Be able to choose the correct encryption mechanism per service, grant least-privilege access through IAM and Lake Formation, and read permission-denied errors to find the missing schema, role, or policy. The single most important skill is mapping a data-access failure to its exact AWS control.
Start practicing
Data Security and Governance — choose a session length
Free · No account required
Domain overview
This domain covers encryption at rest and in transit, IAM and Lake Formation permissions, and audit/governance controls across AWS analytics services. Questions are scenario-based: you pick the right encryption option for S3, RDS, or Redshift, diagnose access-denied errors, or sequence a DMS migration with correct credentials and endpoints.
Exam objectives
Selecting SSE-S3, SSE-KMS, or SSE-C for Amazon S3 data-at-rest encryption
Granting Lake Formation table and column permissions for Athena and Redshift Spectrum
Enforcing TLS for Amazon RDS for MySQL connections with require_secure_transport
Diagnosing Redshift 'permission denied for relation' from schema, ownership, or search_path issues
Assuming a table-level SELECT grant is sufficient in Redshift when the user also lacks USAGE on the schema or is not the owner.
Confusing SSE-C, where the customer supplies and manages the key, with SSE-KMS, where AWS KMS stores and rotates the key.
Forgetting that AWS DMS needs source and target endpoints plus a replication instance and IAM roles before starting the task.
Practice questions for the Data Security and Governance domain are being added. Check back soon.
← Back to all DEA-C01 domainsBe able to choose the correct encryption mechanism per service, grant least-privilege access through IAM and Lake Formation, and read permission-denied errors to find the missing schema, role, or policy. The single most important skill is mapping a data-access failure to its exact AWS control.
The Courseiva DEA-C01 question bank contains 0 questions in the Data Security and Governance domain, covering the 18% of the exam attributed to this domain in the official Amazon Web Services blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Data Security and Governance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included