AWS Certified Data Engineer Associate DEA-C01 Practice Question

A multinational retailer stores product images and customer PII in an Amazon S3 bucket in eu-west-1. Business analysts in us-east-1 need access to only non-sensitive objects for ad-hoc reporting. How can a data engineer ensure that objects containing PII never replicate outside the EU while other objects continue to replicate automatically with the least operational overhead?

  • Attach an IAM permission boundary to the replication role that denies s3:PutObject to the destination bucket when the object prefix indicates /pii/ data.

  • Use Amazon Macie to classify the source bucket and publish findings to Amazon EventBridge; trigger an AWS Lambda function that tags flagged objects with pii=true, and configure an S3 replication rule that only replicates objects whose tag pii=false.

  • Enable S3 Object Lock compliance mode on the source bucket and place a legal hold on objects identified as PII so replication skips locked objects.

  • Encrypt the destination bucket with a customer-managed KMS key restricted to EU principals; replicated PII objects will be unreadable outside the EU.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot