DEA-C01 exam dumps

DEA-C01 practice question 545 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 545

Select 3

Your company operates in multiple countries, including regions with strict data sovereignty laws. You are tasked with designing a data pipeline on AWS to process and store sensitive customer information. Which combination of actions ensures compliance with data sovereignty requirements?

  1. A

    Use AWS Regions that align with the data residency requirements of each country where your company operates.

  2. B

    Enable cross-region replication in S3 to ensure high availability of customer data across multiple regions.

  3. C

    Implement IAM policies that restrict access to data based on user roles and geographic location.

  4. D

    Use AWS Key Management Service (KMS) with customer-managed keys stored in the required region to encrypt sensitive data.

  5. E

    Utilize Amazon CloudFront to cache customer data globally for faster access.

Show answer and explanation

Correct answers: A, C, D

Explanation

Data sovereignty laws require organizations to ensure that sensitive data remains within specified geographic locations and is handled according to specific legal and regulatory requirements. By choosing AWS Regions that comply with these requirements, implementing IAM policies to enforce access restrictions, and using AWS KMS with customer-managed keys in the correct region, you can ensure compliance. However, enabling cross-region replication or globally caching data could lead to violations of data sovereignty laws.

  • A. Correct.

    This option is correct as data sovereignty laws often require data to remain within specific geographic regions. Choosing the appropriate AWS Region ensures compliance.

  • B. Incorrect.

    This option is incorrect because cross-region replication could violate data sovereignty laws if data is replicated to regions outside the required geographic boundaries.

  • C. Correct.

    This option is correct as IAM policies can help enforce access control and restrict data handling based on geographic or organizational requirements, supporting compliance with data sovereignty regulations.

  • D. Correct.

    This option is correct as AWS KMS with customer-managed keys in the appropriate region allows for secure encryption of sensitive data while ensuring compliance with regional data residency requirements.

  • E. Incorrect.

    This option is incorrect because caching data globally via CloudFront could lead to non-compliance with data sovereignty regulations if sensitive customer data is cached in regions where it should not reside.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam