Ensure data encryption and masking.
5 practice questions under this official exam objective (DEA-C01) — each with the community-verified answer, a full option-by-option explanation and instant feedback.
How to Apply Two Layers of Server-Side Encryption to S3 Uploads?
Amazon S3 dual-layer server-side encryption with AWS KMS keys (DSSE-KMS) applies two independent encryption layers to each object and is the compliant
Why Does QuickSight Report Insufficient Permissions for Athena S3 Data?
Amazon QuickSight dashboards backed by Athena over S3 fail with insufficient-permissions errors when the QuickSight service role cannot read the S3 bu
How to Dynamically Redact S3 PII for Multiple Applications?
Amazon S3 Object Lambda runs code on S3 GET requests so PII can be redacted per application without storing duplicate datasets. This page establishes
Least Overhead PII Redaction in S3
This question addresses the best practice for protecting Personally Identifiable Information (PII) stored in Amazon S3 with minimal operational overhe
How to Enforce TLS 1.2 on an AWS Transfer Family Server?
AWS Transfer Family servers enforce encryption-in-transit standards through the server's security policy, not through certificates or network ACLs. Th