DEA-C01 exam dumps

DEA-C01 practice question 411 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 411

Select 4

You are a data engineer working for a financial institution. Your team is using Amazon S3 to store sensitive customer data, and you need to ensure compliance with data governance policies, including encryption and access control. Which combination of actions should you take to secure the data and meet compliance standards?

  1. A

    Enable default encryption on the S3 bucket using an AWS Key Management Service (KMS) key.

  2. B

    Use S3 Access Points to control access to specific customer subsets in the bucket.

  3. C

    Grant public read access to the bucket for easy data sharing among stakeholders.

  4. D

    Enable S3 Object Lock in compliance mode to prevent object deletion or modification.

  5. E

    Use bucket policies to allow access only to specific IAM roles and accounts.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To secure sensitive data on Amazon S3 and meet compliance standards, you must implement encryption, fine-grained access controls, and data immutability. Enabling AWS KMS-based encryption secures data at rest. S3 Access Points help enforce access controls for specific data subsets. Enabling S3 Object Lock in compliance mode ensures data immutability, and bucket policies can restrict access to authorized roles and accounts. Granting public read access, however, is a security risk and violates governance policies.

  • A. Correct.

    Enabling default encryption with an AWS KMS key ensures that all objects are encrypted at rest, which is a best practice for securing sensitive data.

  • B. Correct.

    S3 Access Points allow fine-grained access control for different applications and users, which can help meet governance requirements for accessing subsets of sensitive data.

  • C. Incorrect.

    Granting public read access exposes sensitive customer data to unauthorized users, violating governance and security policies, and should be avoided.

  • D. Correct.

    S3 Object Lock in compliance mode ensures objects cannot be deleted or modified, meeting regulatory requirements for data immutability in financial systems.

  • E. Correct.

    Using bucket policies to restrict access to specific IAM roles and accounts ensures only authorized entities can access the data, aligning with governance and security best practices.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam