Courseiva

DEA-C01 Data Security and Governance Practice Question

A company stores sensitive data in Amazon S3 and uses AWS KMS customer-managed keys for encryption. The security team wants to monitor and audit all KMS API calls that involve the key, including who used the key and when. They also want to receive alerts if the key is used by an unauthorized principal. Which AWS service should the data engineer use to meet these requirements?

⚠ Common exam trap

Many exam-takers confuse configuration compliance (AWS Config) or threat detection (GuardDuty) with API-level auditing and alerting, which CloudTrail and CloudWatch provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail with KMS key usage logs, and Amazon CloudWatch alarms based on CloudTrail metrics.

AWS CloudTrail logs all KMS API calls, providing a detailed audit trail. To receive alerts on unauthorized usage, you can create CloudWatch metric filters on CloudTrail logs and set up CloudWatch alarms. This combination meets both the auditing and alerting requirements. Other services like AWS Config, GuardDuty, or Security Hub do not provide the same level of detailed API call logging and direct alerting for KMS usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon GuardDuty with KMS protection, and AWS Lambda functions to remediate unauthorized access.

    Why it's wrong here

    GuardDuty is a threat detection service that monitors for malicious activity, but it does not provide detailed auditing of all KMS API calls. It may detect anomalous behavior, but it lacks the granular logging of CloudTrail. For comprehensive auditing and alerting on specific key usage, CloudTrail with CloudWatch is the appropriate solution.

  • ✗

    AWS CloudTrail with KMS key usage logs, and AWS Security Hub for automated alerts on unauthorized access.

    Why it's wrong here

    CloudTrail provides the necessary logs, but Security Hub aggregates findings from various services and does not natively alert on individual KMS API calls without additional configuration. Security Hub is more for compliance posture. CloudWatch alarms on CloudTrail metrics are more direct for real-time alerting on KMS usage.

  • ✓

    AWS CloudTrail with KMS key usage logs, and Amazon CloudWatch alarms based on CloudTrail metrics.

    Why this is correct

    AWS CloudTrail captures all KMS API calls as events, including the identity of the caller, time, and key ID. These events can be delivered to an S3 bucket and also to CloudWatch Logs. By creating metric filters and CloudWatch alarms, you can alert on unauthorized usage patterns. This provides both auditing and alerting, meeting the requirements.

  • ✗

    AWS Config with KMS key configuration rules, and Amazon SNS notifications for noncompliance.

    Why it's wrong here

    AWS Config evaluates resource configurations against desired states, but it does not track individual API calls or key usage. It can detect if a key policy changes, but not who used the key or when. SNS notifications would only alert on configuration changes, not on unauthorized usage. CloudTrail is needed for API-level auditing.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.