Courseiva

DEA-C01 Data Security and Governance Practice Question

A company is using Amazon S3 to store log files. The security team requires that all data be encrypted in transit. Which of the following ensures encryption in transit for S3?

⚠ Common exam trap

DEA-C01 often tests the confusion between encryption at rest and encryption in transit, leading candidates to select server-side encryption options that only protect data at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use HTTPS (SSL/TLS) when accessing S3 endpoints.

Encryption in transit for Amazon S3 is ensured by using HTTPS (SSL/TLS) when accessing S3 endpoints. HTTPS encrypts data as it travels between the client and S3, protecting it from eavesdropping. This is the standard method to enforce encryption in transit for S3, and it can be enforced via bucket policies that deny requests not using HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use HTTPS (SSL/TLS) when accessing S3 endpoints.

    Why this is correct

    HTTPS (SSL/TLS) encrypts data between the client and S3 endpoints, directly satisfying the in-transit encryption requirement. Server-side encryption options such as SSE-S3 or SSE-KMS protect data at rest only, leaving network traffic exposed. Enforcing TLS via bucket policies that deny non-secure transport further guarantees this.

  • ✗

    Use Amazon S3 Transfer Acceleration.

    Why it's wrong here

    S3 Transfer Acceleration speeds uploads over AWS edge locations but does not itself enforce TLS; clients can still connect over plain HTTP. It is tempting because it secures nothing yet sounds network-related. It would be the right choice when minimising cross-region upload latency, not when mandating encryption in transit.

  • ✗

    Enable client-side encryption before uploading to S3.

    Why it's wrong here

    Client-side encryption protects data at rest before upload; the encrypted payload still travels over HTTP unless TLS is enforced, so transit encryption is not guaranteed. It is tempting because it gives the customer full control of keys and suits strict at-rest requirements. Encryption in transit requires HTTPS or TLS on the S3 endpoint.

  • ✗

    Use server-side encryption with S3 managed keys (SSE-S3).

    Why it's wrong here

    SSE-S3 encrypts objects at rest after they reach S3; the upload itself still traverses the network unencrypted unless TLS is enforced. It is tempting because it is the simplest at-rest encryption option with no key management overhead. Encryption in transit requires HTTPS or TLS on the S3 endpoint.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.