DEA-C01 exam dumps

DEA-C01 practice question 479 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 479

Select 3

You are a Data Engineer working for a healthcare company that processes sensitive patient data. You are designing a data pipeline in AWS that ingests data into Amazon S3, processes it using AWS Glue, and stores results in an Amazon Redshift data warehouse. To meet compliance requirements, you must ensure that all sensitive data is encrypted and patient identifiers are masked during processing. Which combination of actions will fulfill these requirements?

  1. A

    Enable server-side encryption (SSE) on the Amazon S3 bucket where the data is stored.

  2. B

    Use Amazon Redshift's column-level encryption to encrypt sensitive fields.

  3. C

    Use AWS Glue's built-in support for data masking transformations to anonymize patient identifiers.

  4. D

    Disable default encryption on the Amazon S3 bucket since AWS Glue will handle encryption during processing.

  5. E

    Enable client-side encryption for uploading data into Amazon S3 using an AWS KMS-managed key.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet compliance requirements for encryption and masking in this scenario, you need to ensure data is encrypted at rest (Amazon S3 and Amazon Redshift) and sensitive data is masked during processing (AWS Glue). Enabling server-side encryption for S3, column-level encryption for Redshift, and using AWS Glue's data masking transformations fulfill these requirements. Disabling encryption or relying solely on client-side encryption would not completely meet the requirements.

  • A. Correct.

    This option is correct because enabling server-side encryption (SSE) on the S3 bucket ensures that data at rest in S3 is encrypted, meeting part of the compliance requirement.

  • B. Correct.

    This option is correct because Amazon Redshift supports column-level encryption, which allows you to encrypt specific sensitive fields, ensuring encryption in the data warehouse.

  • C. Correct.

    This option is correct because AWS Glue supports data masking transformations, allowing you to anonymize sensitive data such as patient identifiers, which is required for compliance.

  • D. Incorrect.

    This option is incorrect because disabling encryption on the S3 bucket would expose data at rest to potential security risks and violate compliance requirements.

  • E. Incorrect.

    This option is incorrect because while client-side encryption is a valid approach, it is not required in this scenario since AWS-managed solutions like SSE and AWS KMS provide sufficient encryption capabilities.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam