Courseiva
Question 308 of 1,711
Data Store ManagementmediumMultiple SelectObjective-mapped

DEA-C01 DynamoDB Encryption at Rest Practice Question

A data engineer is using Amazon DynamoDB to store session data for a web application. The engineer wants to ensure that all data is encrypted at rest using an AWS managed key. Which step should the engineer take to achieve this?

⚠ Common exam trap

Candidates often confuse the encryption options across AWS services (e.g., applying S3-specific SSE-S3 to DynamoDB) or mistakenly think that specifying a customer managed key is equivalent to using an AWS managed key. The key distinction is that 'AWS managed key' means the key is owned and managed by AWS (e.g., aws/dynamodb), not a customer-managed KMS key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create the DynamoDB table with encryption at rest enabled using an AWS managed key. [CORRECT]

Only option E is correct. DynamoDB encryption at rest is enabled by default for new tables using an AWS managed key (aws/dynamodb). Creating the table with encryption at rest enabled using an AWS managed key ensures all data is encrypted with a key managed by AWS. Option C is incorrect because specifying a customer managed key would override the default AWS managed key, which does not meet the requirement to use an AWS managed key. Options A, B, and D are incorrect: SSE-S3 is for S3, disabling encryption is unsafe and does not meet the requirement, and client-side encryption is separate from at-rest encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable server-side encryption with S3-managed keys (SSE-S3) on the DynamoDB table. [wrong]

    Why it's wrong here

    Incorrect. Server-side encryption with S3-managed keys (SSE-S3) is for Amazon S3, not DynamoDB. DynamoDB encryption at rest uses AWS KMS.

  • Disable encryption at rest to improve performance. [wrong]

    Why it's wrong here

    Incorrect. Disabling encryption at rest would leave data unencrypted, which does not meet the security requirement.

  • Specify an AWS KMS customer managed key for encryption if required. [wrong]

    Why it's wrong here

    Incorrect. Specifying a customer managed key would use a key managed by the customer, not an AWS managed key. The requirement is to use an AWS managed key, so this option does not satisfy it.

  • Use client-side encryption before writing data to DynamoDB. [wrong]

    Why it's wrong here

    Incorrect. Client-side encryption encrypts data before sending to DynamoDB, but it does not address encryption at rest; it is an additional layer, not the required step.

  • Create the DynamoDB table with encryption at rest enabled using an AWS managed key. [CORRECT]

    Why this is correct

    Correct. Creating the DynamoDB table with encryption at rest enabled using an AWS managed key (the default) ensures all data is encrypted with a key owned and managed by AWS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 24, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.