DEA-C01 Data Security and Governance Practice Question
A company stores sensitive customer data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. However, when a data engineer attempts to upload an object using the AWS CLI, the upload fails with an access denied error. The engineer has s3:PutObject permission on the bucket. Which additional permission is most likely missing?
⚠ Common exam trap
DEA-C01 often tests the confusion between encrypt-time and decrypt-time KMS permissions, so the trap is selecting kms:Decrypt for an upload failure when the actual missing permission is kms:GenerateDataKey.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kms:GenerateDataKey
When S3 encrypts an object with SSE-KMS using a customer-managed key, the caller must have kms:GenerateDataKey permission on that KMS key so S3 can obtain a data key to encrypt the object. The s3:PutObject permission alone authorizes the S3 API call but does not grant the KMS operation needed to produce the encryption key, so the upload fails with AccessDenied. Granting kms:GenerateDataKey on the CMK resolves the failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kms:CreateKey
Why it's wrong here
kms:CreateKey creates new KMS keys and has no role in encrypting an S3 upload. It is tempting because the scenario involves a customer-managed key, but the key already exists; creating keys is the correct permission when a principal must provision new customer-managed keys, not when writing objects.
- ✗
kms:Decrypt
Why it's wrong here
Uploading an object requires kms:GenerateDataKey to obtain a data key for encryption, not kms:Decrypt, which is needed only when reading encrypted objects. Decrypt is the right permission when a principal must download or read data encrypted under the KMS key.
- ✗
s3:PutObjectAcl
Why it's wrong here
s3:PutObjectAcl governs modifying an object's access control list, which the upload does not require. It is tempting because ACLs relate to object writes, but the failure stems from the missing KMS permission; PutObjectAcl would be correct when a principal must change object ACLs on an existing object.
- ✓
kms:GenerateDataKey
Why this is correct
Uploading with a customer-managed KMS key requires kms:GenerateDataKey to obtain a data key for envelope encryption. s3:PutObject alone is insufficient; without that KMS permission, the request fails with AccessDenied even though the S3 action is allowed.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.