Courseiva

DEA-C01 Data Security and Governance Practice Question

A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which TWO steps should the data engineer take? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a customer-managed KMS key with a key policy that grants kms:Decrypt only to the allowed IAM roles

Option C is correct because a customer-managed KMS key allows you to define a key policy that explicitly grants kms:Decrypt only to the specific IAM roles, which is the core mechanism for restricting decryption permissions in KMS. Option E is correct because the S3 bucket must be configured to use SSE-KMS with that customer-managed key; otherwise, S3 would use a different key (such as the default aws/s3 key) and the key policy restriction would not apply to the objects. Option A is incorrect because the default AWS managed key aws/s3 has a key policy managed by AWS that grants broad permissions to the account, so it cannot be scoped to only specific IAM roles. Option B is incorrect because SSE-S3 uses AES-256 with S3-managed keys and does not involve KMS or IAM role-based decrypt permissions at all. Option D is incorrect because requiring MFA for kms:Decrypt adds an authentication condition but does not by itself limit decryption to specific IAM roles, and MFA is not the mechanism that enforces role-level restriction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the default AWS managed KMS key for S3 (aws/s3)

    Why it's wrong here

    The aws/s3 default AWS managed key uses a policy you cannot edit to restrict decryption to specific IAM roles. It is tempting because it requires no key management overhead, and it would be correct when you need basic encryption at rest without granular role-based access control.

  • ✗

    Use SSE-S3 encryption instead of KMS

    Why it's wrong here

    SSE-S3 uses AWS-managed keys with no KMS key policy, so IAM-role-level decrypt restrictions cannot be expressed at all. It is tempting because SSE-S3 removes key management overhead and satisfies baseline encryption-at-rest requirements where no per-identity decryption control is needed.

  • ✓

    Create a customer-managed KMS key with a key policy that grants kms:Decrypt only to the allowed IAM roles

    Why this is correct

    A customer-managed KMS key lets you attach a key policy restricting kms:Decrypt to named IAM roles, satisfying the stem's requirement that only specific roles decrypt. AWS-managed keys use fixed policies you cannot edit, so they cannot enforce this restriction.

  • ✗

    Add an IAM policy to the role that requires MFA for kms:Decrypt

    Why it's wrong here

    Requiring MFA for kms:Decrypt restricts *how* a role authenticates, not *which* roles may decrypt, so any role satisfying the MFA condition still succeeds. It is tempting because MFA conditions genuinely harden sensitive API calls, and would be the right control when the requirement is step-up authentication for privileged human operators rather than role-scoped key access.

  • ✓

    Configure the S3 bucket to use SSE-KMS with the customer-managed key

    Why this is correct

    Configuring SSE-KMS with a customer-managed key replaces AWS-managed encryption, giving you a key policy where you explicitly grant decrypt permissions to named IAM roles. This satisfies the stem's constraint that only specific roles can decrypt, since the key policy governs all cryptographic access independently of bucket policies.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.