Courseiva

DEA-C01 Data Security and Governance Practice Question

A company has an AWS Glue ETL job that reads from an RDS MySQL instance and writes to S3. The security team requires that the connection to RDS be encrypted and that credentials be rotated automatically. Which configuration should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store the password in AWS Secrets Manager with automatic rotation enabled and configure Glue to use SSL for the connection.

AWS Secrets Manager provides automatic rotation of RDS credentials, and AWS Glue can be configured to use SSL for an encrypted connection to RDS MySQL. Option A (Systems Manager Parameter Store) stores encrypted parameters but does not natively support automatic rotation of RDS credentials. Option B (IAM database authentication) provides authentication but does not encrypt the connection itself; SSL is still required for encryption. Option C (encrypted S3 bucket) is not a service designed for dynamic credential management and lacks automatic rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the database password in an encrypted parameter in Systems Manager Parameter Store and enable SSL for the connection.

    Why it's wrong here

    Parameter Store holds static values and offers no native automatic rotation of RDS credentials; rotation requires a Lambda-backed mechanism. It would suit storing configuration secrets, but the stem demands scheduled credential rotation, which Secrets Manager provides natively.

  • ✗

    Use IAM database authentication for RDS and store credentials in Glue connection properties.

    Why it's wrong here

    IAM database authentication issues short-lived tokens, yet Glue connection properties store static values and cannot refresh them automatically. It would suit applications generating tokens at runtime, not the stem's requirement for automatically rotated stored credentials.

  • ✗

    Store the password in a text file in an encrypted S3 bucket and use SSL.

    Why it's wrong here

    An S3 text file provides no rotation mechanism and exposes credentials to anyone with bucket read access, and Glue cannot natively consume it as a rotating secret. It would suit static artefact storage, not the automatic credential rotation the stem requires.

  • ✓

    Store the password in AWS Secrets Manager with automatic rotation enabled and configure Glue to use SSL for the connection.

    Why this is correct

    Secrets Manager with automatic rotation directly satisfies the credential-rotation constraint, unlike static Glue connection passwords. Enabling SSL encrypts data in transit between Glue and RDS MySQL, meeting the encryption requirement. Together these address both security mandates without custom rotation logic or manual credential updates.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A data engineer needs to securely store database credentials for an RDS instance. Which TWO AWS services can be used?

easy
  • A.AWS KMS
  • ✓ B.AWS Secrets Manager
  • C.AWS IAM
  • D.AWS CloudFormation
  • ✓ E.AWS Systems Manager Parameter Store

Why B: AWS Secrets Manager (B) is correct because it is purpose-built to store, rotate, and retrieve secrets such as RDS database credentials, and it natively integrates with RDS for automatic credential rotation. AWS Systems Manager Parameter Store (E) is also correct because it can store database credentials as SecureString parameters, which are encrypted with AWS KMS, allowing the data engineer to retrieve them securely at runtime. AWS KMS (A) only provides encryption keys and cryptographic operations; it does not itself store credentials or secrets. AWS IAM (C) manages identities, roles, and permissions, not secret values. AWS CloudFormation (D) is an infrastructure-as-code provisioning service and is not designed to store or retrieve database credentials.

Variation 2. A data engineer needs to securely store database credentials used by an AWS Glue ETL job. Which THREE steps should the engineer take?

medium
  • A.Hardcode the credentials in the Glue job script.
  • ✓ B.Store the credentials in AWS Secrets Manager.
  • ✓ C.Grant the Glue job's IAM role permission to read the secret.
  • ✓ D.Configure the Glue job to use the Secrets Manager connector to retrieve credentials.
  • E.Use AWS Systems Manager Parameter Store with a SecureString parameter.

Why B: Option B is correct because AWS Secrets Manager is purpose-built for securely storing and rotating sensitive values such as database credentials, keeping them out of code and configuration files. Option C is correct because the Glue job's IAM role must have an explicit policy allowing secretsmanager:GetSecretValue on the specific secret ARN; without this permission the job cannot retrieve the credentials. Option D is correct because the Glue job must be configured to actually fetch the secret at runtime, typically via the Secrets Manager connector or by calling the Secrets Manager API, so the credentials are injected into the connection rather than embedded in the script. Option A is wrong because hardcoding credentials in the Glue script exposes them in plaintext and violates security best practices. Option E is not among the marked answers; while Parameter Store SecureString can store secrets, it is not one of the three steps identified here for this scenario.

Variation 3. A data engineer needs to securely store database credentials used by a Lambda function. The solution must automatically rotate the credentials every 90 days. Which AWS service should the engineer use?

easy
  • A.AWS CloudHSM
  • B.AWS Systems Manager Parameter Store
  • C.IAM Roles for Lambda
  • ✓ D.AWS Secrets Manager

Why D: AWS Secrets Manager is purpose-built for storing and managing secrets such as database credentials, API keys, and tokens. It natively supports automatic rotation via Lambda rotation functions on a schedule (e.g., every 90 days), and integrates with RDS, Redshift, and DocumentDB for managed rotation. This directly satisfies both the secure storage and automatic 90-day rotation requirements.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.