Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is preparing an AWS Glue ETL job that reads from and writes to Amazon S3 and must audit every access to sensitive data for compliance. The security team wants to know which principals accessed which objects and when, and also wants to detect anomalous access patterns. Which TWO AWS services should be used together to meet these requirements? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse data classification and inventory services such as Macie or S3 Inventory with access auditing, which requires CloudTrail data events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon GuardDuty S3 Protection

CloudTrail data events capture object-level API activity with caller identity, bucket, key, and time, forming the required audit trail for sensitive object access. GuardDuty S3 Protection analyzes that activity to surface anomalous or suspicious access. Together they provide both the detailed record and the detection capability, while inventory, bookmarks, and Macie address classification or processing state rather than access auditing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Macie sensitive data discovery jobs

    Why it's wrong here

    Macie discovers and classifies sensitive data such as personally identifiable information in S3 and reports findings about where it resides. It does not log every object access or attribute reads to specific principals, so it cannot serve as the access audit trail. It also does not perform access-pattern anomaly detection for S3 API calls, which is the role of GuardDuty S3 Protection.

  • ✗

    Amazon S3 Inventory reports

    Why it's wrong here

    S3 Inventory produces scheduled reports listing objects and their metadata, such as size, storage class, and encryption status. It is useful for inventory and lifecycle analysis but does not record access events, principals, or timestamps. Because it captures object state rather than activity, it cannot provide an audit trail of reads and writes or support anomaly detection of access patterns.

  • ✗

    AWS Glue job bookmarks

    Why it's wrong here

    Job bookmarks track which data has already been processed during previous runs so incremental ETL avoids reprocessing. They maintain state about source data, not about who accessed which object. They provide no audit trail of principals or timestamps and cannot detect anomalous access, so they do not satisfy either the auditing or the anomaly-detection requirement in this scenario.

  • ✓

    Amazon GuardDuty S3 Protection

    Why this is correct

    GuardDuty S3 Protection continuously analyzes CloudTrail data and management events to identify anomalous or suspicious S3 access, such as unusual API calls or access from unexpected locations. It surfaces findings that help the security team detect behavior changes rather than only recording raw events. Used alongside CloudTrail data events, it covers both the audit record and the anomaly detection requirement.

  • ✓

    AWS CloudTrail data events for S3

    Why this is correct

    CloudTrail data events record object-level API activity such as GetObject and PutObject, including the caller identity, bucket, object key, and timestamp. Enabling data events for the relevant S3 buckets provides the principal-to-object access trail the compliance team requires. Management events alone would not capture object reads, so data events are the correct audit source for sensitive object access.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.