DEA-C01 exam dumps

DEA-C01 practice question 531 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 531

Select 3

You are designing a data pipeline using Amazon S3, AWS Glue, and Amazon Redshift to process and store sensitive customer data. As part of your organization's data privacy compliance, you must ensure that the data is encrypted at rest, access is restricted to authorized users, and audit logs are available for access review. Which actions should you take to meet these requirements?

  1. A

    Enable server-side encryption with AWS Key Management Service (SSE-KMS) for Amazon S3.

  2. B

    Use IAM policies to restrict access to the data in Amazon S3, AWS Glue, and Amazon Redshift.

  3. C

    Disable CloudTrail logging to reduce operational overhead.

  4. D

    Enable encryption for the Amazon Redshift cluster using an AWS KMS key.

  5. E

    Store the encryption keys in plaintext within an Amazon S3 bucket for easy access.

Show answer and explanation

Correct answers: A, B, D

Explanation

To address data privacy and governance requirements, it is crucial to ensure that all data storage services (Amazon S3 and Redshift) use encryption to protect data at rest. Additionally, using IAM policies enforces access restrictions to authorized users. Enabling CloudTrail logging is vital for access review and audit purposes. Avoid practices like storing encryption keys in plaintext, as this compromises security.

  • A. Correct.

    Enabling server-side encryption with AWS KMS ensures that data stored in Amazon S3 is encrypted at rest, addressing the data privacy requirement.

  • B. Correct.

    Using IAM policies to restrict access ensures that only authorized users can access the data, meeting the governance requirement.

  • C. Incorrect.

    Disabling CloudTrail logging would prevent audit logs from being generated, which is contrary to the requirement of having logs for access review.

  • D. Correct.

    Enabling encryption for the Amazon Redshift cluster ensures that data stored in Redshift is encrypted at rest, meeting the data privacy requirement.

  • E. Incorrect.

    Storing encryption keys in plaintext in an S3 bucket violates security best practices and data privacy requirements.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam