DEA-C01 exam dumps

DEA-C01 practice question 543 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 543

Select 3

A company is designing a data pipeline on AWS that processes customer data, including personally identifiable information (PII). The processed data will be stored in Amazon S3. How can the company ensure the PII is protected during storage and processing, while also allowing authorized users to access it securely?

  1. A

    Use Amazon Macie to classify and protect PII data in Amazon S3.

  2. B

    Encrypt the data using AWS Key Management Service (AWS KMS) before storing it in Amazon S3.

  3. C

    Store PII data in plaintext in Amazon S3, but restrict access using AWS Identity and Access Management (IAM) policies.

  4. D

    Enable S3 bucket versioning to ensure data is never lost and can be recovered.

  5. E

    Use server-side encryption with S3-managed keys (SSE-S3) to automatically encrypt data at rest.

Show answer and explanation

Correct answers: A, B, E

Explanation

Protecting PII in AWS requires a combination of tools and practices. Amazon Macie helps classify and detect PII, while encryption (using AWS KMS or SSE-S3) ensures the data is secure at rest. These approaches ensure compliance with data protection regulations and reduce the risk of unauthorized access. Storing plaintext PII or relying solely on IAM policies is insufficient for protecting sensitive data.

  • A. Correct.

    Amazon Macie is a fully managed data security and data privacy service that helps identify and protect PII stored in Amazon S3. It is an essential tool for compliance and data protection.

  • B. Correct.

    Encrypting the data using AWS KMS ensures that PII is protected at rest by providing strong encryption mechanisms and fine-grained access control to encryption keys.

  • C. Incorrect.

    Storing PII in plaintext, even with strict IAM policies, is not recommended. Encryption is essential to protect sensitive data.

  • D. Incorrect.

    While enabling S3 bucket versioning is a good practice for data recovery, it does not directly contribute to protecting PII.

  • E. Correct.

    Using server-side encryption with S3-managed keys (SSE-S3) ensures that data is automatically encrypted at rest, providing an additional layer of security for PII.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam