DEA-C01 Data Security and Governance Practice Question
A company stores sensitive data in Amazon Redshift. The security team requires that all data in the cluster be encrypted at rest using a customer managed key in AWS KMS, and that the key be rotated annually. The data engineer needs to configure the Redshift cluster accordingly. Which action should the engineer take?
⚠ Common exam trap
Many candidates confuse encryption in transit (SSL) with encryption at rest, or assuming that key rotation is configured on the Redshift cluster rather than in KMS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Redshift cluster encryption using AWS KMS and select the customer managed key. Configure automatic key rotation for the KMS key with a 365-day rotation period.
To encrypt a Redshift cluster at rest with a customer managed KMS key, you enable encryption on the cluster and select the key. To rotate the key annually, you enable automatic rotation on that KMS key with a 365-day period. These are separate configurations but together satisfy the requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Redshift Spectrum to query data in S3 that is encrypted with SSE-KMS, and enable key rotation on the S3 bucket's default key.
Why it's wrong here
Redshift Spectrum queries external data in S3, but the requirement is for data stored in the Redshift cluster. Spectrum does not encrypt the cluster's local storage. Enabling rotation on an S3 default key does not apply to Redshift cluster encryption. This approach misinterprets the storage location and does not meet the requirement.
- ✗
Enable Redshift cluster encryption using AWS KMS and set the cluster parameter require_ssl to true.
Why it's wrong here
The require_ssl parameter enforces SSL for connections to the cluster, which is encryption in transit, not at rest. It does not address encryption at rest or key rotation. While important for security, it does not satisfy the requirement for customer managed key encryption and annual rotation. The engineer must configure KMS encryption and key rotation separately.
- ✗
Enable Redshift cluster encryption using AWS KMS and create a scheduled AWS Lambda function that calls kms:RotateKey on the key annually.
Why it's wrong here
AWS KMS does not provide a kms:RotateKey API operation. Key rotation is managed through the KMS console, CLI, or SDK by enabling automatic rotation or calling RotateKeyOnDemand. A Lambda function cannot call a non-existent API. The correct method is to enable automatic key rotation in KMS, which handles the annual rotation without custom code.
- ✓
Enable Redshift cluster encryption using AWS KMS and select the customer managed key. Configure automatic key rotation for the KMS key with a 365-day rotation period.
Why this is correct
Amazon Redshift supports encryption at rest with AWS KMS customer managed keys. When creating or modifying a cluster, you can choose a customer managed key. Separately, in AWS KMS, you can enable automatic rotation for that key with a custom period, such as 365 days. This meets both the encryption and rotation requirements. The key rotation is a property of the KMS key, not the Redshift cluster.
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.