ETExamTower
Q22Data Security and Governance

A data engineer must use AWS services to ingest a dataset into an Amazon S3 data lake. The data engineer profiles the dataset and discovers that the dataset contains personally identifiable information (PII). The data engineer must implement a solution to profile the dataset and obfuscate the PII. Which solution will meet this requirement with the LEAST operational effort?

← → navigate · a answer
Community votes
B
50% (7)
C
43% (6)
A
7% (1)
D
0% (0)
Discussion · 19
B 12
Selected Answer: B How does Data Quality actually obfuscate PII? You can do this right in Glue Studio: https://docs.aws.amazon.com/glue/latest/dg/detect-PII.html
B 5
Selected Answer: B Option C adds extra steps and complexity by creating rules in AWS Glue Data Quality, which means more operational effort than using AWS Glue Studio's capabilities directly.
B 4
Selected Answer: B B is correct. C: glue data quality cannot obfuscate the PII D: need to write code but the question is the "LEAST operational effort"
C 3
Selected Answer: C The Detect PII transform in AWS Glue Studio is specifically used to identify personally identifiable information (PII) in the data. It can detect and flag this information, but by itself, it does not obfuscate or remove these details. To actually obfuscate or alter the identified PII, another transformation would be needed. This could be done in a few ways, such as: Writing a custom script within the same AWS Glue job using Python or Scala to modify the PII data as needed. Using AWS Glue Data Quality, if available, to create rules that automatically obfuscate or modify the data identified as PII. AWS Glue Data Quality is a newer tool that helps improve data quality through rules and transformations, but whether it's needed will depend on the functionality's availability and the specificity of the obfuscation requirements
C 3
Selected Answer: C We cannot directly handle PII with Glue Studio, and Glue Data Quality can be used for PII handling.
3
I don't think we need to use much more services to meet these requirements. Just AWS Glue is enough, it can already detect and obfuscate PII data. Source: https://docs.aws.amazon.com/glue/latest/dg/detect-PII.html#choose-action-pii
2
In python --- from awsglue.utils import getResolvedOptions from pyspark.context import SparkContext from awsglue.context import GlueContext from pyspark.sql import SparkSession # Initialize Spark session spark = SparkSession.builder \ .appName("Example Glue Job") \ .getOrCreate() # Initialize Glue context glueContext = GlueContext(SparkContext.getOrCreate()) # Retrieve Glue job arguments args = getResolvedOptions(sys.argv, ['JOB_NAME']) # Define your EMR step emr_step = [ { "Name": "My EMR Step", "ActionOnFailure": "CONTINUE", "HadoopJarStep": { "Jar": "s3://your-bucket/emr-scripts/your_script.jar", "Args": [ "arg1", "arg2" ] } } ] # Execute the EMR step response = glueContext.start_job_run(args['JOB_NAME'], job_run_args={'--extra-py-files': 'your_script.py'}) print(response)
2
Answer is option C. Period
B 2
Selected Answer: B https://docs.aws.amazon.com/glue/latest/dg/detect-PII.html
B 2
Selected Answer: B B offers a streamlined, mostly visual approach using purpose-built tools for data processing and PII handling, making it the solution with the least operational effort.
2
Yes, and about the "Create a rule in AWS Glue Data Quality to obfuscate the PII. " which is included in answer C, it cannot be done that way because in the aws glue console there is a section, "detect sensitive data" and then "types of sensitive information to detect". So through this console you can obfuscate PII. Relevant tutorial: https://www.youtube.com/watch?v=-TZZBfcnxBw
C 2
Selected Answer: C B. Use the Detect PII transform in AWS Glue Studio to identify the PII. Obfuscate the PII. Use an AWS Step Functions state machine to orchestrate a data pipeline to ingest the data into the S3 data lake. Detect PII transform only detects. Obfuscate the PII ok but how? Answer C explain how
A 1
Selected Answer: A A very easy way is to use the SDK to identify PII. https://docs.aws.amazon.com/code-library/latest/ug/comprehend_example_comprehend_DetectPiiEntities_section.html
C 1
Selected Answer: C answer is C
C 1
Selected Answer: C https://aws.amazon.com/blogs/big-data/automated-data-governance-with-aws-glue-data-quality-sensitive-data-detection-and-aws-lake-formation/
1
Actually it is B
1
The key thing
C 1
Selected Answer: C Why C is better than B: Obfuscation clarity: Option C explicitly says using a Glue Data Quality rule to obfuscate PII, while option B does not say how obfuscation is implemented. Accuracy: Glue Data Quality gives a more structured way to handle obfuscation compared with relying only on Glue Studio's PII detection. So, C is the most accurate and operationally efficient solution.
B 1
Selected Answer: B Actually, it's B. No need to create a rule in AWS Glue.