Courseiva

DEA-C01 Data Security and Governance Practice Question

A company uses Amazon Kinesis Data Streams to ingest real-time financial data. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key, and that the key be rotated annually. The data engineer needs to configure the Kinesis stream to meet these requirements. Which combination of actions should the data engineer take?

⚠ Common exam trap

The trap here is thinking that AWS-managed KMS keys can be rotated by the customer or that manual rotation is necessary, when automatic rotation is available for customer-managed keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable server-side encryption on the Kinesis stream using the StartStreamEncryption API with the customer-managed KMS key, and enable automatic key rotation on the KMS key.

To encrypt a Kinesis data stream at rest with a customer-managed KMS key, you use the StartStreamEncryption API, specifying the stream and the KMS key. This enables server-side encryption. To rotate the key annually, you enable automatic key rotation on the customer-managed KMS key. AWS KMS automatically rotates the key material every year when automatic rotation is enabled. This combination meets both requirements with minimal effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable server-side encryption on the Kinesis stream using the StartStreamEncryption API with the customer-managed KMS key, and enable automatic key rotation on the KMS key.

    Why this is correct

    The StartStreamEncryption API enables server-side encryption for a Kinesis stream using a specified KMS key. By specifying a customer-managed key, the stream data is encrypted at rest with that key. Enabling automatic key rotation on the KMS key ensures the key is rotated annually, meeting the requirement. This is the correct and direct way to achieve both encryption and rotation.

  • ✗

    Enable encryption at rest by setting the Kinesis stream's EncryptionType to KMS and specifying a customer-managed key, then manually rotate the key by creating a new key and updating the stream configuration every year.

    Why it's wrong here

    While setting EncryptionType to KMS with a customer-managed key is correct, manual rotation by creating a new key and updating the stream is operationally heavy and error-prone. AWS KMS supports automatic key rotation for customer-managed keys, which is simpler and less risky. The requirement is for annual rotation, which automatic rotation can provide.

  • ✗

    Use AWS CloudFormation to deploy the Kinesis stream with the KmsKeyId property set to a customer-managed key, and set the EnableKeyRotation property to true on the key resource.

    Why it's wrong here

    AWS CloudFormation can deploy a Kinesis stream with encryption using the KmsKeyId property, and it can create a KMS key with EnableKeyRotation set to true. However, the Kinesis stream resource does not have a property to enable encryption directly; you must use the StreamEncryption property. The option as described might not correctly enable encryption on the stream, and the property names may be inaccurate.

  • ✗

    Configure the Kinesis stream to use AWS-managed KMS keys for encryption, and create a custom AWS Lambda function that rotates the key every 365 days.

    Why it's wrong here

    AWS-managed KMS keys cannot be rotated by the customer; rotation is managed by AWS automatically every three years (or as AWS decides). A custom Lambda function cannot rotate an AWS-managed key. Additionally, the requirement specifies a customer-managed key, so using AWS-managed keys does not meet the mandate.

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.