Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring an AWS Glue ETL job that reads from and writes to an Amazon S3 bucket. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS, and that the job must fail if TLS is not used. Which two actions should the data engineer take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that enabling default encryption or using a VPC endpoint automatically enforces TLS for all traffic, when only explicit bucket policy denials based on aws:SecureTransport guarantee that insecure requests are rejected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a bucket policy that denies s3:GetObject requests where aws:SecureTransport is false.

To enforce TLS for all data in transit between AWS Glue and Amazon S3, you must deny both read and write requests that do not use TLS. Bucket policies that deny s3:GetObject and s3:PutObject when aws:SecureTransport is false accomplish this. Default encryption, VPC endpoint policies, and Transfer Acceleration do not universally enforce TLS for all Glue-to-S3 traffic or cause the job to fail on insecure connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach a bucket policy that denies s3:GetObject requests where aws:SecureTransport is false.

    Why this is correct

    A bucket policy denying s3:GetObject when aws:SecureTransport is false blocks any read request that does not use TLS. This ensures the Glue job cannot read data insecurely and will fail if it attempts a non-TLS connection, satisfying the requirement for encryption in transit on reads.

  • ✗

    Enable default encryption on the S3 bucket using SSE-S3.

    Why it's wrong here

    Default encryption with SSE-S3 protects data at rest, not in transit. It does not enforce TLS for data moving between AWS Glue and S3, so it does not satisfy the requirement that data in transit be encrypted and that the job fail if TLS is not used.

  • ✗

    Configure the Glue job to use a VPC endpoint for Amazon S3 and set the endpoint policy to require TLS.

    Why it's wrong here

    A VPC endpoint for S3 can enforce TLS through an endpoint policy, but it only applies when the Glue job runs within a VPC and uses the endpoint. If the job does not use the endpoint or runs outside a VPC, TLS is not enforced. This is not a reliable way to guarantee TLS for all Glue-to-S3 traffic.

  • ✓

    Attach a bucket policy that denies s3:PutObject requests where aws:SecureTransport is false.

    Why this is correct

    A bucket policy with a Deny effect on s3:PutObject when aws:SecureTransport is false ensures that any upload not using TLS is rejected. This enforces encryption in transit for writes to the bucket, causing the Glue job to fail if it attempts an insecure connection, which meets the requirement to fail without TLS.

  • ✗

    Enable S3 Transfer Acceleration on the bucket.

    Why it's wrong here

    S3 Transfer Acceleration speeds up uploads and downloads by using AWS edge locations, but it does not enforce TLS. It can be used over HTTP or HTTPS, so it does not guarantee encryption in transit and does not cause the job to fail if TLS is not used.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.