Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is designing a data pipeline that processes PII data using AWS Glue and stores results in S3. Which TWO actions should be taken to protect the data? (Choose 2)

⚠ Common exam trap

DEA-C01 often tests the distinction between encryption at rest with AWS-managed keys (SSE-S3) versus customer-managed KMS keys (SSE-KMS), and candidates frequently pick SSE-S3 as 'good enough' for PII, missing that compliance and key control requirements demand KMS; similarly, they may choose HTTPS (already default) as a security measure, overlooking that it only covers transit, not at-rest protection or credential management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Store database credentials in AWS Secrets Manager and reference them in Glue connections.

Option B is correct because storing database credentials in AWS Secrets Manager and referencing them from Glue connections avoids hardcoding secrets in scripts or job parameters, enabling secure, auditable, and rotatable credential management for PII pipelines. Option D is correct because configuring AWS Glue to use a customer-managed KMS key for encrypting data written to S3 provides encryption at rest with control over key policies, rotation, and access auditing, which is appropriate for sensitive PII. Option A is not the best choice because SSE-S3 uses AWS-managed keys with less control and auditability than a KMS key, and the question asks for protective actions beyond default encryption. Option C is incorrect because S3 object deletion protection via retention policies (Object Lock) addresses immutability/deletion, not the confidentiality of PII data being processed. Option E is not selected because HTTPS protects data in transit, but Glue-to-S3 traffic within AWS is already encrypted in transit by default, so it is not one of the two required protective actions for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use S3 default encryption with SSE-S3 for the output bucket.

    Why it's wrong here

    SSE-S3 does not use KMS, but the question is about protecting PII; SSE-S3 is acceptable but not the best with KMS. However, this is a distractor.

  • ✓

    Store database credentials in AWS Secrets Manager and reference them in Glue connections.

    Why this is correct

    AWS Secrets Manager stores the database credentials encrypted and rotates them, and Glue connections reference the secret rather than embedding plaintext passwords in job scripts or catalog properties. This removes hard-coded credentials from the PII pipeline, satisfying the protection requirement.

  • ✗

    Enable S3 object deletion protection by setting a retention policy.

    Why it's wrong here

    Retention policy is for compliance, not encryption.

  • ✓

    Configure AWS Glue to use a KMS key for encrypting data written to S3.

    Why this is correct

    Configuring a KMS key for Glue's S3 writes enforces server-side encryption with a customer-managed key on all output objects, so PII results are encrypted at rest under keys the organisation controls and can audit via CloudTrail.

  • ✗

    Use HTTPS for all data transfer between Glue and S3.

    Why it's wrong here

    HTTPS is already used, but doesn't address at-rest encryption.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.