DEA-C01 Data Security and Governance Practice Question
A data engineer is configuring an AWS Glue job that reads from an Amazon RDS for MySQL database and writes to Amazon S3. The security team requires that the data be encrypted in transit between AWS Glue and Amazon RDS. Which action should the engineer take to meet this requirement?
⚠ Common exam trap
Test-takers frequently confuse encryption at rest with encryption in transit, or assuming that IAM policies can enforce SSL for database connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the AWS Glue connection to use SSL by setting the JDBC URL with the sslMode=REQUIRED parameter and providing the RDS root certificate.
To encrypt data in transit between AWS Glue and Amazon RDS for MySQL, the JDBC connection must be configured to use SSL. Setting sslMode=REQUIRED in the JDBC URL and providing the RDS root certificate ensures that the connection is encrypted and the server certificate is validated. This is the correct approach for meeting the encryption in transit requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an IAM policy to the Glue job role that allows rds:DescribeDBInstances and rds:Connect, which enforces SSL.
Why it's wrong here
IAM policies control API permissions but do not enforce SSL/TLS for database connections. While rds:Connect might be required for IAM database authentication, it does not enable encryption in transit. SSL must be configured on the connection itself, not through IAM policies.
- ✓
Configure the AWS Glue connection to use SSL by setting the JDBC URL with the sslMode=REQUIRED parameter and providing the RDS root certificate.
Why this is correct
For JDBC connections to RDS for MySQL, encryption in transit is enabled by setting sslMode=REQUIRED in the JDBC URL and providing the RDS CA certificate for validation. This ensures that the connection between AWS Glue and RDS is encrypted using SSL/TLS. This is the standard method to enforce encryption in transit for Glue JDBC connections.
- ✗
Use AWS Glue's built-in encryption context to encrypt the data before writing to RDS.
Why it's wrong here
AWS Glue does not have a built-in encryption context that automatically encrypts data in transit to RDS. Encryption in transit must be configured at the connection level, typically via JDBC parameters. Glue's security configurations apply to data at rest in S3 and CloudWatch Logs, not to JDBC connections.
- ✗
Enable encryption at rest on the RDS instance, which automatically encrypts data in transit as well.
Why it's wrong here
Encryption at rest and encryption in transit are separate. Enabling encryption at rest on RDS encrypts the underlying storage but does not encrypt network traffic between the client and the database. The requirement is specifically for data in transit, so this action does not meet it.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.