DEA-C01 Data Security and Governance Practice Question
A company is using Amazon S3 to store log files. The security team requires that all data be encrypted in transit. Which of the following ensures encryption in transit for S3?
⚠ Common exam trap
DEA-C01 often tests the confusion between encryption at rest and encryption in transit, leading candidates to select server-side encryption options that only protect data at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use HTTPS (SSL/TLS) when accessing S3 endpoints.
Encryption in transit for Amazon S3 is ensured by using HTTPS (SSL/TLS) when accessing S3 endpoints. HTTPS encrypts data as it travels between the client and S3, protecting it from eavesdropping. This is the standard method to enforce encryption in transit for S3, and it can be enforced via bucket policies that deny requests not using HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use HTTPS (SSL/TLS) when accessing S3 endpoints.
Why this is correct
HTTPS (SSL/TLS) encrypts data between the client and S3 endpoints, directly satisfying the in-transit encryption requirement. Server-side encryption options such as SSE-S3 or SSE-KMS protect data at rest only, leaving network traffic exposed. Enforcing TLS via bucket policies that deny non-secure transport further guarantees this.
- ✗
Use Amazon S3 Transfer Acceleration.
Why it's wrong here
S3 Transfer Acceleration speeds uploads over AWS edge locations but does not itself enforce TLS; clients can still connect over plain HTTP. It is tempting because it secures nothing yet sounds network-related. It would be the right choice when minimising cross-region upload latency, not when mandating encryption in transit.
- ✗
Enable client-side encryption before uploading to S3.
Why it's wrong here
Client-side encryption protects data at rest before upload; the encrypted payload still travels over HTTP unless TLS is enforced, so transit encryption is not guaranteed. It is tempting because it gives the customer full control of keys and suits strict at-rest requirements. Encryption in transit requires HTTPS or TLS on the S3 endpoint.
- ✗
Use server-side encryption with S3 managed keys (SSE-S3).
Why it's wrong here
SSE-S3 encrypts objects at rest after they reach S3; the upload itself still traverses the network unencrypted unless TLS is enforced. It is tempting because it is the simplest at-rest encryption option with no key management overhead. Encryption in transit requires HTTPS or TLS on the S3 endpoint.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.