DEA-C01 Data Security and Governance Practice Question
A data engineer is preparing an AWS Glue ETL job that reads from and writes to Amazon S3 and must audit every access to sensitive data for compliance. The security team wants to know which principals accessed which objects and when, and also wants to detect anomalous access patterns. Which TWO AWS services should be used together to meet these requirements? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse data classification and inventory services such as Macie or S3 Inventory with access auditing, which requires CloudTrail data events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon GuardDuty S3 Protection
CloudTrail data events capture object-level API activity with caller identity, bucket, key, and time, forming the required audit trail for sensitive object access. GuardDuty S3 Protection analyzes that activity to surface anomalous or suspicious access. Together they provide both the detailed record and the detection capability, while inventory, bookmarks, and Macie address classification or processing state rather than access auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Macie sensitive data discovery jobs
Why it's wrong here
Macie discovers and classifies sensitive data such as personally identifiable information in S3 and reports findings about where it resides. It does not log every object access or attribute reads to specific principals, so it cannot serve as the access audit trail. It also does not perform access-pattern anomaly detection for S3 API calls, which is the role of GuardDuty S3 Protection.
- ✗
Amazon S3 Inventory reports
Why it's wrong here
S3 Inventory produces scheduled reports listing objects and their metadata, such as size, storage class, and encryption status. It is useful for inventory and lifecycle analysis but does not record access events, principals, or timestamps. Because it captures object state rather than activity, it cannot provide an audit trail of reads and writes or support anomaly detection of access patterns.
- ✗
AWS Glue job bookmarks
Why it's wrong here
Job bookmarks track which data has already been processed during previous runs so incremental ETL avoids reprocessing. They maintain state about source data, not about who accessed which object. They provide no audit trail of principals or timestamps and cannot detect anomalous access, so they do not satisfy either the auditing or the anomaly-detection requirement in this scenario.
- ✓
Amazon GuardDuty S3 Protection
Why this is correct
GuardDuty S3 Protection continuously analyzes CloudTrail data and management events to identify anomalous or suspicious S3 access, such as unusual API calls or access from unexpected locations. It surfaces findings that help the security team detect behavior changes rather than only recording raw events. Used alongside CloudTrail data events, it covers both the audit record and the anomaly detection requirement.
- ✓
AWS CloudTrail data events for S3
Why this is correct
CloudTrail data events record object-level API activity such as GetObject and PutObject, including the caller identity, bucket, object key, and timestamp. Enabling data events for the relevant S3 buckets provides the principal-to-object access trail the compliance team requires. Management events alone would not capture object reads, so data events are the correct audit source for sensitive object access.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.