DEA-C01 Data Security and Governance Practice Question
A data engineer is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to an Amazon Redshift cluster. The security team requires that the data be encrypted in transit between Glue and Redshift. Which configuration should the engineer implement to meet this requirement?
⚠ Common exam trap
Candidates often confuse encryption at rest (cluster encryption) with encryption in transit (SSL/TLS), and assuming that enabling cluster encryption covers in-transit encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable SSL in the Redshift connection by setting the sslmode parameter to 'require' in the JDBC URL used by the Glue job.
To encrypt data in transit between AWS Glue and Amazon Redshift, the Glue job must establish an SSL connection to Redshift. This is done by adding sslmode=require to the JDBC URL in the Glue connection. This ensures that the connection uses SSL and rejects non-SSL connections. Other options either address encryption at rest or are not applicable to the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable SSL in the Redshift connection by setting the sslmode parameter to 'require' in the JDBC URL used by the Glue job.
Why this is correct
Amazon Redshift supports SSL encryption for connections. To enforce encryption in transit between Glue and Redshift, the JDBC connection must use SSL. Setting sslmode=require in the JDBC URL ensures that the connection uses SSL and fails if SSL is not available. This is the standard method to encrypt data in transit for Redshift connections from Glue.
- ✗
Use AWS Glue's built-in encryption feature by setting the --encryption-type parameter to 'ssl' in the job configuration.
Why it's wrong here
AWS Glue does not have an --encryption-type parameter for specifying SSL for connections. Glue jobs use connection properties to define how to connect to data stores. For Redshift, encryption in transit is controlled via the JDBC URL's sslmode parameter. This option is invalid and would not enable SSL.
- ✗
Enable encryption on the Redshift cluster by turning on cluster encryption, which automatically encrypts data in transit.
Why it's wrong here
Enabling encryption on a Redshift cluster encrypts data at rest, not in transit. Cluster encryption uses KMS to encrypt stored data. Encryption in transit must be configured separately via SSL/TLS settings in the client connection. Thus, this option does not meet the requirement for encryption in transit.
- ✗
Configure the Glue job to write to Redshift using the Redshift Spectrum feature, which automatically encrypts data in transit.
Why it's wrong here
Redshift Spectrum is used to query data in S3 from Redshift, not for writing data from Glue to Redshift. It does not apply to Glue ETL jobs writing to Redshift. Moreover, Spectrum does not inherently encrypt data in transit; it relies on S3 and Redshift's encryption. This option is irrelevant to the scenario.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.