DEA-C01 Data Security and Governance Practice Question
A data engineer is designing a data lake on Amazon S3 that will store sensitive financial data. The security team requires that access to the data be audited, that data be encrypted at rest with customer-managed keys, and that the engineer be able to identify which IAM principals accessed specific objects. Which TWO AWS services or features should the engineer use to meet these requirements? (Choose two.)
⚠ Common exam trap
Watch out — candidates often confuse server access logging with CloudTrail data events; while both log access, CloudTrail data events are integrated with IAM and CloudTrail Lake for easier analysis of principal activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudTrail data events for S3
CloudTrail data events provide the necessary audit trail for object-level access, identifying IAM principals. SSE-KMS with customer managed keys satisfies the encryption at rest requirement with customer-managed keys. Together, they meet the auditing and encryption needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudTrail data events for S3
Why this is correct
AWS CloudTrail data events capture object-level API activity, such as GetObject and PutObject, including the identity of the caller and the object accessed. This provides the audit trail required to identify which IAM principals accessed specific objects. Management events alone do not log object-level access, so data events are necessary for this granular auditing.
- ✗
Amazon S3 server access logging
Why it's wrong here
Server access logging provides detailed records for requests made to an S3 bucket, including the requester and object. However, it does not integrate with CloudTrail and may not capture all API calls, especially those from other AWS services. It can be used for auditing, but CloudTrail data events are more comprehensive and easier to query for IAM principal activity.
- ✗
Amazon Macie for sensitive data discovery
Why it's wrong here
Amazon Macie uses machine learning to discover and protect sensitive data in S3, such as PII. While it can help identify sensitive data, it does not provide object-level access auditing or encryption key management. It is complementary but does not meet the specific requirements for auditing access and customer-managed encryption.
- ✓
AWS KMS customer managed keys with SSE-KMS
Why this is correct
To encrypt data at rest with customer-managed keys, the engineer should use SSE-KMS with AWS KMS customer managed keys. This allows control over key policies and rotation, and meets the requirement for customer-managed encryption. KMS also integrates with CloudTrail to log key usage, providing additional audit capability.
- ✗
AWS Secrets Manager for storing encryption keys
Why it's wrong here
AWS Secrets Manager is designed for storing and rotating secrets such as database credentials and API keys, not for managing encryption keys for S3. KMS is the appropriate service for creating and managing encryption keys. Using Secrets Manager would not provide the required encryption at rest for S3 objects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.