A company uses AWS Glue to process data from Amazon S3. The data contains personally identifiable information (PII). The data engineer needs to automatically detect and mask PII fields before the data is loaded into Amazon Redshift. Which combination of AWS services should be used?
Amazon Macie uses managed and custom data identifiers to detect PII in S3, publishing findings that drive the masking logic. AWS Glue then applies those detections during ETL, masking fields before writing to Redshift. Together they deliver automated detection and masking without manual schema inspection.
Why this answer
Option A is correct because Amazon Macie uses machine learning to automatically discover and classify PII in S3 data, and AWS Glue can then apply transforms (e.g., via a Glue ETL job or Glue Studio) to mask or redact those fields before loading into Redshift. Macie identifies sensitive data locations, and Glue performs the masking during the ETL pipeline, satisfying the requirement to detect and mask PII automatically.
Exam trap
DEA-C01 often tests the assumption that any AWS service with 'access' or 'analyzer' in its name can detect PII — candidates pick IAM Access Analyzer or S3 Object Lambda instead of Macie, which is the only service purpose-built for PII discovery.
How to eliminate wrong answers
Option B is wrong because CloudWatch Logs and Lambda are for log monitoring and event-driven compute, not for PII detection or data masking in S3-to-Redshift pipelines. Option C is wrong because S3 Object Lambda is used to transform data on retrieval via a Lambda function, but it does not provide automatic PII detection/classification like Macie, and it is not the standard combination for Glue-based ETL masking. Option D is wrong because IAM Access Analyzer identifies resource policies that grant external access — it does not detect or mask PII content.