DEA-C01 exam dumps

DEA-C01 practice question 501 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 501

Select 3

You are designing a data pipeline for a healthcare application that processes sensitive patient data. To comply with data privacy regulations, you need to anonymize personally identifiable information (PII), such as patient names and social security numbers, while ensuring that the data remains usable for analytics. Which of the following approaches would help achieve this requirement?

  1. A

    Use AWS Glue to apply data masking by substituting sensitive values with random characters.

  2. B

    Use AWS KMS to encrypt PII data and store the encryption keys within the data pipeline.

  3. C

    Apply key salting to hash sensitive data consistently while preventing reverse engineering.

  4. D

    Use Amazon Macie to automatically detect and delete all PII from the dataset.

  5. E

    Apply deterministic encryption to PII fields to allow repeatable anonymized values for analytics.

Show answer and explanation

Correct answers: A, C, E

Explanation

Anonymizing sensitive data while keeping it usable for analytics requires techniques like data masking, deterministic encryption, and key salting. These methods ensure compliance with privacy regulations while preserving the data's utility. AWS KMS encryption and Amazon Macie, though useful for data security and detection, do not directly fulfill the requirement of anonymization for analytical purposes.

  • A. Correct.

    Using AWS Glue for data masking is a valid approach to anonymize data by replacing sensitive information with obfuscated values.

  • B. Incorrect.

    While AWS KMS can encrypt data, simply encrypting the data without applying anonymization techniques does not meet the requirement of making the data usable for analytics.

  • C. Correct.

    Key salting ensures that hashed sensitive data is protected from reverse engineering while maintaining consistency, making it a suitable approach for anonymization.

  • D. Incorrect.

    Amazon Macie detects sensitive data but does not provide anonymization or masking capabilities. Deleting all PII would prevent the data from being usable for analytics.

  • E. Correct.

    Deterministic encryption produces consistent outputs for the same input, allowing anonymized values to be used for analytics while protecting sensitive information.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam