Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
AWS logo

AWSCertified Data Engineer - Associate

Domain 4Objective 3

Task 4.3: Ensure Data Encryption and Masking DEA-C01 Practice Questions (Page 3)

Part of the Content Domain 4: Data Security and Governance domain, which accounts for 18% of the DEA-C01 exam. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
8concepts
18%of the exam

Questions 11–15

  1. 11foundation · easy

    Which AWS service can encrypt data at rest in an Amazon Redshift cluster by default?

    Select an answer first
  2. 12expert · hard

    A data engineer is designing a data lake for a multinational company. The data includes personal data of EU citizens. The company must comply with GDPR, which requires that personal data be processed in a way that ensures appropriate security, including encryption. They also need to allow data scientists to run analytics on the data without seeing personally identifiable information (PII). Which combination of techniques should they use?

    Select an answer first
  3. 13application · medium

    A healthcare company needs to share patient data with a research partner. The data must be de-identified so that individual patients cannot be re-identified, but the research partner needs to link records across multiple data files. Which technique should be used?

    Select an answer first
  4. 14expert · hard

    A company uses Amazon Redshift for data warehousing. They need to enable encryption at rest for the Redshift cluster using a customer-managed key (CMK) in AWS KMS. The cluster is already running and contains critical data. What is the most efficient way to achieve this with minimal downtime?

    Select an answer first
  5. 15expert · hard

    A company is subject to HIPAA and stores protected health information (PHI) in Amazon S3. They need to ensure that all PHI is encrypted at rest and that access to the encryption keys is logged for audit purposes. They also need to be able to revoke access to the keys quickly if a security incident occurs. Which solution should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DEA-C01” is a trademark of its owner, used for identification only.