DEA-C01 Data Security and Governance Practice Question
A company wants to enforce encryption in transit for data moving between an EC2 instance and an S3 bucket. Which TWO methods can achieve this? (Choose 2)
⚠ Common exam trap
DEA-C01 often tests the confusion between encryption at rest (SSE-S3) and encryption in transit (HTTPS/TLS), causing candidates to select SSE-S3 or CloudTrail as methods for enforcing in-transit encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy that denies requests without the aws:SecureTransport condition.
Option A is correct because a bucket policy with a Deny effect on s3:* conditioned on "aws:SecureTransport": "false" explicitly rejects any request made over plain HTTP, thereby enforcing encryption in transit for all access to the bucket, including from EC2. Option D is correct because S3's HTTPS endpoint (https://bucket.s3.amazonaws.com or the regional equivalent) uses TLS to encrypt data in transit between the EC2 instance and S3, satisfying the encryption-in-transit requirement directly. Option B is not correct because a VPC endpoint (Gateway or Interface) only changes the network path and can be used with either HTTP or HTTPS; it does not by itself guarantee encryption in transit. Option C is not correct because SSE-S3 provides encryption at rest for objects stored in the bucket, not encryption of data moving over the network. Option E is not correct because CloudTrail only logs and monitors API activity; it is a detective control that does not encrypt traffic or prevent unencrypted requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a bucket policy that denies requests without the aws:SecureTransport condition.
Why this is correct
The aws:SecureTransport condition key evaluates whether the request arrived over TLS; denying when it is false blocks plain HTTP calls to S3. This enforces encryption in transit at the bucket policy layer, satisfying the requirement that EC2-to-S3 traffic never travel unencrypted.
- ✗
Use a VPC endpoint for S3.
Why it's wrong here
A gateway VPC endpoint keeps S3 traffic on the AWS private network but does not by itself require TLS; plain HTTP over the endpoint remains possible. It is tempting because endpoints are genuinely used to bypass NAT gateways and control S3 routing, which is the correct scenario for private connectivity rather than encryption enforcement.
- ✗
Enable default SSE-S3 encryption on the bucket.
Why it's wrong here
SSE-S3 encrypts objects at rest on disk, not traffic between the EC2 instance and the bucket; it cannot enforce TLS. It is tempting because bucket default encryption is a core S3 security control, and it would be the right answer for a question asking how to secure stored objects without managing keys.
- ✓
Use the HTTPS endpoint for S3 API calls.
Why this is correct
Calling the S3 HTTPS endpoint (https://bucket.s3.region.amazonaws.com) wraps API requests in TLS, encrypting data in transit between the EC2 instance and S3. This directly satisfies the requirement that traffic use an encrypted transport rather than plain HTTP.
- ✗
Enable CloudTrail to monitor for non-encrypted requests.
Why it's wrong here
CloudTrail records API activity after the fact; it detects unencrypted requests but cannot enforce or require TLS on them. It is tempting because CloudTrail is genuinely the right service for auditing and alerting on S3 access patterns, just not for mandating encryption in transit.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.