DEA-C01 Data Security and Governance Practice Question
A data engineer is designing a data lake on Amazon S3 that contains personally identifiable information (PII). The compliance team requires that all access to the data be logged and that any attempt to delete or modify data be detected and alerted. The engineer enables AWS CloudTrail data events for the S3 bucket and configures Amazon CloudWatch alarms. Which additional AWS service should the engineer use to automatically detect and remediate unauthorized changes to the S3 bucket's ACLs or policies?
⚠ Common exam trap
Watch out — candidates often confuse threat detection or data classification services with configuration compliance and remediation, which are the core capabilities of AWS Config.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config with managed rules and automatic remediation.
AWS Config is designed to assess, audit, and evaluate configurations of AWS resources. With managed rules for S3, it can detect changes to ACLs and policies, and trigger automatic remediation via SSM Automation. Other services like Macie, Trusted Advisor, and GuardDuty focus on data classification, recommendations, or threat detection, not configuration compliance and remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Trusted Advisor with S3 bucket permissions checks.
Why it's wrong here
AWS Trusted Advisor provides recommendations on security best practices, including S3 bucket permissions, but it does not continuously monitor for changes or automatically remediate them. It is advisory only and cannot enforce or revert unauthorized modifications.
- ✓
AWS Config with managed rules and automatic remediation.
Why this is correct
AWS Config can monitor S3 bucket ACLs and policies for changes, evaluate them against desired configurations, and trigger automatic remediation using AWS Systems Manager Automation documents. This provides continuous detection and enforcement, aligning with the requirement to detect and remediate unauthorized changes.
- ✗
Amazon Macie with custom data identifiers.
Why it's wrong here
Amazon Macie discovers and classifies sensitive data in S3, but it does not monitor or remediate ACL or policy changes. While useful for PII detection, it does not provide configuration compliance or automatic remediation, which are needed to detect and revert unauthorized modifications.
- ✗
Amazon GuardDuty with S3 protection.
Why it's wrong here
Amazon GuardDuty with S3 protection detects suspicious activity and potential threats, such as unusual data access patterns, but it does not monitor configuration changes like ACL or policy modifications. It also does not provide automatic remediation capabilities.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.