DEA-C01 exam dumps

DEA-C01 practice question 378 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 378

Select 3

Your organization is using Amazon S3 to store sensitive customer data, and you are tasked with implementing a solution to detect and log unauthorized access attempts to this data. The requirements include automatically identifying sensitive data, monitoring access patterns, and generating alerts for suspicious activities. Which combination of AWS services should you use to meet these requirements?

  1. A

    Amazon Macie to classify and monitor sensitive data in S3

  2. B

    AWS CloudTrail to log API activity and access requests

  3. C

    Amazon CloudWatch Alarms to trigger alerts based on suspicious activity logs

  4. D

    Amazon GuardDuty to protect sensitive data by encrypting it automatically

  5. E

    AWS Key Management Service (KMS) to detect unauthorized access patterns

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the requirements of detecting and logging unauthorized access attempts to sensitive data in Amazon S3, you need a combination of Amazon Macie, AWS CloudTrail, and Amazon CloudWatch Alarms. Macie identifies and classifies sensitive data, CloudTrail logs access attempts, and CloudWatch Alarms triggers alerts based on suspicious activities. GuardDuty and KMS are not suitable for this specific use case, as they are designed for other purposes like threat detection and encryption key management.

  • A. Correct.

    Amazon Macie is specifically designed to classify and monitor sensitive data in Amazon S3, making it a critical component for identifying at-risk data.

  • B. Correct.

    AWS CloudTrail provides detailed logging of API activity and access requests to S3, which is essential for monitoring and identifying unauthorized access attempts.

  • C. Correct.

    Amazon CloudWatch Alarms can monitor logs and metrics from CloudTrail and trigger alerts for suspicious activities, fulfilling the requirement for generating alerts.

  • D. Incorrect.

    Amazon GuardDuty is a threat detection service, but it does not handle encryption or directly classify sensitive data in Amazon S3.

  • E. Incorrect.

    AWS Key Management Service (KMS) is used for managing encryption keys but does not have the capability to detect unauthorized access patterns.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam