Question 1 · choose 1
A Redshift table holds customer phone numbers. Support agents may see only the last four digits, while the fraud team must see full numbers. The stored data and the existing SQL queries must not change. What should a data engineer use?
- AA view that masks the column, which replaces the table in all queries
- BAn UPDATE statement that overwrites the numbers with masked values
- CEncryption of the cluster and its snapshots with a customer managed KMS key
- DA dynamic data masking policy attached to the column for the support role
Show the answer and why
AA view that masks the column, which replaces the table in all queries
Incorrect
Pointing queries at a view means changing the existing SQL, which the requirement rules out.
BAn UPDATE statement that overwrites the numbers with masked values
Incorrect
This changes the stored data, and the fraud team would lose the full numbers.
CEncryption of the cluster and its snapshots with a customer managed KMS key
Incorrect
Cluster encryption protects data at rest. Every authorized user still reads the full values.
DA dynamic data masking policy attached to the column for the support role
Correct
Dynamic data masking changes what a user or role sees at query time, without transforming the stored data or editing queries.
Masking that depends on who is asking belongs in a dynamic masking policy: same table, same queries, different results per role.
AWS documentation