Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring an AWS Glue job that reads from an Amazon RDS for MySQL database and writes to Amazon S3. The security team requires that the data be encrypted in transit between AWS Glue and Amazon RDS. Which action should the engineer take to meet this requirement?

⚠ Common exam trap

Test-takers frequently confuse encryption at rest with encryption in transit, or assuming that IAM policies can enforce SSL for database connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the AWS Glue connection to use SSL by setting the JDBC URL with the sslMode=REQUIRED parameter and providing the RDS root certificate.

To encrypt data in transit between AWS Glue and Amazon RDS for MySQL, the JDBC connection must be configured to use SSL. Setting sslMode=REQUIRED in the JDBC URL and providing the RDS root certificate ensures that the connection is encrypted and the server certificate is validated. This is the correct approach for meeting the encryption in transit requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM policy to the Glue job role that allows rds:DescribeDBInstances and rds:Connect, which enforces SSL.

    Why it's wrong here

    IAM policies control API permissions but do not enforce SSL/TLS for database connections. While rds:Connect might be required for IAM database authentication, it does not enable encryption in transit. SSL must be configured on the connection itself, not through IAM policies.

  • ✓

    Configure the AWS Glue connection to use SSL by setting the JDBC URL with the sslMode=REQUIRED parameter and providing the RDS root certificate.

    Why this is correct

    For JDBC connections to RDS for MySQL, encryption in transit is enabled by setting sslMode=REQUIRED in the JDBC URL and providing the RDS CA certificate for validation. This ensures that the connection between AWS Glue and RDS is encrypted using SSL/TLS. This is the standard method to enforce encryption in transit for Glue JDBC connections.

  • ✗

    Use AWS Glue's built-in encryption context to encrypt the data before writing to RDS.

    Why it's wrong here

    AWS Glue does not have a built-in encryption context that automatically encrypts data in transit to RDS. Encryption in transit must be configured at the connection level, typically via JDBC parameters. Glue's security configurations apply to data at rest in S3 and CloudWatch Logs, not to JDBC connections.

  • ✗

    Enable encryption at rest on the RDS instance, which automatically encrypts data in transit as well.

    Why it's wrong here

    Encryption at rest and encryption in transit are separate. Enabling encryption at rest on RDS encrypts the underlying storage but does not encrypt network traffic between the client and the database. The requirement is specifically for data in transit, so this action does not meet it.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.