DEA-C01 Data Store Management Practice Question
A company wants to enforce that all data in an S3 bucket is encrypted at rest using AWS KMS. Which bucket policy condition key should be used?
⚠ Common exam trap
Test-takers frequently confuse `aws:kms` with `AES256` (SSE-S3), thinking both enforce KMS encryption, but only `aws:kms` enforces AWS KMS, while `AES256` enforces S3-managed keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3:x-amz-server-side-encryption with value aws:kms
The condition key `s3:x-amz-server-side-encryption` with value `aws:kms` enforces that objects uploaded to the S3 bucket must be encrypted using AWS KMS (SSE-KMS). This bucket policy condition ensures that any PUT request includes the `x-amz-server-side-encryption` header set to `aws:kms`, thereby enforcing encryption at rest with KMS-managed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
s3:x-amz-acl with value bucket-owner-full-control
Why it's wrong here
For ACLs, not encryption.
- ✓
s3:x-amz-server-side-encryption with value aws:kms
Why this is correct
Enforces SSE-KMS.
- ✗
s3:x-amz-server-side-encryption with value AES256
Why it's wrong here
Enforces SSE-S3, not KMS.
- ✗
aws:SourceIp with value 10.0.0.0/8
Why it's wrong here
For IP restrictions, not encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,711 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.