AWS Certified Data Engineer Associate DEA-C01 Practice Question

The analytics team stores PII in an Amazon S3 data lake in us-east-2 and protects it with AWS Backup. Company policy mandates that no backups or object replicas may ever leave us-east-2. You need an organization-wide control that prevents any engineer from configuring cross-Region replication or AWS Backup copy jobs to other Regions while still allowing normal operations in us-east-2. Which approach meets the requirement with minimal ongoing maintenance?

  • Create VPC interface endpoints for Amazon S3 and AWS Backup only in us-east-2 and delete the endpoints in all other AWS Regions.

  • Attach an AWS Organizations SCP that denies s3:PutBucketReplication, s3:CreateBucket, and backup:StartCopyJob whenever aws:RequestedRegion or s3:LocationConstraint is not "us-east-2", and apply the policy to the OU that contains all data accounts.

  • Encrypt all recovery points with a customer-managed AWS KMS key that exists solely in us-east-2 and rotate the key quarterly.

  • Enable Amazon S3 Same-Region Replication on every bucket and remove all cross-Region copy rules from existing AWS Backup plans.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot