Courseiva
Data Store Management →hardMultiple Choice

DEA-C01 Data Store Management Practice Question

A company stores sensitive financial data in an Amazon S3 bucket. The data engineering team must ensure that all data is encrypted at rest using AWS Key Management Service (AWS KMS) customer managed keys, and that the encryption keys are rotated annually. The team also needs to audit key usage. Which solution meets these requirements?

⚠ Common exam trap

Watch out — candidates often confuse AWS managed keys with customer managed keys and assuming that S3 server access logging or S3 Inventory can audit KMS key usage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key, enable automatic key rotation for the KMS key, and enable AWS CloudTrail to log KMS API calls.

The correct solution uses SSE-KMS with a customer managed key to encrypt data at rest, enables automatic key rotation for that key to meet the annual rotation requirement, and enables AWS CloudTrail to log KMS API calls for auditing key usage. Other options either use incorrect key types (SSE-S3 or AWS managed keys) or do not provide the necessary auditing capabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the S3 bucket using SSE-S3, and configure S3 server access logging to track key usage.

    Why it's wrong here

    SSE-S3 uses Amazon S3 managed keys, not AWS KMS customer managed keys, so it does not meet the requirement for customer managed keys. S3 server access logging records requests to the bucket but does not provide detailed audit trails for KMS key usage. To audit key usage, AWS CloudTrail must be used. This option fails both the encryption key type and auditing requirements.

  • ✗

    Use client-side encryption with a customer provided key stored in AWS Secrets Manager, and enable AWS CloudTrail to log S3 API calls.

    Why it's wrong here

    Client-side encryption with a customer provided key does not use AWS KMS customer managed keys, so it fails the encryption requirement. Storing the key in Secrets Manager does not provide automatic annual rotation or integrate with KMS for auditing. CloudTrail logging of S3 API calls does not capture key usage details for client-side encryption. This approach does not meet the specified encryption and auditing needs.

  • ✗

    Enable default encryption on the S3 bucket using SSE-KMS with an AWS managed key, and configure S3 Inventory to report on encryption status.

    Why it's wrong here

    SSE-KMS with an AWS managed key uses keys managed by AWS, not customer managed keys, so it does not satisfy the requirement for customer managed keys. S3 Inventory provides a report of objects and their encryption status but does not audit key usage. There is no automatic annual rotation for AWS managed keys. This option fails the key management and auditing requirements.

  • ✓

    Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key, enable automatic key rotation for the KMS key, and enable AWS CloudTrail to log KMS API calls.

    Why this is correct

    SSE-KMS with a customer managed key satisfies the encryption requirement. Enabling automatic key rotation on the KMS key rotates the key annually. AWS CloudTrail logs all KMS API calls, providing an audit trail of key usage. This combination meets all specified requirements: encryption with customer managed keys, annual rotation, and auditing.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.