DEA-C01 Data Security and Governance Practice Question
A data engineer is configuring an AWS Glue crawler to catalog data stored in an Amazon S3 bucket. The security team requires that all data in transit between the crawler and S3 be encrypted using TLS. Which configuration should the engineer implement to meet this requirement?
⚠ Common exam trap
Watch out — candidates often confuse encryption at rest with encryption in transit, and assuming that S3 default encryption covers data in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a bucket policy to the S3 bucket that denies requests that do not use the aws:SecureTransport condition.
To enforce encryption in transit for S3, the most direct method is to use a bucket policy that denies requests where aws:SecureTransport is false. This forces all clients, including AWS Glue crawlers, to use HTTPS. Glue crawlers use the AWS SDK, which defaults to HTTPS, so they will continue to work. This approach is recommended by AWS for compliance with encryption-in-transit requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption on the S3 bucket with SSE-S3, which automatically encrypts data in transit.
Why it's wrong here
Default encryption with SSE-S3 encrypts data at rest, not in transit. Encryption in transit is about protecting data as it moves over the network, typically using TLS. SSE-S3 does not affect the protocol used for data transfer. Therefore, this option does not enforce TLS for the Glue crawler's requests to S3.
- ✗
Enable SSL/TLS for the Glue crawler by setting the --enable-ssl parameter in the crawler configuration.
Why it's wrong here
AWS Glue crawlers do not have a parameter called --enable-ssl. Data in transit between Glue and S3 is automatically encrypted using TLS when using the AWS SDK, which Glue uses internally. There is no need to enable a specific parameter. Thus, this option is invalid and does not meet the requirement.
- ✓
Attach a bucket policy to the S3 bucket that denies requests that do not use the aws:SecureTransport condition.
Why this is correct
Enforcing TLS for data in transit to S3 is done by adding a bucket policy that denies requests where aws:SecureTransport is false. This ensures that any request, including from Glue crawlers, must use HTTPS. Glue crawlers use the AWS SDK, which uses HTTPS by default, so they will comply. This is the standard method to enforce encryption in transit for S3.
- ✗
Configure the Glue crawler to use a VPC endpoint for S3 and enable encryption in transit on the endpoint.
Why it's wrong here
VPC endpoints for S3 (Gateway or Interface) do not have an 'encryption in transit' setting. Traffic to S3 via a VPC endpoint still uses TLS if the client initiates it. However, a VPC endpoint alone does not enforce TLS; it only provides private connectivity. A bucket policy with aws:SecureTransport is needed to enforce TLS. Thus, this option does not meet the requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.