Courseiva

DEA-C01 Data Security and Governance Practice Question

A company is building a data lake on AWS and must encrypt data at rest. Which services can provide server-side encryption for data stored in Amazon S3? (Choose TWO.)

⚠ Common exam trap

DEA-C01 often tests whether candidates confuse encryption at rest (SSE-S3, SSE-KMS) with encryption in transit (SSL/TLS) or client-side encryption, and may mistakenly select CloudHSM as a direct S3 encryption option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-S3

SSE-S3 (Option A) is correct because Amazon S3 server-side encryption with S3-managed keys (AES-256) encrypts objects at rest automatically, with AWS managing the key material and rotation. SSE-KMS (Option E) is also correct because it performs server-side encryption at rest using AWS KMS customer master keys (CMKs), giving you control over key policies, auditing, and rotation. Both are S3 server-side encryption modes applied after data reaches S3, satisfying the data-at-rest requirement. SSL/TLS (Option B) is wrong because it only encrypts data in transit between the client and S3, not at rest. AWS SDK client-side encryption (Option C) is wrong because it encrypts data before it is sent to S3, so it is client-side, not server-side. AWS CloudHSM (Option D) is wrong because it is a dedicated hardware security module service for key storage and cryptographic operations, not an S3 server-side encryption option by itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSE-S3

    Why this is correct

    SSE-S3 applies AES-256 encryption with keys fully managed and rotated by AWS, requiring no key configuration from the engineer. It satisfies the data-at-rest encryption requirement for S3 objects while removing customer key management overhead entirely.

  • ✗

    SSL/TLS

    Why it's wrong here

    SSL/TLS encrypts data in transit between clients and endpoints, so it cannot satisfy the stem's at-rest requirement for objects stored in Amazon S3. It is tempting because TLS is the standard mechanism for protecting data moving over networks, and it would be the right answer if the question asked how to secure uploads or API calls in flight.

  • ✗

    AWS SDK client-side encryption

    Why it's wrong here

    AWS SDK client-side encryption encrypts objects before they reach S3, so the service stores ciphertext it cannot decrypt — that is client-side, not server-side, encryption. It is tempting because it protects data in transit and at rest from AWS itself, and would be correct where the customer must retain sole control of keys and plaintext.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM supplies dedicated hardware security modules for key storage and cryptographic operations, not server-side encryption of S3 objects itself; S3 SSE-KMS and SSE-S3 perform that encryption. It is tempting because CloudHSM underpins custom key management, and would be correct where you must retain exclusive control of keys under strict compliance rules.

  • ✓

    SSE-KMS

    Why this is correct

    SSE-KMS encrypts S3 objects using AWS KMS customer master keys, giving separate key permissions, audit trails via CloudTrail, and control over rotation. It satisfies data-at-rest encryption while letting the company govern who may decrypt objects.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A data engineer runs the command shown to check the encryption configuration of an S3 bucket. The output shows SSEAlgorithm: AES256. What does this mean?

easy
  • ✓ A.The bucket uses SSE-S3 with Amazon S3-managed keys
  • B.The bucket uses SSE-KMS with a customer-managed key
  • C.The bucket uses SSE-C with customer-provided keys
  • D.The bucket does not have encryption enabled

Why A: AES256 refers to SSE-S3, where Amazon S3 manages the encryption keys using AES-256. Option B (SSE-KMS) would show 'aws:kms'. Option C (SSE-C) would require the customer to provide keys. Option D (no encryption) is incorrect because encryption is enabled.

Variation 2. Refer to the exhibit. A data engineer queries AWS CloudTrail to investigate a PutObject event. What does the exhibit reveal about the object sensitive.csv?

medium
  • A.The upload failed due to encryption mismatch.
  • ✓ B.The object was uploaded with server-side encryption using AWS KMS.
  • C.The object was not encrypted at rest.
  • D.The object was encrypted with SSE-S3.

Why B: The CloudTrail event contains `x-amz-server-side-encryption: aws:kms`, which confirms the object was uploaded with server-side encryption using AWS KMS (SSE-KMS). Option A is incorrect because the event shows a successful upload, not a failure. Option C is incorrect because the event indicates encryption was applied. Option D is incorrect because SSE-S3 would show `AES256`, not `aws:kms`.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.