DEA-C01 Data Security and Governance Practice Question
A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that data be encrypted at rest using a customer-managed AWS KMS key, and that the Glue job be able to decrypt the source data and encrypt the target data. The engineer has already created a KMS key and attached a key policy that allows the Glue service role to use the key for encrypt and decrypt operations. However, when the job runs, it fails with an access denied error related to KMS. What is the most likely cause of the failure?
⚠ Common exam trap
The trap here is assuming that a permissive KMS key policy is enough, overlooking that the IAM role also needs explicit permissions for KMS actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Glue job's IAM role lacks permissions for kms:Decrypt and kms:GenerateDataKey.
For a Glue job to use a customer-managed KMS key, both the key policy and the IAM role's identity-based policy must grant the necessary permissions. The key policy alone is insufficient; the IAM role must explicitly allow kms:Decrypt and kms:GenerateDataKey. This dual authorization ensures least privilege. The error indicates the IAM role lacks these permissions, so adding them resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The KMS key is in a different AWS Region than the S3 buckets, causing cross-Region latency and timeouts.
Why it's wrong here
KMS keys are regional, but S3 buckets and Glue jobs must be in the same Region to use a KMS key. Cross-Region access would cause a different error, such as key not found or invalid ARN. Latency alone would not produce an access denied error; the issue is permissions, not Region mismatch.
- ✗
The Glue job is using an outdated version of the AWS SDK that does not support KMS encryption.
Why it's wrong here
AWS Glue automatically uses current SDKs and supports KMS encryption. An outdated SDK would not cause a permission error; it would likely result in a feature not supported error. The access denied error points to missing IAM permissions for KMS actions, not SDK version.
- ✓
The Glue job's IAM role lacks permissions for kms:Decrypt and kms:GenerateDataKey.
Why this is correct
The Glue job assumes an IAM role to access AWS services. Even if the KMS key policy grants access, the IAM role must also have explicit permissions for kms:Decrypt and kms:GenerateDataKey to use the key for reading and writing encrypted data. Without these IAM permissions, the job cannot decrypt source objects or generate data keys for encryption, resulting in access denied.
- ✗
The S3 bucket policy does not allow the Glue job's IAM role to perform s3:GetObject and s3:PutObject.
Why it's wrong here
While S3 bucket policies control access to objects, the error specifically mentions KMS access denied. If S3 permissions were missing, the error would typically reference S3 actions. Since the key policy already allows the Glue role, the missing piece is likely IAM permissions for KMS operations, not S3.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.