DEA-C01 Data Security and Governance Practice Question
A company is designing a data pipeline using Amazon Kinesis Data Streams. The data includes personally identifiable information (PII). The security team requires that data be encrypted at rest using a customer-managed KMS key. How should the data engineer configure the Kinesis stream?
⚠ Common exam trap
DEA-C01 often tests the confusion between client-side encryption (producer encrypts before sending) and server-side encryption with a customer-managed KMS key, which is what the requirement explicitly asks for.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable server-side encryption on the Kinesis stream and specify the customer-managed KMS key.
Amazon Kinesis Data Streams supports server-side encryption (SSE) with AWS KMS, and you can choose either an AWS-managed key (aws/kinesis) or a customer-managed KMS key. To meet the requirement of encryption at rest with a customer-managed key, you enable SSE on the stream and specify the customer-managed KMS key, which Kinesis uses to encrypt data as it is written to storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Kinesis stream to use AWS CloudHSM for encryption.
Why it's wrong here
CloudHSM provides dedicated hardware security modules for key storage and cryptographic operations; Kinesis server-side encryption integrates only with AWS KMS keys, not CloudHSM directly. It is tempting where FIPS 140-2 Level 3 key custody is mandated, but the requirement here is a customer-managed KMS key on the stream.
- ✓
Enable server-side encryption on the Kinesis stream and specify the customer-managed KMS key.
Why this is correct
Server-side encryption with a customer-managed KMS key encrypts data at rest within the stream's storage layer, satisfying the requirement for customer-controlled key management. Kinesis Data Streams supports specifying a customer-managed key rather than the AWS-owned default, giving the security team the key control and rotation they demanded.
- ✗
Store the encrypted data in S3 and use Kinesis to stream the S3 object keys.
Why it's wrong here
Storing ciphertext in S3 and streaming only object keys moves the data out of Kinesis, so the stream itself is not encrypted at rest with a customer-managed KMS key as required. It is tempting for reducing stream payload size, but it would be correct only if Kinesis were merely a notification channel for S3-stored records.
- ✗
Use client-side encryption in the producer application to encrypt data before sending to Kinesis.
Why it's wrong here
Client-side encryption protects data before it reaches Kinesis, but the stream's at-rest server-side encryption remains AWS-owned rather than a customer-managed KMS key. It is tempting because it gives the producer full control of keys, and it would be correct when the security team mandates that AWS never hold plaintext or keys.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.