AWS Certified Data Engineer Associate DEA-C01 Practice Question

A media company stores incoming customer records in multiple Amazon S3 buckets registered with AWS Lake Formation. Data engineers must automatically discover PII in every new object and block Amazon Athena users who have the analyst role from querying PII columns, while minimizing ongoing code maintenance. Which solution meets these requirements?

  • Configure Amazon S3 Object Lambda to invoke a Lambda function that redacts PII at request time and direct analysts to query the data through the Object Lambda access points.

  • Schedule AWS Glue crawlers with custom classifiers to look for common PII patterns, then manually update Lake Formation permissions after each crawl to block analyst access to identified columns.

  • Enable Amazon Macie automated sensitive data discovery for the buckets, publish findings to Amazon EventBridge, invoke a Lambda function that adds an LF-tag such as pii=yes to the affected Glue Data Catalog columns, and create Lake Formation column-level permissions that deny the analyst role access to that tag.

  • Create AWS Config rules that detect unencrypted S3 objects and apply an IAM service control policy that blocks Athena queries against those objects across the account.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot