AWS Certified Data Engineer Associate DEA-C01 Practice Question

A company keeps PII data in an Amazon S3 data lake in us-east-1. Compliance demands that PII objects never be copied or replicated to S3 buckets in any other Region, and that Athena queries expose PII columns only to approved IAM roles. The data engineers want a low-maintenance, AWS-native solution. Which approach meets both requirements?

  • Create S3 bucket policies that check aws:PrincipalArn and deny object uploads to buckets outside us-east-1, and use IAM permission boundaries to limit Athena access to PII columns.

  • Deploy an AWS Config rule that detects S3 buckets in disallowed Regions and manually remediates them, and create Athena views that exclude PII columns for most users.

  • Enable Amazon S3 Block Public Access on every bucket and configure same-Region replication; use Redshift column-level privileges to control access for Athena queries via Redshift Spectrum.

  • Attach an AWS Organizations SCP that denies s3:PutObject and s3:ReplicateObject when the aws:RequestedRegion is not us-east-1, and implement Amazon Lake Formation LF-tag-based access control to restrict PII columns.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot