AWS Certified Data Engineer Associate DEA-C01 Practice Question
A company keeps PII data in an Amazon S3 data lake in us-east-1. Compliance demands that PII objects never be copied or replicated to S3 buckets in any other Region, and that Athena queries expose PII columns only to approved IAM roles. The data engineers want a low-maintenance, AWS-native solution. Which approach meets both requirements?
Create S3 bucket policies that check aws:PrincipalArn and deny object uploads to buckets outside us-east-1, and use IAM permission boundaries to limit Athena access to PII columns.
Deploy an AWS Config rule that detects S3 buckets in disallowed Regions and manually remediates them, and create Athena views that exclude PII columns for most users.
Enable Amazon S3 Block Public Access on every bucket and configure same-Region replication; use Redshift column-level privileges to control access for Athena queries via Redshift Spectrum.
Attach an AWS Organizations SCP that denies s3:PutObject and s3:ReplicateObject when the aws:RequestedRegion is not us-east-1, and implement Amazon Lake Formation LF-tag-based access control to restrict PII columns.
An AWS Organizations service control policy (SCP) can impose account-wide guardrails that block S3 API calls-such as cross-Region replication (s3:ReplicateObject) or user-initiated copies (s3:PutObject)-when aws:RequestedRegion is not us-east-1, ensuring PII objects cannot be stored outside the approved Region. Amazon Lake Formation LF-tag-based access control lets administrators tag PII columns and grant the tag only to authorized roles, so Athena masks those columns for other analysts. Competing approaches rely on bucket policies that are hard to maintain, services that do not provide organization-wide Region control, or mechanisms that cannot enforce fine-grained column governance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an AWS Organizations SCP?
Open an interactive chat with Bash
What is Amazon Lake Formation LF-tag-based access control?
Open an interactive chat with Bash
Why is the proposed solution preferable to using bucket policies?
Open an interactive chat with Bash
What is an AWS Organizations SCP?
Open an interactive chat with Bash
What is Amazon Lake Formation LF-tag-based access control?
Open an interactive chat with Bash
How does Athena query permissions interact with IAM roles?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .