Use Macie and Step Functions to redact PII in production before copying, and schedule the state machine weekly with EventBridge
A company has an application that stores data that includes personally identifiable information (PII) in an Amazon S3 bucket. All data is encrypted with AWS Key Management Service (AWS KMS) customer managed keys. All AWS resources are deployed from an AWS CloudFormation template. A DevOps engineer needs to set up a development environment for the application in a different AWS account. The data in the development environment's S3 bucket needs to be updated once a week from the production environment's S3 bucket. The company must not move PII from the production environment without anonymizing the PII first. The data in each environment must be encrypted with different KMS customer managed keys. Which combination of steps should the DevOps engineer take to meet these requirements? (Choose two.)
Community Votes
100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The ordering requirement is decisive: redaction must happen in the production account before the data is copied, because once PII is written to the development bucket the violation has already occurred (A). Macie performs the PII discovery and the state machine orchestrates discovery plus redaction, decrypting with the production key and re-encrypting with the development key so the two environments use different keys (A). Creating the development environment from the same CloudFormation template gives the identical baseline, and an EventBridge scheduled rule is the native way to trigger the weekly run (D).
The compliance requirement is that PII must be anonymized before it leaves the production environment, and that each environment uses its own KMS key. Amazon Macie is activated on the production bucket to discover the PII, and an AWS Step Functions state machine runs a discovery job and redacts all PII before writing files to the development bucket, with its tasks granted decrypt on the production key and encrypt on the development key. Separately, the development environment is created from the CloudFormation template and an EventBridge rule starts the state machine once a week, so the redaction and copy cycle runs on the required schedule.
Setting up S3 replication from production to development and redacting as files are copied into the development bucket (B) — replication moves the objects first, so unredacted PII lands in the development account before Macie or the state machine can act, which violates the requirement not to move PII without anonymizing first. Copying with S3 Batch Operations and redacting on read through S3 Object Lambda (C) — the unredacted objects are still copied into the development bucket and remain there, so the PII has moved without being anonymized. Running a cron job on an EC2 instance to start the batch job (E) — this requires a long-running host to schedule work and does not perform the required redaction.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The governing requirement is that PII must not be moved out of production without being anonymized first, which means redaction has to occur while the data is still in the production account. Amazon Macie is activated on the production S3 bucket to discover the sensitive data, and an AWS Step Functions state machine is created to initiate the discovery job and redact all PII before the files are copied into the development account's bucket. Because the state machine operates across two accounts with different keys, its tasks are granted decrypt permission on the KMS key in the production account and encrypt permission on the KMS key in the development account, which satisfies both the anonymization ordering and the requirement that each environment use a different customer managed key (A). The second half creates the development environment from the CloudFormation template so it matches production, and schedules the EventBridge rule to start the state machine once a week, which delivers the required weekly cadence (D). A and D are the correct combination.Why the Other Options Are Wrong
B sets up S3 replication between the production and development buckets, activates Macie on the development bucket, and redacts PII as files are copied into the development bucket. Replication copies the objects first, so the unredacted PII is written into the development account before any redaction occurs; trungtd identified this precisely, noting that B suggests replicating before redacting, which violates the requirement. It also activates Macie on the development bucket rather than production, so discovery happens after the data has already moved. C sets up an S3 Batch Operations job to copy files from production to development, then configures a Lambda in the development account to redact PII and attaches it through S3 Object Lambda for GET requests. The unredacted objects are still copied into the development bucket and persist there; redaction on read does not satisfy a requirement that PII must never be moved unanonymized. E creates the development environment from the CloudFormation template and schedules a cron job on an EC2 instance to start the S3 Batch Operations job weekly, which both requires a host to keep running and performs no redaction at all. A and D are correct.Community Comment Notes
Community voted A,D unanimously. jamesf explained that A addresses the need to anonymize PII before moving data by using Macie to identify PII in the production bucket with Step Functions orchestrating the redaction. trungtd gave the decisive reasoning, that B suggests replicating the data before redacting which violates the requirement, and that C does not ensure the PII is redacted before the copy. getadroit independently concluded A and D, noting the redaction must be done before the copy, and cited the AWS Security Blog on using Macie to preview sensitive data in S3.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →