Use Macie and Step Functions to redact PII in production before copying, and schedule the state machine weekly with EventBridge

Answer Correct answer: A, D — redact PII with Macie and Step Functions in production before copying, and schedule the state machine weekly with EventBridge.

A company has an application that stores data that includes personally identifiable information (PII) in an Amazon S3 bucket. All data is encrypted with AWS Key Management Service (AWS KMS) customer managed keys. All AWS resources are deployed from an AWS CloudFormation template. A DevOps engineer needs to set up a development environment for the application in a different AWS account. The data in the development environment's S3 bucket needs to be updated once a week from the production environment's S3 bucket. The company must not move PII from the production environment without anonymizing the PII first. The data in each environment must be encrypted with different KMS customer managed keys. Which combination of steps should the DevOps engineer take to meet these requirements? (Choose two.)

  1. Activate Amazon Macie on the S3 bucket in the production account. Create an AWS Step Functions state machine to initiate a discovery job and redact all PII before copying files to the S3 bucket in the development account. Give the state machine tasks decrypt permissions on the KMS key in the production account. Give the state machine tasks encrypt permissions on the KMS key in the development account. Correct Answer
  2. Set up S3 replication between the production S3 bucket and the development S3 bucket. Activate Amazon Macie on the development S3 bucket. Create an AWS Step Functions state machine to initiate a discovery job and redact all PII as the files are copied to the development S3 bucket. Give the state machine tasks encrypt and decrypt permissions on the KMS key in the development account.
  3. Set up an S3 Batch Operations job to copy files from the production S3 bucket to the development S3 bucket. In the development account, configure an AWS Lambda function to redact ail PII. Configure S3 Object Lambda to use the Lambda function for S3 GET requests. Give the Lambda function's IAM role encrypt and decrypt permissions on the KMS key in the development account.
  4. Create a development environment from the CloudFormation template in the development account. Schedule an Amazon EventBridge rule to start the AWS Step Functions state machine once a week. Correct Answer
  5. Create a development environment from the CloudFormation template in the development account. Schedule a cron job on an Amazon EC2 instance to run once a week to start the S3 Batch Operations job.

Community Votes

AD
100%

100% of anonymous learners picked answer AD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The ordering requirement is decisive: redaction must happen in the production account before the data is copied, because once PII is written to the development bucket the violation has already occurred (A). Macie performs the PII discovery and the state machine orchestrates discovery plus redaction, decrypting with the production key and re-encrypting with the development key so the two environments use different keys (A). Creating the development environment from the same CloudFormation template gives the identical baseline, and an EventBridge scheduled rule is the native way to trigger the weekly run (D).

The compliance requirement is that PII must be anonymized before it leaves the production environment, and that each environment uses its own KMS key. Amazon Macie is activated on the production bucket to discover the PII, and an AWS Step Functions state machine runs a discovery job and redacts all PII before writing files to the development bucket, with its tasks granted decrypt on the production key and encrypt on the development key. Separately, the development environment is created from the CloudFormation template and an EventBridge rule starts the state machine once a week, so the redaction and copy cycle runs on the required schedule.

Setting up S3 replication from production to development and redacting as files are copied into the development bucket (B) — replication moves the objects first, so unredacted PII lands in the development account before Macie or the state machine can act, which violates the requirement not to move PII without anonymizing first. Copying with S3 Batch Operations and redacting on read through S3 Object Lambda (C) — the unredacted objects are still copied into the development bucket and remain there, so the PII has moved without being anonymized. Running a cron job on an EC2 instance to start the batch job (E) — this requires a long-running host to schedule work and does not perform the required redaction.

Community Discussion (5 comments)

jamesf 👍 4 Selected: AD
Option A addresses the need to anonymize PII before moving data to the development environment. By using Amazon Macie, you can identify PII in the production S3 bucket. AWS Step Functions can orchestrate a workflow to redact this PII before transferring the data. This ensures compliance with data protection requirements. You need to provide the necessary KMS key permissions for decrypting and encrypting data as it moves between accounts. Option D ensures that the data update process is automated and scheduled. Using Amazon EventBridge to trigger the AWS Step Functions state machine on a weekly basis automates the data transfer and anonymization process.
tgv 👍 3 Selected: AD
---> A D
trungtd 👍 3 Selected: AD
A. Anonymizing PII in the Production Account D. Automating the Weekly Data Transfer B suggests replicating the data before redacting PII, which violates the requirement C does not ensure that the PII is redacted before the data is stored in the development environment E introduces additional infrastructure management and costs
getadroit 👍 1
redact should be done before
getadroit 👍 2
A & D https://aws.amazon.com/blogs/security/how-to-use-amazon-macie-to-preview-sensitive-data-in-s3-buckets/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The governing requirement is that PII must not be moved out of production without being anonymized first, which means redaction has to occur while the data is still in the production account. Amazon Macie is activated on the production S3 bucket to discover the sensitive data, and an AWS Step Functions state machine is created to initiate the discovery job and redact all PII before the files are copied into the development account's bucket. Because the state machine operates across two accounts with different keys, its tasks are granted decrypt permission on the KMS key in the production account and encrypt permission on the KMS key in the development account, which satisfies both the anonymization ordering and the requirement that each environment use a different customer managed key (A). The second half creates the development environment from the CloudFormation template so it matches production, and schedules the EventBridge rule to start the state machine once a week, which delivers the required weekly cadence (D). A and D are the correct combination.

Why the Other Options Are Wrong

B sets up S3 replication between the production and development buckets, activates Macie on the development bucket, and redacts PII as files are copied into the development bucket. Replication copies the objects first, so the unredacted PII is written into the development account before any redaction occurs; trungtd identified this precisely, noting that B suggests replicating before redacting, which violates the requirement. It also activates Macie on the development bucket rather than production, so discovery happens after the data has already moved. C sets up an S3 Batch Operations job to copy files from production to development, then configures a Lambda in the development account to redact PII and attaches it through S3 Object Lambda for GET requests. The unredacted objects are still copied into the development bucket and persist there; redaction on read does not satisfy a requirement that PII must never be moved unanonymized. E creates the development environment from the CloudFormation template and schedules a cron job on an EC2 instance to start the S3 Batch Operations job weekly, which both requires a host to keep running and performs no redaction at all. A and D are correct.

Community Comment Notes

Community voted A,D unanimously. jamesf explained that A addresses the need to anonymize PII before moving data by using Macie to identify PII in the production bucket with Step Functions orchestrating the redaction. trungtd gave the decisive reasoning, that B suggests replicating the data before redacting which violates the requirement, and that C does not ensure the PII is redacted before the copy. getadroit independently concluded A and D, noting the redaction must be done before the copy, and cited the AWS Security Blog on using Macie to preview sensitive data in S3.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide