Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring an AWS Glue crawler to catalog data stored in an Amazon S3 bucket. The security team requires that all data in transit between the crawler and S3 be encrypted using TLS. Which configuration should the engineer implement to meet this requirement?

⚠ Common exam trap

Watch out — candidates often confuse encryption at rest with encryption in transit, and assuming that S3 default encryption covers data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a bucket policy to the S3 bucket that denies requests that do not use the aws:SecureTransport condition.

To enforce encryption in transit for S3, the most direct method is to use a bucket policy that denies requests where aws:SecureTransport is false. This forces all clients, including AWS Glue crawlers, to use HTTPS. Glue crawlers use the AWS SDK, which defaults to HTTPS, so they will continue to work. This approach is recommended by AWS for compliance with encryption-in-transit requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the S3 bucket with SSE-S3, which automatically encrypts data in transit.

    Why it's wrong here

    Default encryption with SSE-S3 encrypts data at rest, not in transit. Encryption in transit is about protecting data as it moves over the network, typically using TLS. SSE-S3 does not affect the protocol used for data transfer. Therefore, this option does not enforce TLS for the Glue crawler's requests to S3.

  • ✗

    Enable SSL/TLS for the Glue crawler by setting the --enable-ssl parameter in the crawler configuration.

    Why it's wrong here

    AWS Glue crawlers do not have a parameter called --enable-ssl. Data in transit between Glue and S3 is automatically encrypted using TLS when using the AWS SDK, which Glue uses internally. There is no need to enable a specific parameter. Thus, this option is invalid and does not meet the requirement.

  • ✓

    Attach a bucket policy to the S3 bucket that denies requests that do not use the aws:SecureTransport condition.

    Why this is correct

    Enforcing TLS for data in transit to S3 is done by adding a bucket policy that denies requests where aws:SecureTransport is false. This ensures that any request, including from Glue crawlers, must use HTTPS. Glue crawlers use the AWS SDK, which uses HTTPS by default, so they will comply. This is the standard method to enforce encryption in transit for S3.

  • ✗

    Configure the Glue crawler to use a VPC endpoint for S3 and enable encryption in transit on the endpoint.

    Why it's wrong here

    VPC endpoints for S3 (Gateway or Interface) do not have an 'encryption in transit' setting. Traffic to S3 via a VPC endpoint still uses TLS if the client initiates it. However, a VPC endpoint alone does not enforce TLS; it only provides private connectivity. A bucket policy with aws:SecureTransport is needed to enforce TLS. Thus, this option does not meet the requirement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.