DEA-C01 exam dumps

DEA-C01 practice question 379 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 379

Select 3

A financial institution is required to monitor its sensitive data stored in Amazon S3 buckets and track access patterns for compliance purposes. They also need to be alerted on potential unauthorized access attempts and ensure continuous visibility into API activity. Which combination of AWS services should the institution use to meet these requirements?

  1. A

    Enable Amazon Macie to discover and classify sensitive data in S3 buckets.

  2. B

    Use AWS CloudTrail to monitor and log API activity across the AWS environment.

  3. C

    Set up Amazon CloudWatch Alarms to detect unauthorized access attempts.

  4. D

    Configure Amazon GuardDuty to classify sensitive data in S3 buckets.

  5. E

    Use AWS Config to automatically block unauthorized API activity.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the institution’s requirements, Amazon Macie should be used for discovering and classifying sensitive data in S3 buckets, AWS CloudTrail for monitoring API activities, and Amazon CloudWatch Alarms for real-time alerts on unauthorized access attempts. Together, these services ensure compliance, visibility, and timely detection of anomalies.

  • A. Correct.

    Amazon Macie is designed to discover sensitive data in Amazon S3 and provide insights into access patterns. This aligns with the institution's need to monitor sensitive data.

  • B. Correct.

    AWS CloudTrail provides detailed logs of API activity, which helps ensure continuous visibility into all API actions, fulfilling the compliance requirement.

  • C. Correct.

    Amazon CloudWatch Alarms can be configured to notify the institution of unauthorized access attempts, ensuring timely alerts.

  • D. Incorrect.

    Amazon GuardDuty focuses on threat detection, not classification of sensitive data in S3 buckets. This does not meet the requirement for data monitoring and classification.

  • E. Incorrect.

    AWS Config is used for resource compliance and configuration tracking but does not block unauthorized API activity or directly meet the institution's stated needs.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam