Question 308 of 1,711
DEA-C01 DynamoDB Encryption at Rest Practice Question
A data engineer is using Amazon DynamoDB to store session data for a web application. The engineer wants to ensure that all data is encrypted at rest using an AWS managed key. Which step should the engineer take to achieve this?
⚠ Common exam trap
Candidates often confuse the encryption options across AWS services (e.g., applying S3-specific SSE-S3 to DynamoDB) or mistakenly think that specifying a customer managed key is equivalent to using an AWS managed key. The key distinction is that 'AWS managed key' means the key is owned and managed by AWS (e.g., aws/dynamodb), not a customer-managed KMS key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the DynamoDB table with encryption at rest enabled using an AWS managed key. [CORRECT]
Only option E is correct. DynamoDB encryption at rest is enabled by default for new tables using an AWS managed key (aws/dynamodb). Creating the table with encryption at rest enabled using an AWS managed key ensures all data is encrypted with a key managed by AWS. Option C is incorrect because specifying a customer managed key would override the default AWS managed key, which does not meet the requirement to use an AWS managed key. Options A, B, and D are incorrect: SSE-S3 is for S3, disabling encryption is unsafe and does not meet the requirement, and client-side encryption is separate from at-rest encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable server-side encryption with S3-managed keys (SSE-S3) on the DynamoDB table. [wrong]
Why it's wrong here
Incorrect. Server-side encryption with S3-managed keys (SSE-S3) is for Amazon S3, not DynamoDB. DynamoDB encryption at rest uses AWS KMS.
- ✗
Disable encryption at rest to improve performance. [wrong]
Why it's wrong here
Incorrect. Disabling encryption at rest would leave data unencrypted, which does not meet the security requirement.
- ✗
Specify an AWS KMS customer managed key for encryption if required. [wrong]
Why it's wrong here
Incorrect. Specifying a customer managed key would use a key managed by the customer, not an AWS managed key. The requirement is to use an AWS managed key, so this option does not satisfy it.
- ✗
Use client-side encryption before writing data to DynamoDB. [wrong]
Why it's wrong here
Incorrect. Client-side encryption encrypts data before sending to DynamoDB, but it does not address encryption at rest; it is an additional layer, not the required step.
- ✓
Create the DynamoDB table with encryption at rest enabled using an AWS managed key. [CORRECT]
Why this is correct
Correct. Creating the DynamoDB table with encryption at rest enabled using an AWS managed key (the default) ensures all data is encrypted with a key owned and managed by AWS.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 24, 2026
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.