Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring AWS Glue to crawl a dataset stored in Amazon S3 and populate the AWS Glue Data Catalog. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has already configured the Glue crawler to use a connection with the appropriate VPC settings. What additional step must the engineer take to enforce encryption in transit?

⚠ Common exam trap

Many exam-takers confuse encryption at rest (SSE-KMS) with encryption in transit (TLS), and assuming that enabling SSE-KMS or a Glue security configuration will enforce TLS for S3 requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.

To enforce encryption in transit between AWS Glue and Amazon S3, the engineer must attach a bucket policy that denies requests when aws:SecureTransport is false. This ensures all requests, including those from Glue, use TLS. AWS Glue already uses HTTPS by default, but the bucket policy provides a hard enforcement. Glue security configurations and connection options do not control TLS for S3, and SSE-KMS is for encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.

    Why this is correct

    To enforce encryption in transit, the S3 bucket policy must include a condition that denies requests when aws:SecureTransport is false. This ensures that any request to the bucket, including from AWS Glue, must use TLS. AWS Glue uses HTTPS by default when accessing S3, so the policy will not block legitimate traffic but will reject unencrypted requests, satisfying the security requirement.

  • ✗

    Configure the Glue crawler to use an S3 endpoint with SSL enabled in the connection options.

    Why it's wrong here

    AWS Glue does not provide an option to configure SSL for S3 endpoints in connection options. Glue automatically uses HTTPS for S3 access. There is no setting to enable or disable SSL for S3 in Glue connections. The correct approach is to enforce TLS at the S3 bucket level using a bucket policy, not in Glue connection settings.

  • ✗

    Set the Glue crawler's security configuration to require SSL for S3 connections.

    Why it's wrong here

    AWS Glue security configurations are used to specify encryption settings for CloudWatch Logs, job bookmarks, and S3 targets, but they do not enforce TLS for data in transit between Glue and S3. Glue automatically uses TLS when connecting to S3 endpoints. A security configuration cannot be used to require SSL for S3 connections; that is not a supported feature.

  • ✗

    Enable server-side encryption with AWS KMS (SSE-KMS) on the S3 bucket, which automatically enforces TLS for all requests.

    Why it's wrong here

    Enabling SSE-KMS encrypts data at rest, not in transit. It does not enforce TLS for requests to the bucket. Encryption in transit and at rest are separate concerns. While SSE-KMS is important for data at rest, it does not satisfy the requirement to enforce TLS for data in transit between Glue and S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.