DEA-C01 exam dumps

DEA-C01 practice question 544 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 544

Select 4

You are working as a data engineer for a healthcare company that stores patient information in Amazon S3. The data includes personally identifiable information (PII) such as names, addresses, and Social Security numbers. To comply with regulatory requirements, you must ensure that PII is properly protected while still allowing analysts to query non-sensitive data. Which combination of actions should you take to protect PII in this scenario?

  1. A

    Use AWS Key Management Service (KMS) to encrypt the S3 bucket storing the data.

  2. B

    Implement Amazon Macie to automatically discover and classify sensitive data in the S3 bucket.

  3. C

    Use Amazon S3 Object Lock to prevent deletions of data containing PII.

  4. D

    Tokenize PII fields during data ingestion and store the tokens in place of the original data.

  5. E

    Use AWS Lake Formation to define column-level permissions on sensitive PII fields.

  6. F

    Enable Amazon S3 Transfer Acceleration to ensure secure and fast uploads of data to the bucket.

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To protect PII, a combination of encryption, data classification, and access control mechanisms is required. AWS KMS secures data at rest, while Amazon Macie helps identify sensitive information. Tokenization reduces the risk of exposing sensitive data, and AWS Lake Formation provides fine-grained access control for PII fields. These measures together ensure the security and compliance of PII data, while options like Amazon S3 Object Lock and Transfer Acceleration are not directly relevant to protecting PII.

  • A. Correct.

    Encrypting the S3 bucket using AWS KMS ensures that the data at rest is protected and meets compliance requirements for secure storage.

  • B. Correct.

    Amazon Macie helps discover and classify sensitive data like PII, ensuring proper handling and compliance with regulations.

  • C. Incorrect.

    Amazon S3 Object Lock is designed for data immutability and is not directly related to protecting PII from unauthorized access.

  • D. Correct.

    Tokenizing PII fields replaces sensitive data with non-sensitive equivalents, reducing exposure to risk while still enabling data usage.

  • E. Correct.

    AWS Lake Formation allows the implementation of fine-grained access controls, such as column-level permissions, which help restrict access to PII fields.

  • F. Incorrect.

    Amazon S3 Transfer Acceleration improves upload performance but does not specifically contribute to protecting PII.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam