DEA-C01 exam dumps

DEA-C01 practice question 488 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 488

Select 4

A data engineering team is designing a secure data processing pipeline using AWS analytics services. They want to ensure that all sensitive data is encrypted at rest and in transit. Which of the following encryption options are available for AWS analytics services like Amazon Redshift, Amazon EMR, and AWS Glue?

  1. A

    Use AWS Key Management Service (KMS) to manage encryption keys for data at rest.

  2. B

    Enable Transparent Data Encryption (TDE) for encrypting sensitive data in Amazon Redshift.

  3. C

    Use SSL/TLS for encrypting data during transit between services.

  4. D

    Enable HDFS encryption on Amazon EMR for encrypting data at rest.

  5. E

    Use AWS Glue's default encryption feature to encrypt data stored in S3.

Show answer and explanation

Correct answers: A, C, D, E

Explanation

AWS analytics services like Amazon Redshift, Amazon EMR, and AWS Glue provide robust encryption options to secure data both at rest and in transit. AWS Key Management Service (KMS) is commonly used for managing encryption keys for data at rest. SSL/TLS ensures secure communication of data in transit. For Amazon EMR, HDFS encryption can secure data at rest. AWS Glue supports default encryption for data stored in S3. However, Transparent Data Encryption (TDE) is not supported by any of these services, making it an invalid option.

  • A. Correct.

    AWS Key Management Service (KMS) can be used with Amazon Redshift, Amazon EMR, and AWS Glue to encrypt data at rest, making this a valid option.

  • B. Incorrect.

    Transparent Data Encryption (TDE) is not supported in Amazon Redshift. Instead, Redshift integrates with AWS KMS for encryption at rest.

  • C. Correct.

    SSL/TLS is commonly used in AWS analytics services like Amazon Redshift and AWS Glue to encrypt data in transit, making this a valid option.

  • D. Correct.

    Amazon EMR supports HDFS encryption for encrypting data at rest, managed via AWS KMS.

  • E. Correct.

    AWS Glue supports default encryption for data written to S3, which can be configured to use AWS KMS keys for encryption.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam