
AWSCertified Data Engineer - Associate
Domain 4Objective 3
Task 4.3: Ensure Data Encryption and Masking DEA-C01 Practice Questions (Page 4)
Part of the Content Domain 4: Data Security and Governance domain, which accounts for 18% of the DEA-C01 exam. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
18%of the exam
Questions 16–20
- 16
A data engineer needs to encrypt an Amazon RDS for PostgreSQL database using a customer-managed key (CMK) in AWS KMS. The database is already running. What is the most efficient way to achieve this?
Select an answer first - 17
What is the primary characteristic of a token used in tokenization?
Select an answer first - 18
A financial services company processes credit card numbers in a production application. To reduce PCI DSS scope, they want to replace the card numbers with unique identifiers that can be used for transactions but have no exploitable value if the database is compromised. The original card numbers must be retrievable for dispute resolution. Which approach should they use?
Select an answer first - 19
A data engineer wants to ensure that data is encrypted in transit between users and a web application fronted by an Application Load Balancer. What should be configured on the load balancer?
Select an answer first - 20
A payment processing system stores credit card numbers as tokens. Which statement best describes how tokenization protects the credit card numbers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DEA-C01” is a trademark of its owner, used for identification only.