DEA-C01 Data Store Management Practice Question
A data engineer is configuring an Amazon S3 bucket to store sensitive financial data. The company requires that all data be encrypted at rest using AWS Key Management Service (AWS KMS) customer managed keys, and that the encryption key be automatically rotated every year. The engineer creates a KMS customer managed key and enables automatic rotation. When uploading objects using the AWS CLI, the engineer uses the --sse aws:kms parameter but does not specify a key ID. What is the result of this configuration?
⚠ Common exam trap
The trap here is assuming that specifying --sse aws:kms automatically uses a customer managed key, when in fact it defaults to the AWS managed key unless a key ID is provided.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The objects are encrypted with the AWS managed key for S3 (aws/s3), not the customer managed key.
To use a specific KMS customer managed key for S3 default encryption or per-object encryption, you must explicitly provide the key ARN or alias. Omitting the key ID causes S3 to fall back to the AWS managed key (aws/s3), which does not meet the requirement of using a customer managed key with annual rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The objects are encrypted with the customer managed key because it is the only KMS key in the account.
Why it's wrong here
S3 does not automatically select a customer managed key based on account inventory. Without an explicit key ID, S3 defaults to the AWS managed key. The presence of only one customer managed key does not change this behavior; the key must be specified.
- ✗
The objects are encrypted with the customer managed key, and automatic rotation applies because the key is the default KMS key for the account.
Why it's wrong here
There is no concept of a default KMS key for an account that S3 would automatically use. The customer managed key must be explicitly specified. Automatic rotation is a property of the key itself, but it only applies if that key is used for encryption.
- ✓
The objects are encrypted with the AWS managed key for S3 (aws/s3), not the customer managed key.
Why this is correct
When you specify --sse aws:kms without a key ID, S3 uses the AWS managed key for S3 (aws/s3) by default. This key is managed by AWS and does not support automatic rotation configuration by the customer. To use the customer managed key, the engineer must specify its key ARN or alias with --sse-kms-key-id.
- ✗
The upload fails because a KMS key ID is required when using --sse aws:kms.
Why it's wrong here
The --sse aws:kms parameter can be used without a key ID; S3 will use the default AWS managed key. The upload will succeed, but not with the intended customer managed key. A key ID is only required if you want to use a specific customer managed key.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.