Skip to content
BytePatterns

DEA-C01 · Domain 4: Data Security and Governance · 18% of the exam

Task 4.3: Ensure data encryption and masking

Keeping data unreadable to the wrong people: KMS keys at rest, encryption across accounts, encryption in transit or before sending, and masking or anonymizing sensitive fields.

Study it

  • Encryption with KMS, across accounts and in transit; masking sensitive data

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A Redshift table holds customer phone numbers. Support agents may see only the last four digits, while the fraud team must see full numbers. The stored data and the existing SQL queries must not change. What should a data engineer use?

  1. AA view that masks the column, which replaces the table in all queries
  2. BAn UPDATE statement that overwrites the numbers with masked values
  3. CEncryption of the cluster and its snapshots with a customer managed KMS key
  4. DA dynamic data masking policy attached to the column for the support role
Show the answer and why
  • AA view that masks the column, which replaces the table in all queries

    Incorrect

    Pointing queries at a view means changing the existing SQL, which the requirement rules out.

  • BAn UPDATE statement that overwrites the numbers with masked values

    Incorrect

    This changes the stored data, and the fraud team would lose the full numbers.

  • CEncryption of the cluster and its snapshots with a customer managed KMS key

    Incorrect

    Cluster encryption protects data at rest. Every authorized user still reads the full values.

  • DA dynamic data masking policy attached to the column for the support role

    Correct

    Dynamic data masking changes what a user or role sees at query time, without transforming the stored data or editing queries.

Masking that depends on who is asking belongs in a dynamic masking policy: same table, same queries, different results per role.

Question 2 · choose 2

Objects in an S3 bucket in account A are encrypted with SSE-KMS using a customer managed key in account A. An AWS Glue job role in account B must read them. The bucket policy already allows the role to call s3:GetObject, but the job fails with a KMS access denied error. Which actions are required? (Choose TWO.)

  1. ARe-encrypt all of the objects in account A with the AWS managed key named aws/s3
  2. BIn account A, allow account B to use the key for kms:Decrypt in the key policy
  3. CTurn on S3 Bucket Keys for the bucket in account A
  4. DSet S3 Object Ownership on the bucket to bucket owner enforced
  5. EIn account B, allow kms:Decrypt on the key in the Glue job role's IAM policy
Show the answer and why
  • ARe-encrypt all of the objects in account A with the AWS managed key named aws/s3

    Incorrect

    Resources encrypted under an AWS managed key cannot be shared with other accounts, because its key policy cannot be changed.

  • BIn account A, allow account B to use the key for kms:Decrypt in the key policy

    Correct

    Cross-account use of a KMS key needs permission in the key policy of the key, which lives in account A.

  • CTurn on S3 Bucket Keys for the bucket in account A

    Incorrect

    Bucket Keys reduce the cost of SSE-KMS by cutting requests to KMS. They do not grant anyone permission to use the key.

  • DSet S3 Object Ownership on the bucket to bucket owner enforced

    Incorrect

    Object Ownership controls ACLs and who owns uploaded objects. It does not give the role permission to use the KMS key.

  • EIn account B, allow kms:Decrypt on the key in the Glue job role's IAM policy

    Correct

    Users and roles in the external account cannot use the key until an IAM policy in their own account also allows it.

Cross-account KMS is a two-sided grant: the key policy must trust the other account, and that account must give its principal permission to use the key.

Question 3 · choose 1

A security review found that some applications upload data to a data lake bucket over plain HTTP. All requests to the bucket must use encrypted connections. What should a data engineer do?

  1. ASet the bucket's default encryption to SSE-KMS with a customer managed key in KMS
  2. BTurn on S3 Object Lock in governance mode for the bucket
  3. CAdd a bucket policy that denies requests where aws:SecureTransport is false
  4. DTurn on S3 Versioning so that every upload keeps a copy
Show the answer and why
  • ASet the bucket's default encryption to SSE-KMS with a customer managed key in KMS

    Incorrect

    Default encryption protects objects at rest after they arrive. It does not stop requests sent without TLS.

  • BTurn on S3 Object Lock in governance mode for the bucket

    Incorrect

    Object Lock prevents objects from being deleted or overwritten. It has no effect on the protocol used.

  • CAdd a bucket policy that denies requests where aws:SecureTransport is false

    Correct

    AWS recommends allowing only HTTPS (TLS) connections by using the aws:SecureTransport condition in S3 bucket policies.

  • DTurn on S3 Versioning so that every upload keeps a copy

    Incorrect

    Versioning keeps object versions. It does not affect how requests reach the bucket.

Encryption in transit is enforced at the request: a Deny on aws:SecureTransport = false rejects any HTTP call, whatever the client.

Question 4 · choose 1

Application log events in CloudWatch Logs contain customer email addresses. Most people who read the logs must see the addresses masked, while the security team must be able to see them. What should a data engineer configure?

  1. AA metric filter on the log group that matches the email addresses
  2. BA subscription filter that sends the events to Firehose for masking
  3. CA customer managed KMS key associated with the log group for encryption
  4. DA data protection policy on the log group, and logs:Unmask for security
Show the answer and why
  • AA metric filter on the log group that matches the email addresses

    Incorrect

    Metric filters turn matching log data into numeric metrics. The log events stay readable as they are.

  • BA subscription filter that sends the events to Firehose for masking

    Incorrect

    Subscriptions deliver a copy of the log events to other services. The events in the log group stay unmasked.

  • CA customer managed KMS key associated with the log group for encryption

    Incorrect

    A KMS key encrypts the log data at rest. Anyone allowed to read the logs still sees the email addresses.

  • DA data protection policy on the log group, and logs:Unmask for security

    Correct

    Data protection policies mask matching sensitive data at egress points such as Logs Insights, and only users with logs:Unmask can view it unmasked.

Masking controls what readers see; encryption controls how data is stored. Log group data protection policies do the former, with logs:Unmask as the exception.

Question 5 · choose 2

An Amazon RDS for MySQL DB instance was created without encryption. It must now be encrypted at rest with a KMS key, using snapshots. Which TWO steps should a data engineer take after taking a snapshot of the instance? (Choose TWO.)

  1. ATake a second snapshot of the instance with encryption turned on
  2. BCreate an encrypted read replica of the instance and promote it
  3. CTurn on automatic rotation for the KMS key that will be used
  4. DCreate an encrypted copy of the snapshot with the KMS key
  5. ERestore a new DB instance from the encrypted snapshot copy
Show the answer and why
  • ATake a second snapshot of the instance with encryption turned on

    Incorrect

    You can't create an encrypted snapshot of an unencrypted DB instance.

  • BCreate an encrypted read replica of the instance and promote it

    Incorrect

    You can't have an encrypted read replica of an unencrypted DB instance.

  • CTurn on automatic rotation for the KMS key that will be used

    Incorrect

    Key rotation creates new key material for the key. It does not encrypt an unencrypted DB instance.

  • DCreate an encrypted copy of the snapshot with the KMS key

    Correct

    You can encrypt a copy of an unencrypted snapshot, which is how encryption is added to an unencrypted DB instance with snapshots.

  • ERestore a new DB instance from the encrypted snapshot copy

    Correct

    Restoring from the encrypted copy gives an encrypted copy of the original DB instance.

Snapshot, encrypted copy, restore: the snapshot path to encryption. RDS also documents a blue/green deployment as another way to reach an encrypted instance.

Question 6 · choose 1

An application encrypts records with AWS KMS in us-east-1 before copying them to eu-west-1. Consumers in eu-west-1 must decrypt the records without calling KMS in us-east-1 and without re-encrypting them. What should a data engineer use?

  1. AA single-Region key in us-east-1 with a grant for the consumer role in eu-west-1
  2. BThe AWS managed key for the service in each of the two Regions
  3. CA multi-Region primary key in us-east-1 and its replica key in eu-west-1
  4. DAutomatic key rotation on the existing key in us-east-1
Show the answer and why
  • AA single-Region key in us-east-1 with a grant for the consumer role in eu-west-1

    Incorrect

    A grant gives permission to use the key, but the key stays in us-east-1, so every decrypt is a cross-Region call.

  • BThe AWS managed key for the service in each of the two Regions

    Incorrect

    AWS managed keys are always single-Region keys, so each Region's key is unrelated to the other.

  • CA multi-Region primary key in us-east-1 and its replica key in eu-west-1

    Correct

    Related multi-Region keys share key material and key ID, so data encrypted in one Region can be decrypted in another without a cross-Region call.

  • DAutomatic key rotation on the existing key in us-east-1

    Incorrect

    Rotation changes the key material over time. The key remains in us-east-1 only.

Multi-Region keys exist for this case: cross-Region data that must be decrypted locally, such as replicated or client-side encrypted data.

Question 7 · choose 1

A bucket uses SSE-KMS with a customer managed key, which the company must keep using. Billions of small objects are written each month, and the AWS KMS request charges are high. What should a data engineer do?

  1. ATurn on automatic key rotation for the customer managed key
  2. BRequest a higher KMS request quota for the account in the Region
  3. CTurn on S3 Bucket Keys for the bucket's SSE-KMS encryption
  4. DReplace the customer managed key with a multi-Region key
Show the answer and why
  • ATurn on automatic key rotation for the customer managed key

    Incorrect

    Rotation changes the key material on a schedule. Each object still needs its own call to KMS.

  • BRequest a higher KMS request quota for the account in the Region

    Incorrect

    A higher quota allows more requests per second, but each request is still charged.

  • CTurn on S3 Bucket Keys for the bucket's SSE-KMS encryption

    Correct

    A bucket-level key cuts the request traffic from S3 to KMS and can reduce KMS request costs by up to 99 percent.

  • DReplace the customer managed key with a multi-Region key

    Incorrect

    Multi-Region keys let data be decrypted in other Regions. They do not reduce the number of KMS requests.

For high-volume SSE-KMS buckets, Bucket Keys keep the customer managed key while S3 makes far fewer calls to KMS.

Question 8 · choose 1

An Amazon Redshift provisioned cluster was created without encryption. It must now be encrypted with a customer managed KMS key, with the least effort. What should a data engineer do?

  1. AUNLOAD all tables to S3, create an encrypted cluster, and COPY back
  2. BModify the cluster to turn on AWS KMS encryption with the key
  3. CSet require_ssl to true in the cluster's parameter group
  4. DTurn on automatic key rotation for the customer managed key
Show the answer and why
  • AUNLOAD all tables to S3, create an encrypted cluster, and COPY back

    Incorrect

    This would work, but modifying the cluster migrates the data automatically without a manual unload and reload.

  • BModify the cluster to turn on AWS KMS encryption with the key

    Correct

    You can modify an unencrypted cluster to use KMS encryption, and Redshift migrates the data to a new encrypted cluster automatically.

  • CSet require_ssl to true in the cluster's parameter group

    Incorrect

    require_ssl enforces encrypted connections, which protects data in transit, not data at rest.

  • DTurn on automatic key rotation for the customer managed key

    Incorrect

    Rotation changes the key's material. It does not encrypt an unencrypted cluster.

Redshift can add encryption to a running cluster by modifying it; plan for a read-only period while it migrates.

Practise domain 4 →Practise all domains →