauthorized access to S3 buckets

  5. E

    Amazon GuardDuty to provide insights into S3 anomaly detection for sensitive data

Show answer and explanation

Correct answers: A, B, C

Explanation

To monitor and protect sensitive data in Amazon S3, you need a combination of services: Amazon Macie for sensitive data classification, AWS CloudTrail to log and monitor API activity, and Amazon CloudWatch to set up alerts for unauthorized access patterns or anomalies. Together, these services provide a comprehensive solution for security and compliance in S3.

  • A. Correct.

    Amazon Macie is designed to identify, classify, and monitor sensitive data in S3 buckets. It uses machine learning to detect anomalies and ensure compliance with data privacy regulations.

  • B. Correct.

    AWS CloudTrail provides detailed logs of API activity in your AWS account, including S3 operations. This allows you to track who accessed your data and when.

  • C. Correct.

    Amazon CloudWatch can be used to set up alarms and alerts to notify you about unauthorized access patterns or anomalous activity detected in S3 usage.

  • D. Incorrect.

    While AWS Config is useful for compliance auditing and evaluating resource configurations, it does not directly block unauthorized access or provide monitoring for sensitive data in S3.

  • E. Incorrect.

    Amazon GuardDuty provides threat detection for AWS accounts, but it does not specialize in sensitive data classification or anomaly detection specifically for S3.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam