Courseiva

DEA-C01 Data Security and Governance Practice Question

A company stores sensitive customer data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. However, when a data engineer attempts to upload an object using the AWS CLI, the upload fails with an access denied error. The engineer has s3:PutObject permission on the bucket. Which additional permission is most likely missing?

⚠ Common exam trap

DEA-C01 often tests the confusion between encrypt-time and decrypt-time KMS permissions, so the trap is selecting kms:Decrypt for an upload failure when the actual missing permission is kms:GenerateDataKey.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kms:GenerateDataKey

When S3 encrypts an object with SSE-KMS using a customer-managed key, the caller must have kms:GenerateDataKey permission on that KMS key so S3 can obtain a data key to encrypt the object. The s3:PutObject permission alone authorizes the S3 API call but does not grant the KMS operation needed to produce the encryption key, so the upload fails with AccessDenied. Granting kms:GenerateDataKey on the CMK resolves the failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kms:CreateKey

    Why it's wrong here

    kms:CreateKey creates new KMS keys and has no role in encrypting an S3 upload. It is tempting because the scenario involves a customer-managed key, but the key already exists; creating keys is the correct permission when a principal must provision new customer-managed keys, not when writing objects.

  • ✗

    kms:Decrypt

    Why it's wrong here

    Uploading an object requires kms:GenerateDataKey to obtain a data key for encryption, not kms:Decrypt, which is needed only when reading encrypted objects. Decrypt is the right permission when a principal must download or read data encrypted under the KMS key.

  • ✗

    s3:PutObjectAcl

    Why it's wrong here

    s3:PutObjectAcl governs modifying an object's access control list, which the upload does not require. It is tempting because ACLs relate to object writes, but the failure stems from the missing KMS permission; PutObjectAcl would be correct when a principal must change object ACLs on an existing object.

  • ✓

    kms:GenerateDataKey

    Why this is correct

    Uploading with a customer-managed KMS key requires kms:GenerateDataKey to obtain a data key for envelope encryption. s3:PutObject alone is insufficient; without that KMS permission, the request fails with AccessDenied even though the S3 action is allowed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.