DEA-C01 Data Security and Governance Practice Question
A data engineer is setting up an AWS Glue ETL job that reads data from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that all data in transit be encrypted using TLS. The engineer has configured the job to use the appropriate S3 endpoints. Which additional configuration is necessary to enforce TLS for data in transit between AWS Glue and Amazon S3?
⚠ Common exam trap
Test-takers frequently confuse encryption at rest with encryption in transit, or assuming that VPC endpoints automatically enforce TLS. The condition aws:SecureTransport is the key to enforcing TLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
To enforce TLS for data in transit to S3, you must use a bucket policy that denies requests when aws:SecureTransport is false. This ensures that all access, including from AWS Glue, uses HTTPS. Other options address encryption at rest or network routing, not TLS enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the AWS Glue job's security configuration to enable S3 encryption in transit.
Why it's wrong here
AWS Glue security configurations are used to specify encryption settings for data at rest and in transit for certain targets like S3, but they do not enforce TLS for S3 access. In fact, Glue security configurations primarily apply to CloudWatch Logs and job bookmarks. There is no setting to enforce TLS for S3 data transfer; that must be done via bucket policy.
- ✓
Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
Why this is correct
An S3 bucket policy with a condition that denies requests when aws:SecureTransport is false enforces that all requests to the bucket must use TLS. This applies to AWS Glue and any other client, ensuring data in transit is encrypted. This is a standard method to enforce TLS for S3 access.
- ✗
Enable default encryption on the S3 bucket using SSE-KMS.
Why it's wrong here
Default encryption on S3 encrypts data at rest, not in transit. SSE-KMS protects objects once they are stored, but it does not enforce TLS for data being transferred. The requirement is specifically for data in transit, so this measure does not address the need.
- ✗
Configure the AWS Glue job to use a VPC endpoint for S3 and enable private DNS.
Why it's wrong here
Using a VPC endpoint for S3 keeps traffic within the AWS network, but it does not enforce TLS encryption. While it can improve security by avoiding the public internet, it does not guarantee that TLS is used. The requirement explicitly asks for TLS encryption in transit, which is not ensured by a VPC endpoint alone.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.