Courseiva

DEA-C01 Data Security and Governance Practice Question

A company uses AWS Glue to catalog data in Amazon S3. The data includes personally identifiable information (PII). The security team requires that PII be masked when queried by users who are not data owners. Which AWS service should be used to enforce this requirement?

⚠ Common exam trap

DEA-C01 often tests the misconception that Macie or S3 Object Lambda can enforce masking, when Lake Formation is the service designed for column-level security and data masking in a Glue catalog.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Lake Formation to define column-level security and data masking.

AWS Lake Formation allows you to define column-level security and data masking policies on tables cataloged in the AWS Glue Data Catalog. You can grant or deny access to specific columns and apply masking to sensitive columns like PII for users who are not data owners, enforcing the requirement at query time. This is the native AWS service for fine-grained access control on data lakes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon Macie to automatically redact PII from S3 objects.

    Why it's wrong here

    Macie discovers and classifies PII in S3, generating findings; it does not rewrite or redact object contents at query time. It is tempting because classification is a genuine prerequisite for identifying sensitive data, but masking query results for non-owners requires Lake Formation column-level and row-level controls.

  • ✗

    Use IAM policies with condition keys to restrict access based on tags.

    Why it's wrong here

    IAM condition keys gate whether a principal may call an API at all; they cannot mask individual columns or rows within returned query results. It is tempting because tag-based authorisation genuinely restricts access, but the requirement is partial masking for non-owners, which Lake Formation data filters enforce.

  • ✓

    Use AWS Lake Formation to define column-level security and data masking.

    Why this is correct

    AWS Lake Formation enforces column-level security and data masking through its permissions model, filtering PII columns for non-owner users at query time. This satisfies the requirement that PII be masked for users who are not data owners, without duplicating data or altering the underlying S3 objects.

  • ✗

    Use Amazon S3 Object Lambda to transform data on the fly.

    Why it's wrong here

    S3 Object Lambda transforms objects during retrieval, but it operates on whole objects rather than enforcing per-user column or row masking driven by Glue Data Catalog metadata. It is tempting because on-the-fly transformation sounds like masking, yet Lake Formation applies fine-grained access control at the query layer.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.