AWS Certified Data Engineer Associate DEA-C01 Practice Question
An online marketplace stores raw customer data, such as email addresses and credit-card numbers, in an Amazon S3 data lake. Compliance requires that newly ingested objects be automatically scanned for PII and that Amazon Athena queries expose only non-sensitive columns to data analysts. The data must stay in place, and the solution must use only AWS managed services. Which approach satisfies these requirements?
Deploy Amazon Inspector to scan the bucket and use AWS Config rules to move files with PII to a separate prefix inaccessible to analysts.
Enable Amazon GuardDuty S3 protection and attach IAM policies that deny access to objects tagged as sensitive.
Run an AWS Glue crawler to catalog the S3 data and create IAM policies that block analysts from reading columns identified as PII by the crawler.
Set up an Amazon Macie sensitive-data discovery job on the S3 bucket and use the findings to apply LF-tags in AWS Lake Formation that restrict column-level access for Athena queries.
Amazon Macie can be configured to run recurring sensitive-data discovery jobs on the S3 bucket. Macie's findings are published to Amazon EventBridge, where a rule can invoke an AWS Lambda function to create or update LF-tags in AWS Lake Formation that mark columns containing PII. Lake Formation then enforces column-level permissions so that Athena reveals only non-sensitive data to analysts. The other options fail to provide both automated PII discovery and column-level governance with supported AWS services: GuardDuty detects security threats, not PII; AWS Glue crawlers and IAM policies do not classify or mask sensitive columns automatically; Amazon Inspector and AWS Config cannot scan S3 objects for PII or manage column-level access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Amazon Macie and how does it identify PII?
Open an interactive chat with Bash
What are LF-tags in AWS Lake Formation and how are they used?
Open an interactive chat with Bash
How does Amazon EventBridge interact with AWS Lambda in this solution?
Open an interactive chat with Bash
What is Amazon Macie and how does it help identify PII?
Open an interactive chat with Bash
How do LF-tags in AWS Lake Formation help enforce column-level access control?
Open an interactive chat with Bash
Why is Amazon GuardDuty not suitable for PII detection in this scenario?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .