DEA-C01 Data Store Management Practice Question
A company stores sensitive financial data in an Amazon S3 bucket. The data engineering team must ensure that all data is encrypted at rest using AWS Key Management Service (AWS KMS) customer managed keys, and that the encryption keys are rotated annually. The team also needs to audit key usage. Which solution meets these requirements?
⚠ Common exam trap
Watch out — candidates often confuse AWS managed keys with customer managed keys and assuming that S3 server access logging or S3 Inventory can audit KMS key usage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key, enable automatic key rotation for the KMS key, and enable AWS CloudTrail to log KMS API calls.
The correct solution uses SSE-KMS with a customer managed key to encrypt data at rest, enables automatic key rotation for that key to meet the annual rotation requirement, and enables AWS CloudTrail to log KMS API calls for auditing key usage. Other options either use incorrect key types (SSE-S3 or AWS managed keys) or do not provide the necessary auditing capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption on the S3 bucket using SSE-S3, and configure S3 server access logging to track key usage.
Why it's wrong here
SSE-S3 uses Amazon S3 managed keys, not AWS KMS customer managed keys, so it does not meet the requirement for customer managed keys. S3 server access logging records requests to the bucket but does not provide detailed audit trails for KMS key usage. To audit key usage, AWS CloudTrail must be used. This option fails both the encryption key type and auditing requirements.
- ✗
Use client-side encryption with a customer provided key stored in AWS Secrets Manager, and enable AWS CloudTrail to log S3 API calls.
Why it's wrong here
Client-side encryption with a customer provided key does not use AWS KMS customer managed keys, so it fails the encryption requirement. Storing the key in Secrets Manager does not provide automatic annual rotation or integrate with KMS for auditing. CloudTrail logging of S3 API calls does not capture key usage details for client-side encryption. This approach does not meet the specified encryption and auditing needs.
- ✗
Enable default encryption on the S3 bucket using SSE-KMS with an AWS managed key, and configure S3 Inventory to report on encryption status.
Why it's wrong here
SSE-KMS with an AWS managed key uses keys managed by AWS, not customer managed keys, so it does not satisfy the requirement for customer managed keys. S3 Inventory provides a report of objects and their encryption status but does not audit key usage. There is no automatic annual rotation for AWS managed keys. This option fails the key management and auditing requirements.
- ✓
Enable default encryption on the S3 bucket using SSE-KMS with a customer managed key, enable automatic key rotation for the KMS key, and enable AWS CloudTrail to log KMS API calls.
Why this is correct
SSE-KMS with a customer managed key satisfies the encryption requirement. Enabling automatic key rotation on the KMS key rotates the key annually. AWS CloudTrail logs all KMS API calls, providing an audit trail of key usage. This combination meets all specified requirements: encryption with customer managed keys, annual rotation, and auditing.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.