DEA-C01 Data Security and Governance Practice Question
A data engineer is configuring AWS Glue to crawl a dataset stored in Amazon S3 and populate the AWS Glue Data Catalog. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has already configured the Glue crawler to use a connection with the appropriate VPC settings. What additional step must the engineer take to enforce encryption in transit?
⚠ Common exam trap
Many exam-takers confuse encryption at rest (SSE-KMS) with encryption in transit (TLS), and assuming that enabling SSE-KMS or a Glue security configuration will enforce TLS for S3 requests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
To enforce encryption in transit between AWS Glue and Amazon S3, the engineer must attach a bucket policy that denies requests when aws:SecureTransport is false. This ensures all requests, including those from Glue, use TLS. AWS Glue already uses HTTPS by default, but the bucket policy provides a hard enforcement. Glue security configurations and connection options do not control TLS for S3, and SSE-KMS is for encryption at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
Why this is correct
To enforce encryption in transit, the S3 bucket policy must include a condition that denies requests when aws:SecureTransport is false. This ensures that any request to the bucket, including from AWS Glue, must use TLS. AWS Glue uses HTTPS by default when accessing S3, so the policy will not block legitimate traffic but will reject unencrypted requests, satisfying the security requirement.
- ✗
Configure the Glue crawler to use an S3 endpoint with SSL enabled in the connection options.
Why it's wrong here
AWS Glue does not provide an option to configure SSL for S3 endpoints in connection options. Glue automatically uses HTTPS for S3 access. There is no setting to enable or disable SSL for S3 in Glue connections. The correct approach is to enforce TLS at the S3 bucket level using a bucket policy, not in Glue connection settings.
- ✗
Set the Glue crawler's security configuration to require SSL for S3 connections.
Why it's wrong here
AWS Glue security configurations are used to specify encryption settings for CloudWatch Logs, job bookmarks, and S3 targets, but they do not enforce TLS for data in transit between Glue and S3. Glue automatically uses TLS when connecting to S3 endpoints. A security configuration cannot be used to require SSL for S3 connections; that is not a supported feature.
- ✗
Enable server-side encryption with AWS KMS (SSE-KMS) on the S3 bucket, which automatically enforces TLS for all requests.
Why it's wrong here
Enabling SSE-KMS encrypts data at rest, not in transit. It does not enforce TLS for requests to the bucket. Encryption in transit and at rest are separate concerns. While SSE-KMS is important for data at rest, it does not satisfy the requirement to enforce TLS for data in transit between Glue and S3.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.