DEA-C01 exam dumps

DEA-C01 practice question 475 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 475

Select 3

Your company is building a data lake on Amazon S3 to store sensitive customer data, including personally identifiable information (PII). The data pipeline uses AWS Glue for ETL (Extract, Transform, Load) operations and Amazon Athena for querying. To comply with regulatory requirements, you need to implement data encryption and ensure sensitive data, such as customer names and credit card numbers, is protected during storage and querying. Which combination of steps should you take to achieve this?

  1. A

    Enable server-side encryption (SSE) on the S3 bucket using Amazon S3-managed keys (SSE-S3).

  2. B

    Use AWS Glue's built-in data masking feature to mask sensitive fields during the ETL process.

  3. C

    Enable client-side encryption for all data uploaded to the S3 bucket.

  4. D

    Configure Athena to use encryption with AWS Key Management Service (KMS) for query results.

  5. E

    Use AWS Glue's connection options to disable encryption for temporary data storage during ETL.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure data encryption and masking with regulatory compliance, you must encrypt data at rest and in transit, mask sensitive data during processing, and encrypt query results. Enabling SSE-S3 ensures encryption at rest for the S3 bucket. AWS Glue's data masking capabilities protect sensitive fields during ETL. Finally, configuring Athena to use KMS encryption for query results secures the output data. Client-side encryption and disabling encryption are either unnecessary or counterproductive in this scenario.

  • A. Correct.

    Enabling server-side encryption (SSE) on the S3 bucket using Amazon S3-managed keys (SSE-S3) ensures that all data stored in S3 is encrypted at rest. This is a basic and essential step for protecting sensitive data.

  • B. Correct.

    AWS Glue offers built-in transformations, including data masking, that can be used to obfuscate sensitive data such as PII. This ensures that sensitive fields remain protected while processing data.

  • C. Incorrect.

    Client-side encryption can be used, but it introduces additional operational complexity and is not a straightforward requirement for this scenario since SSE-S3 or AWS KMS can handle encryption effectively.

  • D. Correct.

    Configuring Athena to use encryption with AWS Key Management Service (KMS) ensures that query results are encrypted when stored in S3. This is critical for maintaining data security throughout the pipeline.

  • E. Incorrect.

    Disabling encryption for temporary data storage during ETL directly contradicts the goal of ensuring data security and compliance with regulatory requirements.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam