DEA-C01 exam dumps

DEA-C01 practice question 530 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 530

Select 3

You are designing a data lake on Amazon S3 to store customer data, including personally identifiable information (PII). The company must comply with GDPR regulations to ensure data privacy and governance. Which of the following actions should you take to meet these requirements?

  1. A

    Enable S3 Server-Side Encryption for all buckets storing customer data.

  2. B

    Use Amazon Macie to discover and classify PII data stored in the data lake.

  3. C

    Set up S3 Lifecycle policies to delete data flagged as PII after 30 days.

  4. D

    Restrict access to the S3 buckets storing PII using IAM policies and bucket policies.

  5. E

    Enable S3 Transfer Acceleration to ensure secure data uploads.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet GDPR requirements for data privacy and governance, you must ensure that sensitive data, such as PII, is encrypted at rest, access-controlled, and discoverable for compliance audits. Enabling S3 Server-Side Encryption, using Amazon Macie to classify PII data, and restricting access through IAM and bucket policies are key actions to achieve this. S3 Transfer Acceleration and lifecycle policies, while useful in other scenarios, do not directly address GDPR compliance needs.

  • A. Correct.

    Correct: Enabling S3 Server-Side Encryption ensures that customer data is encrypted at rest, a key requirement for GDPR compliance.

  • B. Correct.

    Correct: Amazon Macie is a tool that helps identify and classify PII data, which is essential for meeting data privacy and governance requirements.

  • C. Incorrect.

    Incorrect: While automating data deletion can be useful, GDPR compliance requires more than just data lifecycle management, including data discovery, access control, and encryption.

  • D. Correct.

    Correct: Restricting access to the S3 buckets using IAM policies and bucket policies ensures that only authorized users can access sensitive PII data.

  • E. Incorrect.

    Incorrect: S3 Transfer Acceleration improves data transfer speed but does not specifically address data privacy or governance requirements.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam