Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is building a data pipeline that ingests sensitive data into Amazon S3 and then processes it with AWS Glue. The security team requires that the data be encrypted at rest using a customer managed key in AWS KMS, and that the engineer be able to audit all key usage. The engineer creates a KMS customer managed key and configures the S3 bucket to use SSE-KMS with that key. The Glue job's IAM role has been granted kms:Decrypt and kms:GenerateDataKey permissions on the key. However, when the Glue job runs, it fails with an access denied error related to KMS. Which additional action should the engineer take to resolve the error?

⚠ Common exam trap

The trap here is assuming that IAM permissions alone are sufficient for KMS access, when the key policy must also grant access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the KMS key policy to allow the Glue job's IAM role to use the key for cryptographic operations.

KMS key policies must explicitly allow the principal to use the key for cryptographic operations. Even with IAM permissions granting kms:Decrypt and kms:GenerateDataKey, the key policy is the ultimate gatekeeper. The Glue job's role must be listed in the key policy with the necessary permissions. Updating the key policy resolves the access denied error while adhering to the requirement for customer managed keys and auditable key usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable automatic key rotation on the KMS key to ensure the Glue job can retrieve the latest key material.

    Why it's wrong here

    Automatic key rotation changes the backing key material but does not affect permissions. It does not resolve access denied errors. The Glue job's failure is due to authorization, not key material availability. Enabling rotation would not grant the necessary permissions and would not fix the error.

  • ✓

    Update the KMS key policy to allow the Glue job's IAM role to use the key for cryptographic operations.

    Why this is correct

    KMS key policies are the primary access control for KMS keys. Even if an IAM policy grants kms:Decrypt and kms:GenerateDataKey, the key policy must also allow the principal to use the key. If the key policy does not explicitly grant access to the Glue job's role, access is denied. Updating the key policy to allow the role resolves the error while maintaining least privilege.

  • ✗

    Change the S3 bucket encryption to SSE-S3 so that KMS permissions are no longer required.

    Why it's wrong here

    Switching to SSE-S3 would remove the KMS dependency, but it violates the security team's requirement to use a customer managed key for encryption at rest and to audit key usage. This option bypasses the requirement rather than solving the permission issue, and it would reduce the security posture of the data.

  • ✗

    Grant the Glue job's IAM role kms:CreateGrant permission on the KMS key.

    Why it's wrong here

    kms:CreateGrant is not required for a Glue job to read and write S3 objects encrypted with SSE-KMS. The necessary permissions are kms:Decrypt and kms:GenerateDataKey, which are already granted. Adding CreateGrant would not resolve the access denied error and could unnecessarily broaden permissions, violating least privilege.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.