DEA-C01 Data Security and Governance Practice Question
A data engineer is responsible for an Amazon Redshift cluster that stores financial data. The security team requires that all connections to the cluster from outside the VPC use SSL, and that the cluster's audit logs capture connection and user activity. The engineer has already enabled audit logging to Amazon S3. Which additional configuration should the engineer apply to meet the SSL requirement?
⚠ Common exam trap
Many exam-takers confuse IAM policies and VPC endpoints with database-level SSL enforcement, when Redshift uses a cluster parameter for this purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Redshift cluster parameter 'require_ssl' to true in the parameter group associated with the cluster.
The require_ssl parameter in the Redshift parameter group is the correct way to enforce SSL for all connections to the cluster. When set to true, any client that attempts to connect without SSL is rejected. This directly meets the security team's requirement for encrypted connections from outside the VPC and works alongside audit logging, which the engineer has already enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the Redshift cluster parameter 'require_ssl' to true in the parameter group associated with the cluster.
Why this is correct
The require_ssl parameter in a Redshift parameter group enforces SSL for all connections to the cluster. When set to true, clients that do not use SSL are rejected. This is the standard cluster-level setting for meeting encryption-in-transit requirements, and it applies to connections from outside the VPC as well as inside, ensuring consistent enforcement.
- ✗
Attach an IAM policy to the Redshift cluster that denies connections without the 'aws:SecureTransport' condition.
Why it's wrong here
IAM policies apply to AWS API actions, not to database connections made over PostgreSQL or JDBC protocols. The aws:SecureTransport condition is used for AWS service API calls such as S3 or KMS, not for Redshift database sessions. This option would not enforce SSL for client connections to the cluster and therefore fails the requirement.
- ✗
Create a VPC endpoint for Redshift and require that all clients use the endpoint's private IP address.
Why it's wrong here
A VPC endpoint provides private connectivity to Redshift but does not enforce SSL encryption. Clients could still connect without SSL over the private network. The requirement is specifically to use SSL, so a VPC endpoint alone does not satisfy it; the require_ssl parameter is needed to enforce encryption in transit.
- ✗
Enable Redshift Spectrum and configure it to use SSL for all external table access.
Why it's wrong here
Redshift Spectrum is a feature for querying data in Amazon S3, not for securing client connections to the Redshift cluster. It does not control how clients connect to the database. Enabling Spectrum would not enforce SSL for JDBC or ODBC connections, so it does not address the security team's requirement for encrypted client connections.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.