DEA-C01 Data Security and Governance Practice Question
A company uses AWS Glue to process data stored in Amazon S3. The security team mandates that all data in transit between AWS Glue and Amazon S3 must be encrypted with TLS. The Glue job connects to S3 using the AWS SDK. Which configuration should the data engineer implement to enforce TLS encryption for the Glue job's S3 connections?
⚠ Common exam trap
Test-takers frequently confuse encryption at rest with encryption in transit, or assuming Glue has a built-in TLS enforcement parameter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
To enforce TLS for all connections to an S3 bucket, including from AWS Glue, an S3 bucket policy that denies requests when aws:SecureTransport is false is the correct approach. This condition evaluates the transport protocol and blocks non-TLS requests. It is a best practice recommended by AWS for ensuring data in transit encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Glue job to use a VPC endpoint for S3 and enable AWS PrivateLink.
Why it's wrong here
Using a VPC endpoint for S3 with AWS PrivateLink keeps traffic within the AWS network, but it does not enforce TLS encryption. In fact, VPC endpoints support HTTP and HTTPS; without a policy, HTTP might be used. This option improves network isolation but does not guarantee TLS. It is not the correct method to enforce encryption in transit.
- ✓
Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
Why this is correct
An S3 bucket policy with a condition that denies access when aws:SecureTransport is false enforces that all requests to the bucket use TLS. This policy applies to any client, including AWS Glue, ensuring data in transit is encrypted. This is the standard AWS method to enforce TLS for S3 access.
- ✗
Set the Glue job parameter --encryption-mode to TLS.
Why it's wrong here
AWS Glue does not have a job parameter named --encryption-mode. Glue job parameters are specific to the script and libraries, and there is no such parameter to enforce TLS. This option is invalid because the parameter does not exist. The engineer would need to use other mechanisms to enforce TLS, such as bucket policies.
- ✗
Enable default encryption on the S3 bucket with SSE-KMS.
Why it's wrong here
Default encryption with SSE-KMS encrypts data at rest, not in transit. It does not enforce TLS for connections to S3. While encryption at rest is important, it does not meet the requirement for encrypting data in transit. This option addresses a different security control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.