DEA-C01 · domain
Data Security and Governance
This domain covers encryption at rest and in transit, IAM and Lake Formation permissions, and audit/governance controls across AWS analytics services. Questions are scenario-based: you pick the right encryption option for S3, RDS, or Redshift, diagnose access-denied errors, or sequence a DMS migration with correct credentials and endpoints.
Focused practice
Practice Data Security and Governance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Data Security and Governance
Be able to choose the correct encryption mechanism per service, grant least-privilege access through IAM and Lake Formation, and read permission-denied errors to find the missing schema, role, or policy. The single most important skill is mapping a data-access failure to its exact AWS control.
Selecting SSE-S3, SSE-KMS, or SSE-C for Amazon S3 data-at-rest encryption
Granting Lake Formation table and column permissions for Athena and Redshift Spectrum
Enforcing TLS for Amazon RDS for MySQL connections with require_secure_transport
Diagnosing Redshift 'permission denied for relation' from schema, ownership, or search_path issues
Watch out for
Common Data Security and Governance exam traps
- ▸Assuming a table-level SELECT grant is sufficient in Redshift when the user also lacks USAGE on the schema or is not the owner.
- ▸Confusing SSE-C, where the customer supplies and manages the key, with SSE-KMS, where AWS KMS stores and rotates the key.
- ▸Forgetting that AWS DMS needs source and target endpoints plus a replication instance and IAM roles before starting the task.
Question index
All Data Security and Governance questions (246)
Click any question to see the full explanation, or start a practice session above.
A data engineer is configuring an AWS Glue job that reads from an Amazon RDS for MySQL database and writes to Amazon S3. The security team requires that the data be encrypted in transit between AWS Glue and Amazon RDS. Which action should the engineer take to meet this requirement?
Medium2A data engineer manages an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another S3 bucket. Both buckets are encrypted with SSE-KMS using customer managed keys. The Glue job execution role has permissions to read from the source bucket and write to the target bucket, and has kms:Decrypt permission on the source key, but the job fails with an error indicating it cannot write to the target bucket due to encryption. What is the MOST likely cause?
Medium3A data engineer notices that an S3 bucket policy allows access to a user from another AWS account, but the access is being denied. What could be the reason?
Hard4A company has a multi-account AWS environment with a centralized data lake in the Security account. Data producers in other accounts use AWS Glue to write data to S3 buckets in the Security account. The Security account uses AWS Lake Formation to manage permissions. The data engineer is setting up cross-account access so that users in the Producer account can query the data using Athena in their own account. The engineer has registered the S3 buckets and Data Catalog tables in Lake Formation. The IAM roles in the Producer account have the necessary permissions. However, when a user in the Producer account tries to query the table, they get an AccessDenied error. The error message indicates that the principal is not authorized to perform lakeformation:GetTable on the resource. What is the most likely cause?
Hard5A company wants to audit all data access events in their S3 buckets, including who accessed objects and from which IP address. Which AWS service should be used to capture these events?
Easy6A company needs to audit all API calls made in their AWS account, including actions performed by the root user. Which AWS service should be used?
Easy7A company stores regulated records in an Amazon S3 bucket and must prove that individual objects cannot be deleted or overwritten for 365 days after creation, even by the account root user. The compliance team also needs to retain the ability to delete the bucket itself after the retention window expires. Which configuration meets these requirements?
Hard8A data engineer is building an AWS Lake Formation governed data lake. The security team wants to grant a group of analysts access to only the non-sensitive columns of a table in the Data Catalog, while denying access to columns containing Social Security numbers. The analysts use Amazon Athena to query the data. Which Lake Formation permission model should the data engineer use?
Medium9A data engineer is troubleshooting an issue where an AWS Glue ETL job fails when trying to read data from an S3 bucket encrypted with SSE-KMS. The job has an IAM role that includes `kms:Decrypt` permission. What is the most likely reason for the failure?
Medium10A data engineer needs to ensure that an Amazon Redshift cluster encrypts all data at rest. Which setting must be enabled when creating the cluster?
Easy11A data engineer is troubleshooting an Amazon Redshift cluster that is not allowing connections from a specific IP range. The engineer verified that the cluster's security group allows inbound traffic from the IP range. What is the next step to resolve the issue?
Hard12A company uses Amazon Redshift to store customer data. The security team requires that all queries are logged for auditing purposes. Which step should be taken to meet this requirement? (Select ONE.)
Medium13A data engineer stores sensitive records in an Amazon S3 bucket. The security team wants to guarantee that every object is encrypted before it is written to disk and that the bucket automatically rejects any unencrypted PUT request, regardless of which IAM principal sends it. Which configuration should the data engineer apply?
Easy14A data engineer is designing a data lake on Amazon S3 that will store sensitive financial data. The security team requires that access to the data be audited, that data be encrypted at rest with customer-managed keys, and that the engineer be able to identify which IAM principals accessed specific objects. Which TWO AWS services or features should the engineer use to meet these requirements? (Choose two.)
Hard15A company stores raw customer records in an Amazon S3 bucket and processes them with AWS Glue. A governance requirement states that a specific tag named DataClass must exist on every catalog table, and any table missing that tag must not be queryable. Where should the data engineer enforce this requirement with the least operational effort?
Easy16A data engineer is designing a data lake on S3 and needs to ensure that data is encrypted at rest using customer-managed KMS keys. The engineer also needs to audit all access to the KMS keys. Which combination of services should be used?
Medium17A data engineer needs to enforce that all data in an Amazon S3 bucket is encrypted at rest. Which of the following can be used to achieve this? (Choose TWO.)
Easy18A company wants to securely store database credentials used by a Lambda function. Which AWS service should be used to store and rotate the credentials automatically?
Easy19A company uses AWS Glue to run ETL jobs on data stored in S3. The data is encrypted with SSE-KMS. The Glue job fails with an 'AccessDenied' error when trying to read the data. What is the MOST likely cause?
Medium20A company wants to enforce encryption in transit for data moving between an EC2 instance and an S3 bucket. Which TWO methods can achieve this? (Choose 2)
Easy21An organization is using AWS Glue to process sensitive data. The data is stored in S3 with server-side encryption using AWS KMS (SSE-KMS). The Glue job fails with an error indicating that it cannot read the data. The IAM role used by Glue has the following policy. What is missing?
Hard22A company uses Amazon Kinesis Data Streams to ingest real-time data. The compliance team requires that all data in the stream be encrypted at rest. Which configuration should be enabled?
Medium23A data engineer needs to audit all access to an Amazon S3 bucket containing sensitive data. The audit must capture who accessed the bucket, from which IP address, and what actions were performed. Which AWS service should be enabled?
Medium24A data engineer needs to ensure that data stored in Amazon S3 is protected against accidental deletion and that the data cannot be altered for a period of 7 years to meet compliance requirements. The engineer must also ensure that the data remains encrypted at rest using SSE-KMS. Which two actions should the engineer take? (Choose two.)
Medium25A data engineer needs to share a dataset from an S3 bucket in Account A with another AWS account (Account B). The data must remain encrypted at rest with KMS. Which steps are required?
Easy26A company is using Amazon Redshift for analytics and needs to ensure that all data is encrypted at rest. The current cluster does not have encryption enabled. What is the most efficient way to enable encryption?
Medium27A data engineer must ensure that all objects written to an S3 bucket by an AWS Glue ETL job are encrypted with a customer-managed AWS KMS key, even if the job does not explicitly specify encryption parameters. The bucket policy already denies unencrypted PUT requests. Which configuration will enforce the required encryption with the LEAST operational overhead?
Medium28A data engineer needs to securely store database credentials used by a Lambda function. The solution must automatically rotate the credentials every 90 days. Which AWS service should the engineer use?
Easy29A company uses AWS KMS to encrypt sensitive data stored in S3. To meet compliance requirements, they need to ensure that the encryption keys are automatically rotated every year. Which type of KMS key should they use?
Hard30A data engineer needs to store sensitive data in Amazon S3 and automatically classify the data using a managed service. The data is uploaded via an S3 bucket. Which AWS service can automatically detect and classify sensitive data?
Medium31Which THREE AWS services can be used to centrally manage and govern data across multiple AWS accounts? (Select THREE.)
Easy32A data engineer is designing a data pipeline that processes PII data using AWS Glue and stores results in S3. Which TWO actions should be taken to protect the data? (Choose 2)
Medium33A data engineer is designing a data pipeline that ingests data from an on-premises system into Amazon S3 using AWS Transfer Family. The data must be encrypted at rest using a customer-managed key in AWS KMS. The S3 bucket policy must allow only encrypted connections. Which policy condition should be used?
Hard34A company uses AWS Lake Formation to manage access to a data lake in Amazon S3. A data engineer needs to grant a specific IAM role access to only the columns containing non-sensitive data in a table, while hiding columns with personally identifiable information (PII). The engineer has already registered the S3 bucket and the table in Lake Formation. What should the engineer do to meet this requirement?
Hard35A data engineer is configuring an AWS Glue ETL job that processes data from an Amazon S3 bucket. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer needs to ensure that the Glue job uses HTTPS endpoints when reading from and writing to S3. Which action should the engineer take?
Easy36A company needs to monitor and record all changes to IAM policies in their AWS account. Which AWS service should be used?
Medium37A company uses Amazon Redshift for its data warehouse and needs to enforce column-level security on sensitive columns. Which TWO approaches can achieve this?
Hard38A company wants to centrally manage encryption keys for multiple AWS services and automatically rotate them every year. Which AWS service should be used?
Medium39A data engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest using a customer managed key in AWS KMS. The engineer also needs to enforce that any attempt to upload an object without specifying the correct KMS key is denied. Which combination of actions should the engineer take?
Medium40A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which TWO steps should the data engineer take? (Choose two.)
Hard41A company wants to monitor and alert on unauthorized API calls in their AWS account. Which AWS service should be used to detect and notify on such events?
Medium42A company is using Amazon Redshift for data warehousing. They need to ensure that data is encrypted at rest and in transit. Which TWO configurations are required to meet these requirements?
Medium43A data engineer is troubleshooting an AWS Glue ETL job that fails with an access denied error when writing to an S3 bucket. The Glue job uses an IAM role that has an S3 bucket policy attached. The bucket policy denies access to any principal that does not use server-side encryption. What is the most likely cause of the failure?
Hard44A company is using an Amazon RDS for PostgreSQL database to store personally identifiable information (PII). The security team wants to ensure that database administrators cannot view the plaintext PII data. Which solution should a data engineer implement?
Hard45A company uses AWS Lake Formation to manage data lake permissions. The data lake contains sensitive customer data in the 'customer' database. The security team wants to ensure that only users with a specific tag 'access_level=analyst' can query the 'customer' table. Which combination of steps should the data engineer take to enforce this?
Medium46A data engineer manages an AWS Glue Data Catalog table that contains sensitive customer PII. The table's underlying data is in Amazon S3 and is queried by several AWS analytics services. The security team wants to implement column-level access control so that only authorized principals can view the PII columns, while other principals can still query non-sensitive columns. The solution must integrate with AWS Lake Formation and be enforced consistently across all query engines. Which approach should the data engineer take?
Medium47A company needs to protect sensitive data stored in Amazon S3 from unauthorized access. Which TWO actions should the data engineer take? (Choose two.)
Medium48A company wants to grant cross-account access to an S3 bucket without using IAM roles. The data engineer needs to write a bucket policy that allows another AWS account to list objects. Which Principal should be specified in the bucket policy?
Medium49A data engineer is designing a data lake on Amazon S3 that must comply with a regulatory requirement to prevent any data from being overwritten or deleted for 7 years after creation. Which S3 feature should be used?
Hard50Refer to the exhibit. A data engineer checks the versioning status of an S3 bucket and sees the above output. The bucket contains critical logs that must not be permanently deleted. What should the engineer do to enhance protection against accidental or malicious deletion?
Easy51A company stores sensitive customer data in an Amazon S3 bucket with versioning enabled. A data engineer accidentally deleted the current version of an object. What is the quickest way to restore the object to its previous state without additional data transfer costs?
Hard52A company uses AWS Glue to process sensitive data stored in Amazon S3. The security team requires that all data in transit between AWS Glue and S3 be encrypted. Which configuration should be used to meet this requirement?
Easy53An organization needs to audit all access to their S3 buckets for compliance purposes. They want to log both successful and failed API calls. Which AWS service should be used?
Medium54A data engineer needs to ensure that an S3 bucket can only be accessed from a specific VPC. Which policy element should be used?
Medium55A data engineer needs to grant an IAM role read-only access to Amazon DynamoDB tables in a specific AWS account. Which IAM policy element should be used to restrict access to only the 'GetItem' and 'Query' actions?
Easy56A data engineer manages an Amazon Redshift cluster that contains a table with credit card numbers. The security team requires that the credit card column be stored in encrypted form and that only users with a specific IAM role can see the full values. Other users should see a partially masked value when they query the table. Which Redshift feature should the data engineer use?
Hard57A data engineer is configuring a data lake on Amazon S3 that contains sensitive customer information. The company requires that all access to this data be logged and monitored, and that any data shared with external partners must be anonymized before leaving the S3 bucket. Which combination of AWS services should the engineer use to meet these requirements? (Choose THREE.)
Medium58A data engineer needs to grant an AWS Glue ETL job access to read data from an Amazon S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs with an IAM role. Which action must the engineer take to allow the Glue job to decrypt the data?
Easy59A company wants to grant read-only access to an S3 bucket for a data analyst. The analyst should be able to list objects and read object content. Which IAM policy effect and action combination is correct?
Easy60A company is using AWS Lake Formation to manage permissions on a data lake. They want to grant a data scientist the ability to query tables in the 'analytics' database using Amazon Athena, but prevent them from accessing the underlying S3 data directly. What is the best way to achieve this?
Easy61A healthcare company uses AWS Lake Formation to manage access to a data lake in Amazon S3. The data lake contains a table with patient records, and the company needs to ensure that only users in the 'Cardiology' department can query columns containing sensitive information such as patient name and diagnosis. Other departments should be able to query non-sensitive columns like patient ID and visit date. The company wants to implement this with the least operational overhead. What should the data engineer do?
Hard62A company uses Amazon Redshift for data warehousing. The security team requires that all data stored in Redshift be encrypted at rest using a customer-managed KMS key. How should the data engineer configure this?
Medium63A data engineering team needs to encrypt data at rest in an Amazon S3 bucket that stores sensitive customer information. The team must use an AWS Key Management Service (AWS KMS) customer managed key with automatic rotation enabled. Which configuration meets these requirements?
Medium64A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The engineer needs to grant a specific IAM role read access to only the columns 'customer_id' and 'purchase_amount' in a table stored in the AWS Glue Data Catalog. The table contains sensitive columns like 'credit_card_number'. Which Lake Formation permission model should the engineer use to achieve this?
Hard65A company uses Amazon RDS for MySQL to store transactional data. The database contains sensitive financial information. The company's security policy requires that all data at rest be encrypted using a customer-managed KMS key. The database was originally launched without encryption at rest. The security team now needs to enable encryption without significant downtime. What should they do?
Medium66A data engineer is configuring an S3 bucket to host sensitive data. The security policy requires that all objects be encrypted with a key that is generated and managed by the customer, and that the key be stored in AWS KMS. Which encryption option should be used?
Medium67A data engineer is setting up a data pipeline that ingests streaming data from Amazon Kinesis Data Streams into an S3 data lake using Amazon Kinesis Data Firehose. The data contains personally identifiable information (PII). The security team requires that all data be encrypted at rest in S3 using an AWS KMS customer managed key (CMK) that is specific to the application. Additionally, the data must be encrypted in transit between all services. The engineer creates the KMS key and configures Firehose to use server-side encryption with the key for the S3 destination. However, Firehose delivery fails with an error indicating that the KMS key is not accessible. What is the most likely cause?
Medium68A media company stores video metadata in an Amazon DynamoDB table. The security team requires that all data at rest in the table be encrypted with a customer managed key in AWS KMS, and that the key usage be auditable. The data engineer needs to configure encryption for the table. Which action should the data engineer take?
Medium69A data engineer is configuring an AWS Lake Formation permissions model for a data lake in Amazon S3. Analysts must query a table through Amazon Athena and see only rows where the 'region' column equals 'EU'. The engineer has already registered the S3 location with Lake Formation and created the table in the AWS Glue Data Catalog. Which action should the engineer take to enforce the row-level restriction?
Hard70A company has a requirement to store audit logs for 7 years for compliance. The logs are stored in S3 and must be immutable. Which S3 feature should be used?
Hard71A company stores sensitive data in Amazon S3 and requires that all data in transit between on-premises applications and S3 be encrypted. The applications use the AWS SDK to upload and download objects. Which configuration should the data engineer implement to enforce encryption in transit?
Easy72A data engineer needs to allow an AWS Lambda function to access a specific AWS KMS customer managed key to decrypt data. The Lambda function assumes an IAM role. Which policy statement should be added to the KMS key policy to grant the necessary permissions with least privilege?
Medium73A company runs a data lake on AWS using S3 for storage and AWS Glue for ETL. The security team discovers that a contractor who left the company two months ago still has access to an S3 bucket containing sensitive data. The access was granted via an IAM user that was not deleted. The data engineer is asked to implement a solution to prevent future occurrences. The company uses AWS Organizations and has multiple accounts. The requirement is to automatically detect and remediate IAM users that have not been used for 90 days by disabling their access keys and notifying the security team. The solution must be least privilege and use AWS-native services. Which approach should the data engineer take?
Hard74A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket encrypted with SSE-KMS and writes to another S3 bucket also encrypted with SSE-KMS. The job uses an IAM role. The security team requires that the job have only the minimum necessary permissions to decrypt and encrypt data. Which TWO actions should be included in the IAM policy attached to the Glue job role? (Choose two.)
Medium75A company needs to ensure that data stored in Amazon RDS is encrypted at rest. Which action should the data engineer take?
Easy76A company uses Amazon RDS for MySQL to store financial data. A compliance requirement mandates that all database connections must be encrypted. Which configuration step is necessary?
Medium77A company stores data in Amazon S3 with server-side encryption using AWS KMS (SSE-KMS). The data engineer needs to give a third-party auditor read-only access to the encrypted objects. The auditor has an AWS account. Which strategy should be used?
Hard78A data engineer needs to ensure that an Amazon Redshift cluster encrypts data at rest using a customer-managed AWS KMS key. Which configuration step is required?
Easy79A data engineer is configuring an AWS Glue ETL job that reads from and writes to an Amazon S3 bucket. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS, and that the job must fail if TLS is not used. Which two actions should the data engineer take to meet these requirements? (Choose two.)
Hard80A data engineer needs to audit data access in Amazon S3 for compliance. Which TWO services can be used to capture and analyze S3 access logs? (Choose TWO.)
Easy81A data engineer is preparing an AWS Glue ETL job that reads from and writes to Amazon S3 and must audit every access to sensitive data for compliance. The security team wants to know which principals accessed which objects and when, and also wants to detect anomalous access patterns. Which TWO AWS services should be used together to meet these requirements? (Choose two.)
Medium82A healthcare company stores patient records in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A new AWS Glue ETL job must read these records and write transformed data to another S3 bucket that is also encrypted with the same KMS key. The company's security policy requires that the Glue job's access to the KMS key be least-privilege and auditable. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)
Hard83A data engineer must ensure that an AWS Glue ETL job can read from an Amazon S3 bucket encrypted with SSE-KMS and write to another S3 bucket also encrypted with SSE-KMS, using a single KMS key. The engineer has created an IAM role for the Glue job with permissions to access both buckets. What additional step is required to allow the Glue job to decrypt and encrypt data using the KMS key?
Medium84A company is designing a data lake on Amazon S3. The security team requires granular access control based on data classifications. Which TWO AWS services can be used together to implement attribute-based access control (ABAC) for objects in S3?
Medium85A data engineer needs to ensure that an AWS Glue ETL job can access an Amazon S3 bucket that is encrypted with SSE-KMS. The Glue job runs with an IAM role. The KMS key policy grants access to the account root. Which TWO actions are required to allow the Glue job to read and write data in the bucket? (Choose two.)
Medium86A data engineer needs to grant an IAM user the ability to view Amazon CloudWatch Logs log groups and stream log events from a specific log group. Which IAM policy action should be used?
Easy87A company stores sensitive data in an Amazon S3 bucket. To comply with regulations, all data must be encrypted at rest using server-side encryption. The security team wants to ensure that any attempt to upload an unencrypted object is automatically denied. Which S3 bucket policy condition should be used?
Medium88A team is designing a data lake on S3 and needs to enforce encryption at rest. They want to use server-side encryption with a KMS key that they manage. Which encryption option should they configure on the S3 bucket?
Medium89A company uses AWS CloudTrail to log all API calls. The security team wants to ensure that log files are tamper-proof and cannot be deleted. Which TWO actions should the data engineer take? (Choose TWO.)
Medium90A data engineer is building an AWS Glue Data Catalog table that references an Amazon S3 bucket containing CSV files. The security team requires that column-level access be restricted so that only specific IAM principals can view the column containing personally identifiable information (PII). The engineer needs to implement this restriction without modifying the underlying data. Which combination of actions should the engineer take?
Hard91A data engineer needs to share a dataset stored in an Amazon S3 bucket with another AWS account. The dataset must remain encrypted at rest using AWS KMS. The data engineer creates a bucket policy that grants the other account access to the bucket. However, the other account reports that objects appear encrypted and they cannot decrypt them. What is the most likely cause?
Hard92A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket containing sensitive customer records. The security team requires that the job's data be encrypted at rest using a customer managed AWS KMS key, and that the key policy restrict usage to the specific IAM role used by the Glue job. The engineer has already created the KMS key and attached the necessary IAM policy to the Glue job role. What additional step is required to ensure the Glue job can decrypt the S3 data using the customer managed key?
Medium93A data engineer is building an AWS Glue job that reads a table from the AWS Glue Data Catalog. The table contains columns with customer names, email addresses, and account numbers. The security team wants the job to mask the last four digits of account numbers in the output while leaving other columns unchanged. Which approach should the data engineer use?
Medium94A data engineer is using AWS Lake Formation to manage permissions on a Data Catalog table backed by Amazon S3. Analysts query the table with Amazon Athena. The security team wants analysts to see only rows where the region column equals 'EU' and to prevent them from viewing the customer_id column entirely. Which combination of Lake Formation features should the engineer implement?
Hard95A data engineer receives an alert that an AWS KMS key has been scheduled for deletion by mistake. What is the immediate action to prevent the key from being deleted?
Easy96Refer to the exhibit. An IAM policy is attached to a user. What is the security implication of this policy?
Easy97A company uses AWS Glue to process sensitive data stored in S3. The security team requires that all data be encrypted at rest using customer-managed KMS keys. The data engineers are encountering 'Access Denied' errors when running Glue ETL jobs. What is the most likely cause?
Medium98A data engineer manages an AWS Glue Data Catalog used by Amazon Athena analysts. The security team wants column-level restrictions so that analysts querying a specific table cannot view the values in a cardholder_name column, while still being able to query all other columns. The analysts connect through Athena using an IAM role. Which approach meets this requirement with the LEAST operational overhead?
Medium99A data engineer manages an AWS Glue ETL job that processes sensitive customer records stored in Amazon S3. The security team mandates that all data at rest in the S3 bucket be encrypted with AWS KMS keys, and that the Glue job have the minimum permissions necessary to read and write data. The engineer creates a KMS key and configures the S3 bucket to use SSE-KMS with that key. Which additional step is required to allow the Glue job to access the encrypted data?
Medium100An organization wants to audit all API calls made to AWS services for compliance. Which AWS service should be used to capture and store these API calls?
Medium101A company needs to encrypt data in transit between an EC2 instance and an S3 bucket. Which method should be used?
Easy102Order the steps to migrate an on-premises database to Amazon RDS using AWS DMS.
Medium103A company stores sensitive customer data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. However, when a data engineer attempts to upload an object using the AWS CLI, the upload fails with an access denied error. The engineer has s3:PutObject permission on the bucket. Which additional permission is most likely missing?
Medium104A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that the KMS key can only be used from within the company's VPC. Which policy element should be added to the KMS key policy?
Easy105A company wants to implement least privilege access for its data lake on S3. Which THREE practices should be followed? (Choose THREE.)
Hard106A data engineer needs to implement encryption for data at rest in an Amazon S3 bucket that stores sensitive financial records. The company's security policy requires that the encryption keys be managed by the company and rotated annually. The data engineer wants to use AWS Key Management Service (AWS KMS) to meet these requirements. Which solution should the data engineer implement?
Medium107A data engineer is designing a data lake on Amazon S3 that contains personally identifiable information (PII). The compliance team requires that all access to the data be logged and that any attempt to delete or modify data be detected and alerted. The engineer enables AWS CloudTrail data events for the S3 bucket and configures Amazon CloudWatch alarms. Which additional AWS service should the engineer use to automatically detect and remediate unauthorized changes to the S3 bucket's ACLs or policies?
Hard108A data engineer needs to grant an IAM role used by an AWS Lambda function permission to read encrypted data from an Amazon S3 bucket. The data is encrypted with a customer-managed AWS KMS key. The engineer wants to follow the principle of least privilege. Which combination of actions should the engineer include in the IAM policy for the Lambda execution role?
Hard109A data engineer is using AWS Glue to process data stored in Amazon S3. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has verified that the Glue job uses the AWS Glue Data Catalog and that the S3 bucket policy allows access. What should the engineer do to ensure that the Glue job enforces TLS when reading from and writing to S3?
Easy110A company is using Amazon S3 to store log files. The security team requires that all data be encrypted in transit. Which of the following ensures encryption in transit for S3?
Easy111A data engineer is designing a data lake on Amazon S3. The compliance team requires that objects be automatically deleted after 7 years. Additionally, objects must be transitioned to Amazon S3 Glacier Instant Retrieval after 30 days to reduce costs. Which S3 lifecycle policy configuration meets these requirements?
Hard112A data engineer needs to share a dataset stored in an S3 bucket with a partner AWS account. The partner should be able to read the data without needing to authenticate with the engineer's account. The engineer must not share any secret keys. Which approach should be used?
Hard113A data engineer needs to audit all AWS KMS key usage events for the past 90 days to verify compliance. Which AWS service should be used?
Easy114A data engineer is setting up cross-account access to an encrypted S3 bucket. The bucket uses a customer-managed KMS key. The engineer has configured the bucket policy and the IAM role in the source account. The target account still gets access denied errors when trying to read objects. What is the most likely cause?
Medium115A data engineer stores raw customer records in an Amazon S3 bucket and runs an AWS Glue job that writes curated Parquet files to a second bucket. The governance team requires that the curated data carry a verifiable record of which job run produced it and that any modification to a curated file be detectable. The engineer must also prove that the curated dataset has not been altered since a nightly baseline. Which combination of AWS features should the engineer use?
Hard116A data engineer manages an AWS Lake Formation governed data lake. Analysts query tables through Amazon Athena and must see only rows where the region column equals their assigned region, while column-level restrictions must also hide a national ID column. The engineer grants table SELECT to the analysts' IAM role in Lake Formation. What should the engineer configure next?
Hard117A company needs to share a dataset stored in an S3 bucket with a partner account. The dataset contains sensitive information, so the company wants to ensure that the partner account can only access the data using a specific VPC endpoint in the partner's account. Which S3 bucket policy condition key should be used?
Hard118A company uses S3 to store sensitive data. Which TWO S3 features can be used to protect data at rest?
Medium119A data engineer manages an AWS Glue Data Catalog shared across teams. Analysts in one team must be able to query only the sales database and its tables, while another team owns the marketing database. The engineer wants permissions managed centrally in Lake Formation and wants the analysts to be able to create their own temporary tables but not alter the sales tables. Which combination of Lake Formation grants should the engineer apply?
Hard120A data engineer wants to ensure that only users with a specific tag (e.g., "Department": "DataEngineering") can access an S3 bucket. How can this be enforced?
Easy121A company uses Amazon RDS for PostgreSQL with encryption at rest using AWS KMS. The company needs to share a database snapshot with a different AWS account. What must be done to allow the target account to restore the snapshot?
Hard122A data engineer is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team requires that all data be encrypted at rest and that the job use a customer-managed KMS key for encryption. The engineer configures the job with `--encryption-type sse-kms` and a KMS key ID. However, the job fails with an access denied error when writing to S3. The IAM role used by the Glue job has permissions to read and write the S3 buckets but has no KMS permissions. Which additional IAM permissions are required for the Glue job role to successfully write encrypted data?
Medium123A data engineer is responsible for an Amazon Redshift cluster that stores financial data. The security team requires that all connections to the cluster from outside the VPC use SSL, and that the cluster's audit logs capture connection and user activity. The engineer has already enabled audit logging to Amazon S3. Which additional configuration should the engineer apply to meet the SSL requirement?
Medium124A data engineer needs to grant an IAM user access to query a specific table in Amazon Athena, but the user should not be able to view other tables in the same database. Which method should the engineer use?
Easy125A data engineer is setting up an AWS Glue job that reads from an Amazon Kinesis Data Stream and writes to an Amazon S3 bucket. The security team requires that all data in transit be encrypted using TLS, and that the Glue job must use a VPC endpoint to access Kinesis and S3. Which configuration ensures compliance?
Medium126A data engineer is building an AWS Lambda function that processes records from an Amazon Kinesis data stream. The Lambda function needs to read from the stream and write processed data to an Amazon S3 bucket. The security team requires that all data in transit be encrypted using TLS, and that the Lambda function authenticate to Kinesis and S3 using temporary credentials. Which combination of configurations should the engineer use?
Medium127A company has multiple AWS accounts and wants to centrally manage permissions and access to data lakes. They have enabled AWS Organizations and want to use a single set of policies that apply to all accounts. Which policy type should be used at the organization level?
Hard128Which TWO actions should a data engineer take to protect sensitive data in an Amazon S3 bucket from being accessed by unauthorized users? (Select TWO.)
Medium129A data engineer needs to securely store database credentials for an RDS instance. Which TWO AWS services can be used?
Easy130A company uses AWS Glue to catalog data in Amazon S3. The data includes personally identifiable information (PII). The security team requires that PII be masked when queried by users who are not data owners. Which AWS service should be used to enforce this requirement?
Medium131A data engineer is configuring cross-account access so that an analytics AWS account can read objects from a data-lake S3 bucket in a producer account. The objects are encrypted with SSE-KMS using a customer managed key in the producer account. The engineer has already added a bucket policy granting s3:GetObject to the analytics account's IAM role. Reads still fail with AccessDenied. Which additional change is required?
Medium132A data engineer needs to share a dataset stored in Amazon S3 with another AWS account. The bucket policy currently grants access only to the owning account. What is the simplest way to grant cross-account access?
Medium133A data engineer must give an AWS Lambda function temporary credentials to read objects from a specific Amazon S3 prefix. The function runs in a VPC and accesses S3 through a gateway VPC endpoint. The security team forbids long-lived access keys on the function. What should the data engineer configure?
Medium134A data engineer needs to audit data access events in Amazon S3. Which AWS service should be used to record and monitor API calls for S3 buckets?
Easy135Match each AWS storage class to its description.
Medium136A data engineer is configuring an Amazon Redshift cluster to encrypt data at rest. The company policy requires that encryption keys be stored in AWS CloudHSM. Which integration should the engineer use to meet this requirement?
Medium137A company wants to enforce that all data written to an S3 bucket is encrypted with a customer-managed AWS KMS key. The data engineer has created the KMS key and attached an S3 bucket policy. However, users are still able to upload objects without specifying the KMS key. What is the most likely cause?
Easy138A company stores sensitive financial data in Amazon S3 and requires that all data be encrypted at rest using customer-managed keys. A data engineer configures the S3 bucket to use SSE-KMS with a customer-managed KMS key. The security team now wants to audit all API calls that use the KMS key to decrypt data. Which AWS service should the engineer use to capture and review these KMS API calls?
Easy139A data engineer needs to restrict access to an S3 bucket so that only users from a specific AWS account can read objects. Which S3 bucket policy element should be used?
Easy140A company wants to audit API calls made to its Amazon S3 buckets. Which AWS services can be used to achieve this? (Choose TWO.)
Easy141A company stores sensitive data in Amazon S3 and uses AWS KMS customer-managed keys for encryption. The security team wants to monitor and audit all KMS API calls that involve the key, including who used the key and when. They also want to receive alerts if the key is used by an unauthorized principal. Which AWS service should the data engineer use to meet these requirements?
Medium142A company uses AWS Lake Formation to manage access to data in a data lake. A new data engineer has been granted SELECT permission on a table but receives an 'AccessDeniedException' when querying via Amazon Athena. The table is registered in Lake Formation and the data is encrypted with SSE-KMS. Which of the following is the MOST likely cause?
Hard143A data engineer is building a governed data lake in AWS Lake Formation. The security team wants to detect sensitive data such as credit card numbers in newly registered S3 tables and automatically apply column-level access restrictions to those columns. Which TWO actions should the engineer take to meet these requirements? (Choose two.)
Hard144A data engineer needs to grant an IAM user read-only access to an S3 bucket named 'data-lake'. Which IAM policy statement should be used?
Easy145A company stores sensitive data in Amazon Redshift. The security team requires that all data in the cluster be encrypted at rest using a customer managed key in AWS KMS, and that the key be rotated annually. The data engineer needs to configure the Redshift cluster accordingly. Which action should the engineer take?
Medium146A company uses AWS Glue to process sensitive customer data stored in S3. The security team requires that all data be encrypted at rest using a customer-managed KMS key and that access to the key be auditable. Which solution meets these requirements?
Medium147A company has a data lake in Amazon S3 with millions of objects. The security team wants to enforce that all objects are encrypted with a specific customer-managed KMS key. The data engineer configures an S3 bucket policy to deny PutObject if the encryption is not set to that key. However, some existing objects are not encrypted with that key. What is the most efficient way to remediate the existing objects?
Hard148A company uses AWS Lake Formation to manage data lake permissions. The data engineer notices that a user with SELECT permission on a table can also query the underlying data in Amazon S3 directly. How can the engineer enforce that access to the S3 data is only through Lake Formation?
Hard149A company is using Amazon EMR to process data stored in Amazon S3. The S3 bucket is configured with a bucket policy that denies access unless the request includes a specific tag. The EMR cluster's IAM role has s3:GetObject permission. However, the EMR job fails to read data from S3. What is the most likely cause?
Hard150A company is using Amazon EMR with Kerberos authentication. They want to ensure that data in transit between EMR cluster nodes is encrypted. Which configuration should be applied?
Hard151A data engineering team is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team mandates that both read and write operations use a customer-managed AWS KMS key so they can audit key usage. Which configuration should the data engineer apply to the Glue job to meet this requirement?
Medium152A data engineer needs to audit all AWS KMS key usage in the account. Which AWS service should be used to record KMS API calls?
Easy153A company wants to audit all changes to IAM policies in their AWS account. Which combination of services should be used to achieve this?
Hard154A company needs to enforce encryption in transit for all data moving between its Amazon S3 bucket and a fleet of Amazon EC2 instances. The data is accessed via S3 API calls over the internet. Which configuration ensures encryption in transit?
Medium155A company is building a data pipeline that ingests sensitive customer data from an on-premises database into Amazon S3 using AWS DMS. The data must be encrypted at rest in S3 and in transit. The security team requires that the encryption keys be managed by the company (not AWS). Which TWO actions should the data engineer take to meet these requirements? (Choose TWO.)
Medium156A financial services company uses a multi-account AWS Organization with hundreds of accounts. The data engineering team needs to enable cross-account access to an encrypted S3 bucket in the data lake account (account ID 111111111111) for a Glue ETL job running in the analytics account (account ID 222222222222). The S3 bucket uses AWS KMS customer managed key (CMK) for server-side encryption (SSE-KMS). The Glue job fails with an AccessDenied error when trying to read data from the bucket. The IAM roles in both accounts have the necessary S3 permissions and the bucket policy allows access from the analytics account. What is the most likely cause of the failure?
Hard157Refer to the exhibit. An IAM policy includes the above statement to allow decryption of a KMS key under specific conditions. What does this policy allow?
Easy158A data engineer needs to ensure that all data in an S3 bucket is encrypted at rest. The bucket currently contains unencrypted objects from past uploads. Which action will encrypt these existing objects without re-uploading them?
Easy159A company has an AWS Glue ETL job that reads data from an S3 bucket, transforms it, and writes to another S3 bucket. The security team requires that data in transit between the Glue job and S3 be encrypted using TLS. The Glue job runs in a VPC with a VPC endpoint for S3. Which configuration ensures TLS encryption for all data transfer?
Hard160A company wants to centrally manage access to multiple AWS accounts for its data engineers. The company already uses AWS Organizations. Which AWS service should be used to define fine-grained permissions across accounts?
Easy161A company uses Amazon Redshift for data warehousing. The security team requires that all data in transit between the Redshift cluster and clients be encrypted. Which feature should be enabled?
Easy162A company uses AWS Lake Formation to manage data lakes on Amazon S3. The data engineer needs to grant a data analyst access to query specific columns in a table using Amazon Athena, but deny access to columns containing personally identifiable information (PII). Which Lake Formation feature should be used?
Hard163A data engineer needs to ensure that an Amazon Redshift cluster only accepts encrypted connections. Which parameter should be modified?
Easy164A data engineer is setting up an Amazon RDS for MySQL database. The compliance team requires that all data at rest be encrypted. What must the engineer do to enable encryption for this database?
Easy165A data engineer is configuring AWS Glue to crawl a dataset stored in Amazon S3 and populate the AWS Glue Data Catalog. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has already configured the Glue crawler to use a connection with the appropriate VPC settings. What additional step must the engineer take to enforce encryption in transit?
Hard166A data engineer is managing an AWS Glue Data Catalog that contains metadata for tables in Amazon S3. The security team requires that access to the Data Catalog be restricted based on the user's department, and that users can only see tables that belong to their department. The Data Catalog tables are tagged with a 'Department' key. Which AWS feature should the engineer use to enforce this requirement?
Hard167A data engineer is configuring a VPC for an Amazon Redshift cluster. The cluster must be accessible only from a specific on-premises network via a Direct Connect connection. Which TWO actions should the engineer take to meet this requirement? (Choose TWO.)
Hard168A data engineer manages an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another bucket. The security team mandates that all data at rest in both buckets be encrypted with customer-managed AWS KMS keys, and that each service use a distinct key. The Glue job's IAM role currently has s3:GetObject and s3:PutObject permissions but jobs fail with an access denied error when writing output. What is the MOST likely cause?
Hard169A data engineer is configuring an AWS Glue crawler to catalog data stored in an Amazon S3 bucket. The security team requires that all data in transit between the crawler and S3 be encrypted using TLS. Which configuration should the engineer implement to meet this requirement?
Easy170A data engineer is building a data pipeline that ingests sensitive data into Amazon S3 and then processes it with AWS Glue. The security team requires that the data be encrypted at rest using a customer managed key in AWS KMS, and that the engineer be able to audit all key usage. The engineer creates a KMS customer managed key and configures the S3 bucket to use SSE-KMS with that key. The Glue job's IAM role has been granted kms:Decrypt and kms:GenerateDataKey permissions on the key. However, when the Glue job runs, it fails with an access denied error related to KMS. Which additional action should the engineer take to resolve the error?
Hard171A company uses Amazon S3 to store log files. The security team notices that some objects are being accessed from an unexpected AWS account. The data engineer needs to identify which specific IAM user or role is accessing the objects. Which AWS service should be used to get this information?
Medium172A data engineer needs to restrict access to an Amazon S3 bucket so that only objects encrypted with a specific AWS KMS key can be uploaded. Which S3 bucket policy condition should be used?
Easy173Refer to the exhibit. A data engineer runs the AWS CLI command shown to encrypt a file using AWS KMS. The command succeeds. Later, the engineer tries to decrypt the file using the same key but without providing an encryption context. The decryption fails. What is the most likely reason?
Hard174A data engineer is setting up an AWS Glue ETL job that reads data from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that all data in transit be encrypted using TLS. The engineer has configured the job to use the appropriate S3 endpoints. Which additional configuration is necessary to enforce TLS for data in transit between AWS Glue and Amazon S3?
Easy175Refer to the exhibit. A data engineer applies this S3 bucket policy to an S3 bucket. What is the effect of this policy?
Medium176A retail company uses Amazon Redshift for its data warehouse. The security team requires that all data in the cluster be encrypted at rest using a hardware security module (HSM) to manage the encryption keys. The data engineer needs to configure the Redshift cluster accordingly. Which action should the data engineer take?
Easy177A company needs to centralize audit logs from multiple AWS accounts into a single S3 bucket. Which service should be used to aggregate these logs?
Easy178A data engineer needs to ensure that data in transit between an Amazon RDS for PostgreSQL database and an application is encrypted. Which configuration should be used?
Easy179A company wants to enable automatic encryption for all new objects written to an S3 bucket. The bucket has existing objects that are unencrypted. Which solution meets these requirements with the least operational overhead?
Medium180A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer grants a data analyst SELECT permission on a table in the AWS Glue Data Catalog. However, when the analyst queries the table using Amazon Athena, they receive an error that they are not authorized to access the underlying S3 data. What is the MOST likely reason?
Hard181A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer needs to grant a data analyst read access to specific columns in a table registered in the AWS Glue Data Catalog, while hiding other columns that contain personally identifiable information. The analyst uses Amazon Athena to query the table. Which Lake Formation feature should the engineer use?
Hard182Refer to the exhibit. The S3 bucket policy above is applied to the bucket "example-bucket". An IAM user attempts to upload an object to the bucket without specifying any encryption header. What is the outcome?
Medium183A data engineer needs to ensure that data stored in Amazon S3 is automatically deleted after 30 days. Which S3 feature should be used?
Easy184A healthcare company stores patient records in an S3 bucket encrypted with SSE-S3. The data engineering team uses AWS Glue ETL jobs to process this data and load it into an Amazon Redshift cluster for analytics. Recently, the security team mandated that all sensitive data must be encrypted at rest using customer-managed keys (CMK) in AWS KMS, and that the keys must be rotated automatically every year. The team updated the S3 bucket to use SSE-KMS with a CMK and enabled automatic key rotation. However, after the change, the Glue ETL jobs that read from the S3 bucket started failing with 'Access Denied' errors. The Glue job uses an IAM role named 'GlueETLRole' that has the following permissions: s3:GetObject on the bucket, kms:Decrypt and kms:GenerateDataKey on the CMK, and all necessary Glue permissions. The Redshift cluster is also encrypted with a different CMK, and the Glue role has kms:Decrypt on that key as well. What is the most likely cause of the failure?
Hard185A company needs to automate the detection of sensitive data in Amazon S3 and generate reports. Which AWS service should be used?
Medium186A data engineer maintains an AWS Glue Data Catalog with databases for several lines of business. Auditors require that every change to table definitions, partition additions, and schema edits in the catalog be recorded with the identity of the caller and that the records be retained for 365 days in a dedicated S3 bucket. Which solution should the data engineer implement?
Hard187Refer to the exhibit. A data engineer runs this AWS CLI command to execute an Athena query. What is the purpose of the EncryptionConfiguration parameter?
Medium188A data engineer needs to encrypt data in transit between an Amazon RDS for MySQL instance and an application. Which solution should be used?
Easy189A financial services company needs to share sensitive customer data with a third-party analytics firm. The data resides in an S3 bucket encrypted with an AWS KMS customer managed key. The third party has their own AWS account. Which combination of steps is required to securely share the data? (Choose TWO.)
Hard190A company has an AWS Glue ETL job that reads from an RDS MySQL instance and writes to S3. The security team requires that the connection to RDS be encrypted and that credentials be rotated automatically. Which configuration should be used?
Hard191A data engineer is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to an Amazon Redshift cluster. The security team requires that the data be encrypted in transit between Glue and Redshift. Which configuration should the engineer implement to meet this requirement?
Medium192A data engineer is troubleshooting an ETL job that reads from an S3 bucket encrypted with SSE-KMS. The job is failing with an error indicating that the IAM role does not have permission to decrypt the data. What is the most likely missing permission?
Hard193A company wants to audit all changes to IAM policies in their AWS account. Which AWS service should be used to record these changes for compliance purposes?
Easy194A data engineer is using AWS Lake Formation to manage fine-grained access to a data lake in Amazon S3. The engineer grants a data analyst SELECT permission on a table but wants to ensure that the analyst cannot access columns containing sensitive data such as social security numbers. The table is registered in the AWS Glue Data Catalog. Which Lake Formation feature should the engineer use to restrict access to specific columns?
Medium195A data engineer needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used?
Easy196A healthcare company stores patient records in an Amazon S3 bucket and uses AWS Lake Formation to manage access for multiple analytics teams. The compliance team requires that any column containing patient identifiers be masked by default for all users except a privileged data steward role. Which Lake Formation feature should the data engineer implement to meet this requirement?
Medium197A company is building a data lake on AWS and must encrypt data at rest. Which services can provide server-side encryption for data stored in Amazon S3? (Choose TWO.)
Medium198A data engineer must give an Amazon Redshift cluster the ability to load data from an Amazon S3 bucket using the COPY command. The security team prohibits embedding long-term AWS credentials in SQL and requires that access be revoked automatically when the cluster is deleted. The S3 bucket is encrypted with SSE-KMS using a customer managed key. Which approach should the data engineer use?
Medium199A data engineer must mask the last four digits of a credit card column in an Amazon Redshift table so that analysts in a specific role see masked values while a fraud team sees the full values. The engineer wants a solution that applies to all queries without modifying each analyst's SQL. Which approach should the engineer use?
Medium200A financial services company uses AWS Glue ETL jobs to process sensitive customer data stored in Amazon S3. The data is encrypted at rest with SSE-KMS using a customer-managed key. Recently, the security team discovered that the Glue job's IAM role has an overly permissive policy that allows the 'kms:Decrypt' action for all KMS keys in the account. The company wants to follow the principle of least privilege. The Glue job runs on a schedule and reads from a specific S3 bucket. The security team needs to update the IAM policy to restrict KMS decryption to only the specific key used for that bucket. What should they do?
Medium201A data engineer needs to allow an IAM user to rotate the secret in AWS Secrets Manager for an RDS database. Which IAM action should be included in the policy?
Medium202A data engineer needs to ensure that an Amazon S3 bucket containing sensitive customer data is encrypted at rest. Which AWS service can be used to manage the encryption keys?
Easy203A company is using AWS Lake Formation to manage permissions on a data lake. Which of the following are valid ways to grant access to a user or role? (Choose THREE.)
Medium204A data engineer is troubleshooting an Amazon Redshift cluster that is not responding to queries. The engineer suspects that the cluster may have been accidentally deleted. Which AWS service should be used to investigate the deletion?
Medium205A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that data be encrypted at rest using a customer-managed AWS KMS key, and that the Glue job be able to decrypt the source data and encrypt the target data. The engineer has already created a KMS key and attached a key policy that allows the Glue service role to use the key for encrypt and decrypt operations. However, when the job runs, it fails with an access denied error related to KMS. What is the most likely cause of the failure?
Medium206A data engineer manages an AWS Glue job that reads from an Amazon S3 bucket containing PII. The security team requires that the data be encrypted at rest using a customer-managed AWS KMS key, and that the engineer be able to audit key usage. The engineer has already created a KMS key. Which combination of steps should the engineer take to meet these requirements?
Medium207A data engineer needs to share an S3 bucket with another AWS account. They want to ensure that the objects in the bucket remain encrypted with SSE-KMS using a customer managed key. What additional step is required for cross-account access?
Medium208A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The company wants to grant a data analyst read-only access to specific columns in a table stored in the AWS Glue Data Catalog. The analyst should not be able to see other columns or any rows that contain sensitive data. The engineer sets up Lake Formation permissions on the table, granting SELECT on specific columns. However, when the analyst queries the table using Amazon Athena, they can see all columns. What is the most likely reason?
Medium209A data engineer runs the command shown to check the encryption configuration of an S3 bucket. The output shows SSEAlgorithm: AES256. What does this mean?
Easy210Refer to the exhibit. A data engineer queries AWS CloudTrail to investigate a PutObject event. What does the exhibit reveal about the object sensitive.csv?
Medium211A data engineer is configuring an S3 bucket for storing sensitive customer data. The bucket must be encrypted at rest using an AWS Key Management Service (KMS) key that is managed by the data engineering team. The team wants to ensure that only users with explicit permission can decrypt the data. Which S3 encryption option should be used?
Medium212A data engineer is designing a data lake on S3 with sensitive data. The security policy mandates that data must be encrypted at rest and in transit, and that an inventory of all objects must be maintained for compliance. Which actions should be taken?
Medium213A company has an S3 bucket that stores logs for compliance. The compliance team requires that objects are retained for 7 years and cannot be deleted or overwritten. Which S3 feature should be used?
Easy214A data engineer is building an AWS Glue job that reads from a JDBC source and must retrieve the database password at runtime without hardcoding it in the script or job parameters in plaintext. The company already stores the password in AWS Secrets Manager. Which action should the engineer take?
Easy215A company is designing a data lake on AWS and must comply with GDPR requirements. The company needs to implement data masking for personally identifiable information (PII) columns in Amazon Redshift. Which feature should be used?
Medium216A data engineer is troubleshooting an issue where an IAM role used by AWS Glue cannot read data from an S3 bucket encrypted with SSE-KMS. The bucket policy allows the role to perform s3:GetObject. What additional permission is needed?
Hard217A company uses AWS Lake Formation to manage fine-grained access to a data lake in Amazon S3. A data analyst needs to query a table in the AWS Glue Data Catalog that contains columns with sensitive data. The analyst must be able to see only non-sensitive columns and only rows where the region column equals 'US'. The analyst uses Amazon Athena for queries. Which Lake Formation permission model should the data engineer implement?
Hard218A data engineer is configuring an S3 bucket policy to allow cross-account access for a partner account to read objects. The bucket is encrypted with SSE-KMS using a customer-managed key. What additional configuration is needed to allow the partner account to decrypt the objects?
Medium219A data engineer needs to ensure that all objects written to an S3 bucket are encrypted with SSE-KMS using a specific customer managed key, and that any upload without that encryption is rejected. The engineer has created the bucket and the KMS key. Which approach will enforce this requirement at the bucket level?
Medium220A company must comply with a regulation that requires logging all access to sensitive data stored in Amazon S3. Which AWS services can be used to capture and store access logs? (Choose TWO.)
Easy221A company uses Amazon QuickSight for data visualization. The data engineer needs to ensure that users can only see data relevant to their department. The data is stored in Amazon S3 and is accessed via SPICE. The engineer has created datasets in QuickSight and wants to implement row-level security (RLS). The dataset contains a column 'Department' that indicates which department a row belongs to. The engineer has configured RLS rules using a separate permissions dataset. However, users report that they can see all rows, not just their department's rows. What is the most likely reason?
Easy222A data engineer must give an AWS Glue ETL job temporary access to data in an Amazon S3 bucket without creating long-term IAM user access keys. The job runs on a schedule and must retrieve credentials automatically. Which mechanism should the engineer use?
Easy223A company wants to ensure that all S3 buckets are encrypted using server-side encryption. Which AWS service can be used to automatically remediate non-compliant buckets?
Easy224A data engineer is configuring AWS Glue jobs to access data stored in Amazon S3. The data is encrypted using server-side encryption with AWS KMS (SSE-KMS). The Glue job needs to read and write data to the S3 bucket. Which IAM policy statement should be added to the Glue job's IAM role to allow it to use the KMS key?
Easy225A media company stores video files in an Amazon S3 bucket. The bucket policy allows access only from a specific VPC. The company has enabled S3 Server Access Logs to monitor access. Recently, the security team found that some requests were coming from an IP address outside the allowed VPC. They suspect that the bucket policy may have an incorrect condition. What should they check first?
Easy226A company uses AWS Glue to process data from Amazon S3. The data contains personally identifiable information (PII). The data engineer needs to automatically detect and mask PII fields before the data is loaded into Amazon Redshift. Which combination of AWS services should be used?
Hard227A company's security policy states that no S3 bucket in the data platform account may ever be made public, even accidentally. A data engineer must implement a guardrail that blocks any attempt to set a public bucket ACL or public bucket policy, regardless of who makes the change. Which solution enforces this requirement?
Easy228A company uses Amazon Kinesis Data Streams to ingest real-time financial data. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key, and that the key be rotated annually. The data engineer needs to configure the Kinesis stream to meet these requirements. Which combination of actions should the data engineer take?
Medium229A data engineer is designing a solution to securely store and rotate database credentials used by an application. The credentials should be automatically rotated every 90 days. Which AWS service should be used?
Hard230A data engineer is using AWS Glue to transform data stored in Amazon S3. The security team requires that data in transit between AWS Glue and Amazon S3 be encrypted. The engineer wants to ensure that all connections use TLS. Which action should the engineer take to enforce encryption in transit for AWS Glue jobs accessing S3?
Easy231A company uses AWS Glue to process data stored in Amazon S3. The security team mandates that all data in transit between AWS Glue and Amazon S3 must be encrypted with TLS. The Glue job connects to S3 using the AWS SDK. Which configuration should the data engineer implement to enforce TLS encryption for the Glue job's S3 connections?
Medium232A data engineer manages an AWS Lake Formation governed data lake. Analysts in the finance department must query only the rows in a shared Amazon S3 table where the region column equals 'EMEA', while analysts in the marketing department must see all rows but must not see the customer_email column. Which TWO Lake Formation configurations should the data engineer implement to meet these requirements? (Choose two.)
Medium233A company is designing a data pipeline using Amazon Kinesis Data Streams. The data includes personally identifiable information (PII). The security team requires that data be encrypted at rest using a customer-managed KMS key. How should the data engineer configure the Kinesis stream?
Hard234A company is using AWS Lake Formation to manage access to a data lake in S3. They want to grant a data analyst access to specific columns in a table, but not to the entire table. Which Lake Formation feature should be used?
Medium235A data engineer needs to grant a data scientist access to query a Glue Data Catalog database but must prevent the data scientist from seeing the underlying S3 data locations. Which approach should be used?
Hard236A data engineer is setting up a data pipeline using AWS DMS to migrate data from an on-premises database to Amazon RDS for MySQL. The data must be encrypted in transit. Which TWO options can the engineer use? (Choose TWO.)
Easy237Arrange the steps to implement data encryption at rest for an Amazon Redshift cluster using AWS KMS.
Medium238A company uses Amazon Redshift for data warehousing. The security team requires that all data loading into Redshift be encrypted in transit. Which configuration ensures this requirement is met?
Medium239A data engineer is troubleshooting an issue where an Amazon Redshift query returns an error: 'ERROR: permission denied for relation table_name'. The user has been granted SELECT on the table. What is the most likely cause?
Hard240A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The engineer needs to grant a specific IAM role access to only the columns containing non-sensitive data in a table stored in the AWS Glue Data Catalog. The role should not have access to sensitive columns. What should the engineer do?
Medium241A data engineer must give an AWS Glue ETL job access to an S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs under an IAM role. The security team wants the least-privilege permissions required for the job to read and write objects in that bucket. Which TWO actions must be included in the IAM role's policy? (Choose two.)
Medium242A company needs to enforce encryption at rest for all data stored in Amazon S3. Which of the following are valid methods to achieve this? (Choose TWO.)
Medium243Refer to the exhibit. A data engineer applies the following S3 bucket policy to an S3 bucket. What does this policy enforce?
Medium244A data engineer needs to store encryption keys used for protecting data in Amazon S3 and automatically rotate them every year. Which service should be used?
Easy245A company wants to enforce that all data in Amazon S3 is encrypted at rest. They want to automatically reject any PUT request that does not include encryption headers. What S3 feature should they use?
Easy246A data engineer needs to share a dataset from an S3 bucket in Account A with users in Account B. The dataset must remain encrypted at rest with an S3-managed key. What is the MOST secure way to grant cross-account access?
EasyOther domains
All DEA-C01 exam domains
Frequently asked questions
- What does the Data Security and Governance domain cover on the DEA-C01 exam?
- Be able to choose the correct encryption mechanism per service, grant least-privilege access through IAM and Lake Formation, and read permission-denied errors to find the missing schema, role, or policy. The single most important skill is mapping a data-access failure to its exact AWS control.
- How many questions are in this domain?
- This page lists all 246 Data Security and Governance questions in the DEA-C01 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Data Security and Governance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.