DEA-C01 Data Security and Governance Practice Question
A data engineer is designing a data pipeline that processes PII data using AWS Glue and stores results in S3. Which TWO actions should be taken to protect the data? (Choose 2)
⚠ Common exam trap
DEA-C01 often tests the distinction between encryption at rest with AWS-managed keys (SSE-S3) versus customer-managed KMS keys (SSE-KMS), and candidates frequently pick SSE-S3 as 'good enough' for PII, missing that compliance and key control requirements demand KMS; similarly, they may choose HTTPS (already default) as a security measure, overlooking that it only covers transit, not at-rest protection or credential management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store database credentials in AWS Secrets Manager and reference them in Glue connections.
Option B is correct because storing database credentials in AWS Secrets Manager and referencing them from Glue connections avoids hardcoding secrets in scripts or job parameters, enabling secure, auditable, and rotatable credential management for PII pipelines. Option D is correct because configuring AWS Glue to use a customer-managed KMS key for encrypting data written to S3 provides encryption at rest with control over key policies, rotation, and access auditing, which is appropriate for sensitive PII. Option A is not the best choice because SSE-S3 uses AWS-managed keys with less control and auditability than a KMS key, and the question asks for protective actions beyond default encryption. Option C is incorrect because S3 object deletion protection via retention policies (Object Lock) addresses immutability/deletion, not the confidentiality of PII data being processed. Option E is not selected because HTTPS protects data in transit, but Glue-to-S3 traffic within AWS is already encrypted in transit by default, so it is not one of the two required protective actions for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use S3 default encryption with SSE-S3 for the output bucket.
Why it's wrong here
SSE-S3 does not use KMS, but the question is about protecting PII; SSE-S3 is acceptable but not the best with KMS. However, this is a distractor.
- ✓
Store database credentials in AWS Secrets Manager and reference them in Glue connections.
Why this is correct
AWS Secrets Manager stores the database credentials encrypted and rotates them, and Glue connections reference the secret rather than embedding plaintext passwords in job scripts or catalog properties. This removes hard-coded credentials from the PII pipeline, satisfying the protection requirement.
- ✗
Enable S3 object deletion protection by setting a retention policy.
Why it's wrong here
Retention policy is for compliance, not encryption.
- ✓
Configure AWS Glue to use a KMS key for encrypting data written to S3.
Why this is correct
Configuring a KMS key for Glue's S3 writes enforces server-side encryption with a customer-managed key on all output objects, so PII results are encrypted at rest under keys the organisation controls and can audit via CloudTrail.
- ✗
Use HTTPS for all data transfer between Glue and S3.
Why it's wrong here
HTTPS is already used, but doesn't address at-rest encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.