DEA-C01 exam dumps

DEA-C01 practice question 489 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 489

Select 3

You are designing a data pipeline using AWS analytics services for a financial application. The pipeline involves storing sensitive financial data in Amazon Redshift, processing data with Amazon EMR, and transforming data using AWS Glue. Which encryption options should you use to ensure data is encrypted at rest and in transit across all services?

  1. A

    Enable Amazon Redshift encryption at rest using AWS Key Management Service (KMS).

  2. B

    Use server-side encryption with S3-managed keys (SSE-S3) for EMR intermediate data stored in Amazon S3.

  3. C

    Configure AWS Glue to use SSL/TLS for encrypting data in transit.

  4. D

    Enable Amazon Redshift to use client-side encryption for data at rest.

  5. E

    Use Amazon EMR's default encryption for data at rest without any additional configuration.

Show answer and explanation

Correct answers: A, B, C

Explanation

To secure sensitive financial data across all services, encryption must be applied both at rest and in transit. Amazon Redshift supports encryption at rest using AWS KMS. Amazon EMR, when integrated with S3, should use server-side encryption like SSE-S3 to protect intermediate data at rest. AWS Glue requires SSL/TLS to ensure data in transit is encrypted. These configurations collectively ensure end-to-end security for the data pipeline.

  • A. Correct.

    Enabling Amazon Redshift encryption at rest using AWS KMS ensures that all data stored in Redshift is encrypted with a managed key, which is a standard approach for securing sensitive data at rest.

  • B. Correct.

    Using server-side encryption with S3-managed keys (SSE-S3) ensures that intermediate data stored in Amazon S3 during EMR processing is encrypted at rest, making it compliant with security requirements.

  • C. Correct.

    Configuring AWS Glue to use SSL/TLS secures data in transit by encrypting communication between Glue and other services, meeting encryption requirements for sensitive financial data.

  • D. Incorrect.

    Client-side encryption is not typically used with Amazon Redshift as it relies on server-side encryption methods, such as using KMS, for securing data at rest.

  • E. Incorrect.

    Amazon EMR's default configuration does not provide encryption for data at rest unless explicitly configured. You need to specify encryption options such as SSE-S3 or SSE-KMS for data stored in S3.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam