Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is designing a data lake on Amazon S3 that will store sensitive financial data. The security team requires that access to the data be audited, that data be encrypted at rest with customer-managed keys, and that the engineer be able to identify which IAM principals accessed specific objects. Which TWO AWS services or features should the engineer use to meet these requirements? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse server access logging with CloudTrail data events; while both log access, CloudTrail data events are integrated with IAM and CloudTrail Lake for easier analysis of principal activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS CloudTrail data events for S3

CloudTrail data events provide the necessary audit trail for object-level access, identifying IAM principals. SSE-KMS with customer managed keys satisfies the encryption at rest requirement with customer-managed keys. Together, they meet the auditing and encryption needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS CloudTrail data events for S3

    Why this is correct

    AWS CloudTrail data events capture object-level API activity, such as GetObject and PutObject, including the identity of the caller and the object accessed. This provides the audit trail required to identify which IAM principals accessed specific objects. Management events alone do not log object-level access, so data events are necessary for this granular auditing.

  • ✗

    Amazon S3 server access logging

    Why it's wrong here

    Server access logging provides detailed records for requests made to an S3 bucket, including the requester and object. However, it does not integrate with CloudTrail and may not capture all API calls, especially those from other AWS services. It can be used for auditing, but CloudTrail data events are more comprehensive and easier to query for IAM principal activity.

  • ✗

    Amazon Macie for sensitive data discovery

    Why it's wrong here

    Amazon Macie uses machine learning to discover and protect sensitive data in S3, such as PII. While it can help identify sensitive data, it does not provide object-level access auditing or encryption key management. It is complementary but does not meet the specific requirements for auditing access and customer-managed encryption.

  • ✓

    AWS KMS customer managed keys with SSE-KMS

    Why this is correct

    To encrypt data at rest with customer-managed keys, the engineer should use SSE-KMS with AWS KMS customer managed keys. This allows control over key policies and rotation, and meets the requirement for customer-managed encryption. KMS also integrates with CloudTrail to log key usage, providing additional audit capability.

  • ✗

    AWS Secrets Manager for storing encryption keys

    Why it's wrong here

    AWS Secrets Manager is designed for storing and rotating secrets such as database credentials and API keys, not for managing encryption keys for S3. KMS is the appropriate service for creating and managing encryption keys. Using Secrets Manager would not provide the required encryption at rest for S3 objects.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.