Courseiva
Data Operations and Support →mediumMultiple Choice

S3 Encryption at Rest and Access Auditing

A data engineer is designing a data pipeline that processes sensitive personal data. The data is ingested via Amazon Kinesis Data Firehose and stored in Amazon S3. The pipeline must ensure that the data is encrypted at rest and in transit. The engineer also needs to audit access to the data. Which combination of services meets these requirements?

Quick Answer

The correct answer is S3 server-side encryption (SSE-S3) for at-rest encryption, HTTPS for in-transit encryption, and AWS CloudTrail for auditing. This combination works because SSE-S3 encrypts data at the object level as it is written to Amazon S3, HTTPS secures the data during ingestion from Kinesis Data Firehose, and CloudTrail records all S3 API calls—such as GetObject and PutObject—to provide a detailed audit trail of who accessed the data and when. On the AWS Certified Data Engineer Associate DEA-C01 exam, this question tests your ability to distinguish between services that handle data protection versus configuration or monitoring: a common trap is confusing CloudWatch Logs (which monitors performance metrics) or AWS Config (which tracks resource compliance) with CloudTrail’s specific role in auditing data access. For a quick memory tip, think “SSE + HTTPS + Trails” to recall the three pillars of encryption and auditing for sensitive data in S3.

⚠ Common exam trap

DEA-C01 often tests the confusion between services that provide auditing (CloudTrail) versus monitoring (CloudWatch) or compliance (Config), and between encryption mechanisms for data at rest (SSE-S3, SSE-KMS) versus in transit (TLS/HTTPS).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 server-side encryption (SSE-S3) for at-rest encryption, HTTPS for in-transit encryption, and AWS CloudTrail for auditing.

Option C correctly combines S3 server-side encryption (SSE-S3) for data at rest, HTTPS (TLS) for data in transit, and AWS CloudTrail for auditing access. SSE-S3 provides AES-256 encryption managed by S3, HTTPS ensures secure ingestion and retrieval, and CloudTrail logs all API calls to S3, enabling audit trails. This meets all three requirements: encryption at rest, encryption in transit, and auditability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS KMS for encryption at rest, Kinesis Data Analytics for in-transit encryption, and AWS CloudTrail for auditing.

    Why it's wrong here

    Kinesis Data Analytics performs stream processing, not in-transit encryption; TLS secures Firehose delivery instead. KMS and CloudTrail correctly cover encryption at rest and access auditing, so the failure is isolated to the in-transit component. Data Analytics suits real-time SQL analytics on streaming data, a different purpose entirely.

  • ✗

    AWS KMS for encryption at rest, Amazon CloudWatch Logs for auditing, and TLS for in-transit encryption.

    Why it's wrong here

    CloudWatch Logs captures application and service log output, not S3 object-level access events, so the audit requirement goes unmet. KMS and TLS correctly satisfy encryption at rest and in transit; CloudWatch suits operational monitoring and alerting, whereas CloudTrail data events record who accessed the objects.

  • ✓

    S3 server-side encryption (SSE-S3) for at-rest encryption, HTTPS for in-transit encryption, and AWS CloudTrail for auditing.

    Why this is correct

    SSE-S3 encrypts objects at rest, HTTPS secures data in transit from Firehose to S3, and CloudTrail records API activity for auditing. Together these three satisfy the encryption and access-audit requirements for the sensitive personal data pipeline.

  • ✗

    S3 client-side encryption, AWS Config for auditing, and TLS for in-transit encryption.

    Why it's wrong here

    Client-side encryption places key management on the engineer and does not encrypt Firehose's in-transit delivery or S3 server-side storage by default, while AWS Config records resource configuration changes rather than data-access events. Client-side encryption suits scenarios demanding provider-independent keys, not this audit requirement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A data engineer needs to ensure that sensitive data stored in Amazon S3 is encrypted at rest. Which TWO options meet this requirement? (Choose TWO.)

medium
  • ✓ A.Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
  • ✓ B.Server-Side Encryption with S3-Managed Keys (SSE-S3)
  • C.Using a VPC to restrict network access
  • D.Enabling MFA Delete on the S3 bucket
  • E.Client-Side Encryption with SSL/TLS

Why A: Options A (SSE-KMS) and B (SSE-S3) are correct because both are server-side encryption mechanisms that encrypt S3 objects at rest: SSE-KMS uses AWS KMS customer master keys (CMKs) to generate and manage data keys, while SSE-S3 uses AES-256 keys fully managed by Amazon S3. Both satisfy the requirement that sensitive data stored in S3 be encrypted at rest, and each is applied per-object when the object is written to the bucket. Option C is incorrect because a VPC only controls network-level access to S3 (via endpoints and policies) and does not encrypt data at rest. Option D is incorrect because MFA Delete only adds an authentication requirement for deleting objects or changing versioning state; it provides no encryption. Option E is incorrect because SSL/TLS encrypts data in transit, not at rest, and client-side encryption is a separate approach not represented by that option.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.