DEA-C01 Data Ingestion and Transformation Practice Question
A social media company ingests user activity data from multiple sources using Amazon Kinesis Data Firehose. The data is delivered to Amazon S3 in near-real-time. The company wants to transform the data by adding a timestamp and masking email addresses before storing it in S3. The transformation should be applied to all records. What is the most cost-effective way to implement this transformation?
⚠ Common exam trap
The trap is choosing batch or post-storage transformation methods (Glue, S3 Events) instead of inline transformation, which is more efficient and cost-effective for near-real-time streaming data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Firehose delivery stream to invoke a Lambda function for data transformation.
Amazon Kinesis Data Firehose supports invoking an AWS Lambda function for inline data transformation before delivering data to the destination. This allows adding timestamps and masking email addresses in near-real-time as data flows through the delivery stream. It is the most cost-effective and operationally efficient way because it avoids additional storage, batch processing, or separate compute resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon Athena to run a CTAS query that transforms the data and writes to a new location.
Why it's wrong here
Athena CTAS queries operate on data *after* it is already stored in S3, not during ingestion; the requirement demands transformation *before* storage, which Kinesis Data Firehose’s built-in Lambda integration performs in-stream. This option is tempting because Athena is cost-effective for ad-hoc analytical transformations on historical data, and would be correct if the company needed to reprocess already-landed data rather than transform records in near-real-time during delivery.
- ✗
Use AWS Glue to schedule a batch job every 5 minutes to transform the data.
Why it's wrong here
Glue batch jobs introduce five-minute scheduling latency and pay for separate Spark or Python execution capacity, duplicating work Firehose already performs inline. It is tempting because Glue is a familiar managed transformation service, and would be correct for large periodic ETL over data already landed in S3.
- ✗
Use Amazon S3 Events to trigger a Lambda function whenever a new object is created.
Why it's wrong here
S3 event-triggered Lambda runs after objects are written, so unmasked email addresses are already stored and every object invokes a separate function. It is tempting because event-driven Lambda is serverless and familiar, and would be correct for post-landing processing where raw storage is acceptable.
- ✓
Configure the Firehose delivery stream to invoke a Lambda function for data transformation.
Why this is correct
Firehose supports inline Lambda transformation, invoking the function on each batch before delivery to Amazon S3. This applies the timestamp addition and email masking to all records without managing servers, satisfying the stem's cost-effectiveness and universal-transformation constraints more cheaply than separate processing infrastructure.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.