DEA-C01 exam dumps

DEA-C01 practice question 541 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 541

Select 4

You are designing a data pipeline to process customer data that includes personally identifiable information (PII). The processed data will be stored in Amazon S3 and analyzed using Amazon Athena. Which approaches should you implement to ensure the PII is protected and compliant with data privacy regulations?

  1. A

    Encrypt the data at rest in Amazon S3 using AWS Key Management Service (KMS).

  2. B

    Use Amazon Macie to identify and classify PII in the stored data.

  3. C

    Grant public read access to the S3 bucket to simplify data sharing.

  4. D

    Implement column-level encryption for PII fields in the data using AWS Glue.

  5. E

    Ensure the IAM policies for accessing the S3 bucket follow the principle of least privilege.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To protect PII in compliance with data privacy regulations, it is essential to implement security and access control measures such as encryption at rest (using AWS KMS), classification of sensitive data (using Amazon Macie), granular encryption of PII fields (column-level encryption), and access policies based on the principle of least privilege. Granting public access to the S3 bucket is not a valid approach as it exposes PII to unauthorized access, which violates compliance standards.

  • A. Correct.

    Encrypting data at rest using AWS Key Management Service (KMS) ensures that the PII stored in Amazon S3 is protected, even in the event of unauthorized access to the storage layer.

  • B. Correct.

    Amazon Macie is a service that uses machine learning to identify and classify sensitive data, including PII, which helps ensure compliance with data privacy requirements.

  • C. Incorrect.

    Granting public read access to the S3 bucket exposes the data, including PII, to unauthorized users. This approach directly violates data protection and privacy regulations.

  • D. Correct.

    Implementing column-level encryption for specific PII fields ensures additional security by encrypting sensitive data fields individually, which enhances data protection.

  • E. Correct.

    Restricting access to the S3 bucket using IAM policies that follow the principle of least privilege limits access to only those users or roles that absolutely need it, reducing the risk of unauthorized access to PII.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam