DEA-C01 Data Ingestion and Transformation Practice Question
A company uses AWS Glue DataBrew to clean and normalize data from an Amazon S3 bucket before loading it into Amazon Redshift. The data contains PII such as social security numbers. A compliance policy requires that PII be masked in the DataBrew output. Which DataBrew transformation should the engineer use to replace the last four digits of each SSN with asterisks?
⚠ Common exam trap
The trap here is assuming that encryption is a form of masking; masking replaces characters with symbols, while encryption transforms data into ciphertext.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Mask value' transformation with a custom pattern to mask the last four characters.
AWS Glue DataBrew provides a 'Mask value' transformation that can apply custom masking patterns to specific characters. By configuring a pattern to mask the last four digits of the SSN with asterisks, the engineer preserves the first five digits for analytics while complying with the PII masking policy. Other transformations either over-mask, encrypt, or remove the data, failing the specific requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'Encrypt' transformation with AWS KMS to encrypt the SSN column.
Why it's wrong here
Encryption would render the SSN unreadable and require decryption for any use, which is not the same as masking. The requirement is to replace the last four digits with asterisks in the output, not to encrypt the entire value. Encryption also adds key management overhead and does not produce a partially masked string.
- ✗
Use the 'Remove columns' transformation to drop the SSN column entirely.
Why it's wrong here
Dropping the SSN column would eliminate the data entirely, which may not be acceptable if the first five digits are needed for analytics or joining. The requirement is to mask only the last four digits, not to remove the column. This action would violate the need to retain partial information.
- ✓
Use the 'Mask value' transformation with a custom pattern to mask the last four characters.
Why this is correct
DataBrew's 'Mask value' transformation supports custom patterns and can mask specific characters. By defining a pattern that targets the last four digits, the engineer can replace them with asterisks while preserving the rest of the SSN. This meets the compliance requirement precisely and is a built-in DataBrew feature.
- ✗
Use the 'Replace value or pattern' transformation to replace the entire SSN with a fixed string.
Why it's wrong here
Replacing the entire SSN with a fixed string would remove all information, including the first five digits that might be needed for analysis. The requirement is to mask only the last four digits, not the whole value. This transformation is too broad and would not preserve partial data as specified.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.