DEA-C01 Data Security and Governance Practice Question
A data engineer must mask the last four digits of a credit card column in an Amazon Redshift table so that analysts in a specific role see masked values while a fraud team sees the full values. The engineer wants a solution that applies to all queries without modifying each analyst's SQL. Which approach should the engineer use?
⚠ Common exam trap
The trap here is choosing row-level security or a masking view, when only dynamic data masking changes column values transparently per role without altering queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a dynamic data masking policy with the credit card column, then attach it to the analyst role so masking applies automatically at query time.
Redshift dynamic data masking attaches a masking policy to a role, so any query by that role against the tagged column returns masked values automatically, with no SQL rewriting. Users in roles without the policy see the original data. This provides column-level, role-based protection that satisfies both teams' visibility needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a view that applies a masking expression to the credit card column and grant the analyst role access only to the view.
Why it's wrong here
A view can mask data, but analysts must be prevented from querying the base table directly, which requires separate privilege management and can break existing queries that reference the table. It also does not apply to all queries automatically. Dynamic data masking is the native mechanism designed to mask values transparently for selected roles.
- ✗
Encrypt the credit card column with AWS KMS and grant the analyst role decrypt permissions on a different key than the fraud team.
Why it's wrong here
Redshift does not expose per-column KMS decryption that yields different plaintext per role at query time. Encryption protects data at rest, but once a user can query the table they see decrypted values. Column-level role-based masking is the correct feature, not differential key access.
- ✗
Use row-level security to restrict the analyst role to rows where the credit card column is not null.
Why it's wrong here
Row-level security filters which rows a role can see; it does not alter the values within a column. Analysts would still view full credit card numbers in the rows they are permitted to read. The requirement is to obscure column values for a role, which is column-level masking rather than row filtering.
- ✓
Create a dynamic data masking policy with the credit card column, then attach it to the analyst role so masking applies automatically at query time.
Why this is correct
Redshift dynamic data masking policies are attached to roles and applied automatically whenever a user in that role queries the column, so no SQL changes are required. The fraud team, not attached to the masking policy, continues to see full values. This satisfies both the blanket masking requirement and role-based visibility in a single column-level control.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.