DEA-C01 Data Security and Governance Practice Question
A data engineer is building a governed data lake in AWS Lake Formation. The security team wants to detect sensitive data such as credit card numbers in newly registered S3 tables and automatically apply column-level access restrictions to those columns. Which TWO actions should the engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming CloudTrail or Glue classifiers detect sensitive values in object contents, when content inspection belongs to Macie.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an EventBridge rule that invokes an AWS Lambda function to apply Lake Formation column-level grants or LF-Tags based on the Macie findings.
Amazon Macie performs sensitive data discovery on S3 objects and emits findings that can flow through EventBridge, providing the detection layer. A Lambda function triggered by those findings can then apply Lake Formation column-level grants or LF-Tags, automating enforcement so sensitive columns are restricted as data is registered and classified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an EventBridge rule that invokes an AWS Lambda function to apply Lake Formation column-level grants or LF-Tags based on the Macie findings.
Why this is correct
An EventBridge rule matching Macie findings can trigger a Lambda function that calls Lake Formation APIs to restrict columns or attach LF-Tags. This automates the response so newly detected sensitive columns receive restrictive permissions without manual review, satisfying the automatic restriction requirement.
- ✗
Enable AWS CloudTrail data events on the S3 bucket and use them to identify objects containing credit card numbers.
Why it's wrong here
CloudTrail data events record object-level API activity such as GetObject and PutObject; they log who accessed objects, not the content of the objects. They cannot identify credit card numbers inside files, so they do not provide the detection capability the security team needs.
- ✓
Use Amazon Macie to run sensitive data discovery jobs against the S3 bucket and publish findings to Amazon EventBridge.
Why this is correct
Amazon Macie identifies sensitive data such as credit card numbers in S3 objects and publishes findings to EventBridge. Those findings are the detection signal that a remediation workflow can consume to identify which objects and columns contain sensitive values, enabling automated governance actions.
- ✗
Configure an AWS Glue crawler with a custom classifier to detect credit card number patterns and tag the columns in the Data Catalog.
Why it's wrong here
A Glue custom classifier can recognize custom formats during crawling, but classifiers affect schema inference and table creation, not the automated application of Lake Formation column permissions. It also does not produce the sensitive-data findings that drive governance actions on already registered tables.
- ✗
Configure S3 Block Public Access on the bucket and require SSE-KMS encryption for all objects.
Why it's wrong here
Block Public Access and SSE-KMS protect the bucket from public exposure and encrypt objects at rest, but neither inspects object contents for credit card numbers nor applies column-level permissions in Lake Formation. These controls address different risks than sensitive data detection and column restriction.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.