DEA-C01 exam dumps

DEA-C01 practice question 478 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 478

Select 3

A financial company is using Amazon S3 to store sensitive customer data, including personally identifiable information (PII). They need to ensure that the data is encrypted at rest and also masked when accessed by unauthorized users. Which of the following steps should the company take to meet these requirements?

  1. A

    Enable default server-side encryption (SSE) on the S3 bucket with AWS Key Management Service (KMS) and enforce encryption through bucket policies.

  2. B

    Use AWS Glue DataBrew to mask sensitive data by applying data transformations before exposing it to unauthorized users.

  3. C

    Configure S3 Object Lock to ensure data masking is applied to all sensitive objects.

  4. D

    Use client-side encryption to encrypt the data before uploading it to Amazon S3.

  5. E

    Implement AWS Lake Formation to define fine-grained access controls and mask sensitive columns when accessed by unauthorized users.

Show answer and explanation

Correct answers: A, B, E

Explanation

To ensure data encryption and masking, the company must encrypt data at rest and implement access controls to mask sensitive information for unauthorized users. Enabling server-side encryption with AWS KMS meets the encryption requirement. AWS Glue DataBrew provides masking capabilities, while AWS Lake Formation allows for fine-grained access control and masking of sensitive data. S3 Object Lock and client-side encryption do not meet the masking requirements in this scenario.

  • A. Correct.

    Correct: Enabling server-side encryption with AWS KMS ensures that the data is encrypted at rest in the S3 bucket. Enforcing encryption through bucket policies ensures compliance.

  • B. Correct.

    Correct: AWS Glue DataBrew can be used to mask sensitive data through data transformations, ensuring that unauthorized users do not access raw PII.

  • C. Incorrect.

    Incorrect: S3 Object Lock is used for write-once-read-many (WORM) protection to prevent data deletions or modifications, but it does not provide masking functionality.

  • D. Incorrect.

    Incorrect: While client-side encryption encrypts data before it is uploaded, it does not address the requirement for data masking when accessed by unauthorized users.

  • E. Correct.

    Correct: AWS Lake Formation allows fine-grained access control and provides column-level security, including data masking for unauthorized users.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam