DEA-C01 Data Security and Governance Practice Question
A company uses AWS Glue to process sensitive data stored in S3. The security team requires that all data be encrypted at rest using customer-managed KMS keys. The data engineers are encountering 'Access Denied' errors when running Glue ETL jobs. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Glue service role does not have kms:Decrypt and kms:Encrypt permissions for the KMS key.
To decrypt S3 objects encrypted with a customer-managed KMS key, the AWS Glue job's service role must have kms:Decrypt and kms:Encrypt permissions in its IAM policy, and the KMS key policy must grant that role access. The most likely cause of the Access Denied error is missing KMS permissions on the Glue service role (A). Option B is a possible KMS key policy denial, but it is less likely than missing IAM KMS permissions in this scenario and is not as direct. Option C is irrelevant because Data Catalog encryption uses a different key and does not prevent S3 object access. Option D would be an S3 bucket policy denial, not a KMS 'Access Denied'; the issue here is KMS permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Glue service role does not have kms:Decrypt and kms:Encrypt permissions for the KMS key.
Why this is correct
Correct. The Glue service role must have kms:Decrypt and kms:Encrypt permissions for the KMS key to read/write encrypted data from S3.
- ✗
The KMS key policy does not allow the AWS Glue service to use the key.
Why it's wrong here
Incorrect. The KMS key policy can grant access to the Glue service principal, but the error is more likely due to missing IAM permissions on the Glue service role.
- ✗
The Glue Data Catalog is encrypted with a different KMS key.
Why it's wrong here
Incorrect. The KMS Data Catalog encryption uses a different key, but the error is about accessing S3 data, not the catalog.
- ✗
The S3 bucket policy denies access to the Glue service role.
Why it's wrong here
Incorrect. The 'Access Denied' error is related to KMS key permissions, not S3 bucket policy. S3 bucket policy denials would result in a different error message.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DEA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A financial services company uses AWS Glue ETL jobs to process sensitive customer data stored in Amazon S3. The data is encrypted at rest with SSE-KMS using a customer-managed key. Recently, the security team discovered that the Glue job's IAM role has an overly permissive policy that allows the 'kms:Decrypt' action for all KMS keys in the account. The company wants to follow the principle of least privilege. The Glue job runs on a schedule and reads from a specific S3 bucket. The security team needs to update the IAM policy to restrict KMS decryption to only the specific key used for that bucket. What should they do?
medium- A.Update the policy to allow 'kms:Decrypt' with a resource of 'arn:aws:kms:us-east-1:123456789012:key/*' to cover all keys in the account.
- B.Update the policy to allow 'kms:Decrypt' with a resource of '*' to ensure the job can always decrypt data.
- ✓ C.Update the policy to allow 'kms:Decrypt' only for the specific KMS key ARN used by the S3 bucket containing the customer data.
- D.Remove the 'kms:Decrypt' action from the policy and rely on S3 bucket policies to grant decryption permissions.
Why C: To follow least privilege, the IAM role for the Glue job should only have access to decrypt using the specific KMS key that encrypts the S3 bucket containing the customer data. This is done by allowing 'kms:Decrypt' with a resource set to the exact ARN of that key, not a wildcard or all keys. Option A is incorrect because using a wildcard in the key ARN (key/*) still grants access to all keys under that key hierarchy, which is overly permissive. Option B is incorrect because allowing 'kms:Decrypt' with resource '*' would grant access to all keys in the account, violating least privilege. Option D is incorrect because removing 'kms:Decrypt' from the IAM policy would prevent the Glue job from decrypting the data; the job's IAM role needs the permission, and relying solely on S3 bucket policies cannot grant decryption permissions cross-account or for IAM roles.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.