Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is designing a data lake on Amazon S3 that contains personally identifiable information (PII). The compliance team requires that all access to the data be logged and that any attempt to delete or modify data be detected and alerted. The engineer enables AWS CloudTrail data events for the S3 bucket and configures Amazon CloudWatch alarms. Which additional AWS service should the engineer use to automatically detect and remediate unauthorized changes to the S3 bucket's ACLs or policies?

⚠ Common exam trap

Watch out — candidates often confuse threat detection or data classification services with configuration compliance and remediation, which are the core capabilities of AWS Config.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Config with managed rules and automatic remediation.

AWS Config is designed to assess, audit, and evaluate configurations of AWS resources. With managed rules for S3, it can detect changes to ACLs and policies, and trigger automatic remediation via SSM Automation. Other services like Macie, Trusted Advisor, and GuardDuty focus on data classification, recommendations, or threat detection, not configuration compliance and remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Trusted Advisor with S3 bucket permissions checks.

    Why it's wrong here

    AWS Trusted Advisor provides recommendations on security best practices, including S3 bucket permissions, but it does not continuously monitor for changes or automatically remediate them. It is advisory only and cannot enforce or revert unauthorized modifications.

  • ✓

    AWS Config with managed rules and automatic remediation.

    Why this is correct

    AWS Config can monitor S3 bucket ACLs and policies for changes, evaluate them against desired configurations, and trigger automatic remediation using AWS Systems Manager Automation documents. This provides continuous detection and enforcement, aligning with the requirement to detect and remediate unauthorized changes.

  • ✗

    Amazon Macie with custom data identifiers.

    Why it's wrong here

    Amazon Macie discovers and classifies sensitive data in S3, but it does not monitor or remediate ACL or policy changes. While useful for PII detection, it does not provide configuration compliance or automatic remediation, which are needed to detect and revert unauthorized modifications.

  • ✗

    Amazon GuardDuty with S3 protection.

    Why it's wrong here

    Amazon GuardDuty with S3 protection detects suspicious activity and potential threats, such as unusual data access patterns, but it does not monitor configuration changes like ACL or policy modifications. It also does not provide automatic remediation capabilities.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.