Courseiva

DEA-C01 Data Security and Governance Practice Question

A company uses Amazon Kinesis Data Streams to ingest real-time data. The compliance team requires that all data in the stream be encrypted at rest. Which configuration should be enabled?

⚠ Common exam trap

Many candidates confuse encryption in transit (TLS) with encryption at rest (SSE), leading candidates to select TLS as the solution for at-rest compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable server-side encryption using an AWS KMS key

Server-side encryption (SSE) for Amazon Kinesis Data Streams uses an AWS KMS key to automatically encrypt data at rest as it is written to the stream and decrypt it when read. This meets the compliance requirement for encryption at rest without requiring any changes to the producer or consumer applications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable TLS encryption on the Kinesis stream

    Why it's wrong here

    TLS secures data in transit between producers, consumers and the Kinesis endpoint; it does not encrypt records stored on stream shards, so the at-rest requirement remains unmet. It is tempting because TLS is a genuine Kinesis security control, and would be the right answer if the question asked about encryption in flight.

  • ✓

    Enable server-side encryption using an AWS KMS key

    Why this is correct

    Server-side encryption with an AWS KMS key encrypts stream data at rest, meeting the compliance mandate. Kinesis encrypts using the specified customer managed key before writing to storage and decrypts on retrieval, so producers and consumers need no changes beyond KMS permissions.

  • ✗

    Use client-side encryption in the producer application

    Why it's wrong here

    Client-side encryption protects records before they leave the producer, but the compliance requirement targets data at rest inside the stream itself, which server-side encryption with a KMS key addresses. It is tempting because client-side encryption is valid for end-to-end confidentiality, and would be correct where producers must hold keys and AWS must never see plaintext.

  • ✗

    Store the data in Amazon CloudWatch Logs instead

    Why it's wrong here

    CloudWatch Logs is a log storage and monitoring service, not a Kinesis stream destination that preserves real-time ingestion; it cannot hold stream records, so encryption at rest is irrelevant. It is tempting because CloudWatch Logs does encrypt stored log data, which would be the right choice for centralising application log retention.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.