Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is building an AWS Lambda function that processes records from an Amazon Kinesis data stream. The Lambda function needs to read from the stream and write processed data to an Amazon S3 bucket. The security team requires that all data in transit be encrypted using TLS, and that the Lambda function authenticate to Kinesis and S3 using temporary credentials. Which combination of configurations should the engineer use?

⚠ Common exam trap

The trap here is thinking that TLS must be explicitly configured or that KMS encryption is needed for data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an IAM role to the Lambda function with permissions for Kinesis and S3, and use the AWS SDK for Python (Boto3) to read and write data, relying on the SDK's default TLS.

AWS Lambda functions use an IAM role to obtain temporary credentials automatically. The AWS SDKs, such as Boto3, use TLS for all API calls by default, ensuring encryption in transit. This combination satisfies both the authentication and encryption requirements without manual key management. Other options either use long-term credentials, confuse encryption at rest with in transit, or use an inappropriate identity service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store long-term IAM user access keys in Lambda environment variables, and use them to sign requests to Kinesis and S3 over HTTPS.

    Why it's wrong here

    Using long-term IAM user access keys violates the requirement for temporary credentials and is a security risk. Environment variables can be exposed. While HTTPS provides TLS, the credentials are not temporary. Lambda should use an IAM role for temporary credentials, which is more secure and aligns with best practices.

  • ✓

    Assign an IAM role to the Lambda function with permissions for Kinesis and S3, and use the AWS SDK for Python (Boto3) to read and write data, relying on the SDK's default TLS.

    Why this is correct

    Lambda functions assume an IAM role that provides temporary credentials automatically. The AWS SDKs use TLS by default for all service communications, including Kinesis and S3. This setup meets the requirements for temporary credentials and encryption in transit. No additional configuration is needed for TLS; it is enforced by the SDK endpoints.

  • ✗

    Configure the Lambda function to use AWS KMS to encrypt the data before sending it to Kinesis and S3, and use an IAM role for authentication.

    Why it's wrong here

    KMS encryption is for data at rest, not in transit. The requirement is for TLS encryption in transit, which is provided by the AWS SDK. Adding KMS encryption would not satisfy the in-transit requirement and adds unnecessary complexity. Authentication via IAM role is correct, but the encryption method is wrong.

  • ✗

    Use Amazon Cognito identity pools to provide temporary credentials to the Lambda function, and enable TLS on the Kinesis and S3 clients.

    Why it's wrong here

    Cognito identity pools are designed for federated identity and mobile/web applications, not for Lambda execution roles. Lambda should use an IAM role for temporary credentials. While TLS is enabled by default, using Cognito here is inappropriate and adds unnecessary complexity. The IAM role approach is simpler and correct.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.