DEA-C01 Data Store Management Practice Question
A company stores critical financial data in Amazon DynamoDB. To meet compliance requirements, the data must be encrypted at rest with a customer-managed key. Which solution should the data engineer implement?
⚠ Common exam trap
Test-takers frequently confuse encryption at rest with encryption in transit (TLS) or assume that CloudHSM can be directly used with DynamoDB, when in fact DynamoDB only supports KMS for encryption at rest, and CloudHSM requires a custom integration layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the DynamoDB table to use a customer managed key from AWS KMS.
AWS DynamoDB integrates with AWS KMS to support encryption at rest using customer-managed keys (CMKs). By selecting a customer-managed key from KMS during table creation or via an update, the company can meet compliance requirements for controlling the encryption key lifecycle, including rotation and access policies. This approach ensures that the data is encrypted using AES-256 encryption, with the key material managed by the customer rather than AWS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the DynamoDB table to use a customer managed key from AWS KMS.
Why this is correct
DynamoDB supports encryption at rest using AWS KMS customer managed keys, configured per table. Selecting a customer managed key rather than the AWS owned default key satisfies the compliance requirement for a key the company controls and can audit.
- ✗
Use AWS CloudHSM to generate a key and import it into DynamoDB.
Why it's wrong here
DynamoDB does not accept imported CloudHSM keys for its at-rest encryption; it integrates with AWS KMS customer-managed keys instead. CloudHSM is tempting for dedicated key custody, yet the table's server-side encryption must reference a KMS key, not a CloudHSM-generated key imported directly.
- ✗
Enable default encryption on the DynamoDB table using S3-managed keys.
Why it's wrong here
DynamoDB cannot use S3-managed keys; its default encryption uses AWS-owned keys, and S3 key management is unrelated to DynamoDB tables. It is tempting because S3 default encryption is familiar, but the compliance requirement for a customer-managed key demands an AWS KMS customer-managed key on the table.
- ✗
Use AWS Certificate Manager to issue a certificate and configure TLS.
Why it's wrong here
AWS Certificate Manager issues TLS certificates for data in transit, which does nothing for encryption at rest in DynamoDB. It is tempting because compliance often demands encryption, but ACM addresses transport security; the requirement is a customer-managed KMS key applied to the table's server-side encryption at rest.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.