Courseiva

DEA-C01 Data Security and Governance Practice Question

A company is using Amazon Redshift for analytics and needs to ensure that all data is encrypted at rest. The current cluster does not have encryption enabled. What is the most efficient way to enable encryption?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a snapshot of the cluster and restore it to a new cluster with encryption enabled

Redshift does not support enabling encryption on an existing cluster; a new encrypted cluster must be created and data migrated. Modifying the cluster configuration or parameter groups does not enable encryption. Creating a snapshot and restoring it to a new cluster with encryption enabled is the standard approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the cluster parameter group to enable encryption

    Why it's wrong here

    Cluster parameter groups tune database configuration values; they contain no encryption setting, so this changes nothing about data-at-rest protection. Parameter groups are correct for workgroup or query tuning. Encryption requires either enabling it at cluster creation or restoring an unencrypted snapshot into a new encrypted cluster.

  • ✗

    Modify the cluster configuration to enable encryption

    Why it's wrong here

    Redshift cannot toggle encryption on an existing cluster; the modify API rejects the change, so data must be moved to a new encrypted cluster. It tempts because modifying configuration is the normal route for most Redshift settings, and would be correct for parameters such as node type or maintenance windows.

  • ✗

    Use AWS DMS to migrate data to a new encrypted cluster

    Why it's wrong here

    AWS DMS migrates data between engines and would require provisioning a new cluster plus copying all data, which is not the most efficient route. It is tempting because migration tools are familiar, but Redshift supports enabling encryption on an existing cluster directly, avoiding the full data copy.

  • ✓

    Create a snapshot of the cluster and restore it to a new cluster with encryption enabled

    Why this is correct

    Redshift cannot enable encryption in place on an existing unencrypted cluster. Snapshotting and restoring into a new cluster with encryption enabled is the supported, least-effort migration path, preserving data while applying KMS encryption at rest.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Arrange the steps to implement data encryption at rest for an Amazon Redshift cluster using AWS KMS.

medium
  • ✓ A.Step 1: Create a KMS key. Step 2: Launch a new Amazon Redshift cluster. Step 3: Enable encryption and specify the KMS key during launch. Step 4: Verify that the cluster is encrypted at rest.
  • B.Step 1: Launch a new Amazon Redshift cluster. Step 2: Create a KMS key. Step 3: Enable encryption and specify the KMS key. Step 4: Verify encryption.
  • C.Step 1: Create a KMS key. Step 2: Verify encryption. Step 3: Launch a new Amazon Redshift cluster. Step 4: Enable encryption and specify the KMS key.
  • D.Step 1: Specify the KMS key. Step 2: Create a KMS key. Step 3: Launch a new Amazon Redshift cluster. Step 4: Verify encryption.

Why A: First, create the KMS key. Then launch a new encrypted cluster, specify the key, configure, and verify encryption.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.