DEA-C01 exam dumps

DEA-C01 practice question 477 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 477

Select 3

You are designing a data pipeline on AWS to process sensitive customer information stored in Amazon S3. The data must be encrypted at rest and in transit, and certain sensitive fields, such as Social Security Numbers (SSNs), must be masked in the output files. Which combination of actions should you take to meet these requirements?

  1. A

    Enable server-side encryption with AWS KMS for the S3 bucket storing the data.

  2. B

    Use Amazon Macie to automatically mask sensitive fields such as Social Security Numbers during data processing.

  3. C

    Configure client-side encryption for data uploaded to S3 using a custom encryption key.

  4. D

    Implement AWS Glue DataBrew to create a recipe for masking sensitive fields like SSNs.

  5. E

    Enable HTTPS for all data transfers to and from Amazon S3 to ensure encryption in transit.

  6. F

    Use the AWS Key Management Service (KMS) to rotate encryption keys manually every 30 days.

Show answer and explanation

Correct answers: A, D, E

Explanation

To ensure data encryption and masking, you need to encrypt data at rest, encrypt it in transit, and mask sensitive fields. Enabling server-side encryption with AWS KMS for the S3 bucket secures data at rest. Using AWS Glue DataBrew allows you to mask sensitive fields like SSNs during processing, and enabling HTTPS ensures encryption of data in transit. Other options, such as using Amazon Macie or manually rotating keys with AWS KMS, do not fully align with the requirements or add unnecessary complexity.

  • A. Correct.

    This is correct because enabling server-side encryption with AWS KMS ensures data is encrypted at rest in the S3 bucket.

  • B. Incorrect.

    Amazon Macie does not provide masking functionality; its primary role is to identify and classify sensitive data, not mask it.

  • C. Incorrect.

    While client-side encryption is an option, it is generally not necessary when using AWS-managed server-side encryption for data at rest. This approach also adds complexity unnecessarily in this scenario.

  • D. Correct.

    This is correct because AWS Glue DataBrew enables you to build recipes to mask sensitive fields like Social Security Numbers during data processing.

  • E. Correct.

    This is correct because enabling HTTPS ensures that data is encrypted during transit to and from Amazon S3.

  • F. Incorrect.

    While AWS KMS can be used for key management, manually rotating encryption keys every 30 days is not a requirement in this scenario, and AWS KMS can automate key rotation to simplify operations.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam