AWS Certified Data Engineer Associate DEA-C01 Practice Question

Your data engineering team uses AWS Glue to transform data that lands in Amazon S3. To comply with EU data-sovereignty rules, every analytic object must remain in either eu-west-1 or eu-central-1. Across dozens of AWS accounts, you must prevent any resource creation or data replication in other Regions. Which solution BEST enforces this requirement?

  • Require SSE-KMS with customer-managed keys created in the EU Regions and mandate bucket policies that enforce encryption on all uploads.

  • Attach a service control policy (SCP) to the organization that denies all actions in Regions other than eu-west-1 and eu-central-1 by using the aws:RequestedRegion global condition key.

  • Turn on Amazon Macie automatic sensitive-data discovery and configure Security Hub to raise findings when objects are stored in non-EU Regions.

  • Enable S3 Object Lock on all buckets and configure default retention settings so that objects cannot be deleted or overwritten outside the EU.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot