DEA-C01 Data Security and Governance Practice Question
A company uses AWS Glue to catalog data in Amazon S3. The data includes personally identifiable information (PII). The security team requires that PII be masked when queried by users who are not data owners. Which AWS service should be used to enforce this requirement?
⚠ Common exam trap
DEA-C01 often tests the misconception that Macie or S3 Object Lambda can enforce masking, when Lake Formation is the service designed for column-level security and data masking in a Glue catalog.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Lake Formation to define column-level security and data masking.
AWS Lake Formation allows you to define column-level security and data masking policies on tables cataloged in the AWS Glue Data Catalog. You can grant or deny access to specific columns and apply masking to sensitive columns like PII for users who are not data owners, enforcing the requirement at query time. This is the native AWS service for fine-grained access control on data lakes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon Macie to automatically redact PII from S3 objects.
Why it's wrong here
Macie discovers and classifies PII in S3, generating findings; it does not rewrite or redact object contents at query time. It is tempting because classification is a genuine prerequisite for identifying sensitive data, but masking query results for non-owners requires Lake Formation column-level and row-level controls.
- ✗
Use IAM policies with condition keys to restrict access based on tags.
Why it's wrong here
IAM condition keys gate whether a principal may call an API at all; they cannot mask individual columns or rows within returned query results. It is tempting because tag-based authorisation genuinely restricts access, but the requirement is partial masking for non-owners, which Lake Formation data filters enforce.
- ✓
Use AWS Lake Formation to define column-level security and data masking.
Why this is correct
AWS Lake Formation enforces column-level security and data masking through its permissions model, filtering PII columns for non-owner users at query time. This satisfies the requirement that PII be masked for users who are not data owners, without duplicating data or altering the underlying S3 objects.
- ✗
Use Amazon S3 Object Lambda to transform data on the fly.
Why it's wrong here
S3 Object Lambda transforms objects during retrieval, but it operates on whole objects rather than enforcing per-user column or row masking driven by Glue Data Catalog metadata. It is tempting because on-the-fly transformation sounds like masking, yet Lake Formation applies fine-grained access control at the query layer.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.