Courseiva

DEA-C01 Data Security and Governance Practice Question

A company is using Amazon Redshift for data warehousing. They need to ensure that data is encrypted at rest and in transit. Which TWO configurations are required to meet these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable encryption on the Redshift cluster using AWS KMS.

Option A is correct because enabling encryption on the Redshift cluster using AWS KMS provides encryption at rest — Redshift uses KMS customer master keys to encrypt the cluster's data blocks and system metadata on disk. Option B is correct because configuring the Redshift cluster to require SSL connections (via the require_ssl parameter set to true in the cluster's parameter group) enforces encryption in transit for all client and JDBC/ODBC connections to the cluster. Option C is not required because Redshift's at-rest encryption is natively managed through AWS KMS, not CloudHSM, and CloudHSM is not a prerequisite for meeting these requirements. Option D is incorrect because VPC Flow Logs capture IP traffic metadata for network monitoring and do not encrypt data at rest or in transit. Option E is incorrect because Redshift manages its own storage encryption at the cluster level; enabling EBS encryption on cluster nodes is neither a supported nor a required configuration for Redshift data encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable encryption on the Redshift cluster using AWS KMS.

    Why this is correct

    Enabling encryption on the Redshift cluster with AWS KMS satisfies the at-rest requirement, as it encrypts cluster data and snapshots using customer-managed or AWS-managed keys. This addresses the storage-layer constraint directly, though it does nothing for data in transit, which requires separate SSL/TLS configuration.

  • ✓

    Configure the Redshift cluster to require SSL connections.

    Why this is correct

    Requiring SSL connections forces every client session to negotiate TLS before queries execute, satisfying the in-transit encryption requirement. Redshift rejects unencrypted connections when this parameter is enabled, so data moving between clients and the cluster cannot be intercepted in plaintext. This directly addresses the transit half of the stem's two-part constraint.

  • ✗

    Use AWS CloudHSM to manage encryption keys for Redshift.

    Why it's wrong here

    CloudHSM manages keys for encryption at rest but provides no mechanism for encrypting data in transit, so it satisfies only half the requirement. It is tempting because customer-managed keys strengthen at-rest encryption, yet transit encryption requires TLS via the SSL option or parameter group setting.

  • ✗

    Enable VPC Flow Logs on the Redshift subnet.

    Why it's wrong here

    VPC Flow Logs capture metadata about IP traffic traversing the subnet; they neither encrypt nor enforce encryption of Redshift connections. It is tempting because flow logs are a network-security control, but transit encryption needs the cluster's SSL requirement enabled, and at-rest encryption needs a KMS key.

  • ✗

    Enable EBS encryption on the Redshift cluster nodes.

    Why it's wrong here

    EBS encryption protects volume data at rest beneath the cluster, but Redshift's requirement is met by cluster-level encryption (SSE-KMS or SSE-S3) plus TLS for in-transit connections. EBS encryption is tempting because it secures node storage, yet it neither encrypts Redshift-managed data nor enforces TLS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses Amazon Redshift for data warehousing. The security team requires that all data in transit between the Redshift cluster and clients be encrypted. Which feature should be enabled?

easy
  • A.Client-side VPN
  • ✓ B.SSL/TLS encryption
  • C.AWS KMS key
  • D.VPC peering

Why B: Amazon Redshift supports SSL/TLS encryption for client connections to ensure data in transit is encrypted. Option A (Client-side VPN) is not a Redshift feature for encrypting client connections. Option C (AWS KMS key) is used for encrypting data at rest, not in transit. Option D (VPC peering) does not provide encryption of data in transit between the cluster and clients.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.