DEA-C01 Data Store Management Practice Question
A data engineer is using Amazon Redshift to store sales data. The engineer needs to ensure that the data is encrypted at rest and that encryption keys are managed by AWS. The engineer also wants to minimize administrative overhead. Which Redshift encryption option should the engineer use?
⚠ Common exam trap
The trap here is equating 'managed by AWS' with 'customer managed key', which actually requires more administrative effort.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS KMS AWS managed key (aws/redshift)
Amazon Redshift supports encryption at rest using AWS KMS. The AWS managed key (aws/redshift) is automatically created and managed by AWS, providing encryption without the need for manual key management. This minimizes administrative overhead while ensuring data is encrypted at rest. Customer managed keys offer more control but require more management, and HSM or client-side encryption add complexity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Key Management Service (AWS KMS) customer managed key
Why it's wrong here
Using a customer managed KMS key gives you control over key rotation and policies, but it requires more administrative effort to manage the key lifecycle and permissions. While it provides encryption at rest, it does not minimize administrative overhead as much as using an AWS managed key. The scenario asks for minimal overhead, so this is not the best fit.
- ✓
AWS KMS AWS managed key (aws/redshift)
Why this is correct
The AWS managed key for Redshift is automatically created and managed by AWS, providing encryption at rest with minimal administrative effort. You do not need to manage key rotation or policies; AWS handles these tasks. This meets the requirement for encryption at rest while minimizing overhead, making it the ideal choice for this scenario.
- ✗
Client-side encryption with a custom key
Why it's wrong here
Client-side encryption requires the application to encrypt data before loading into Redshift, adding complexity and administrative burden. Redshift does not natively support client-side encryption for data at rest; it would need to be implemented manually. This approach does not minimize overhead and is not a standard Redshift feature for encryption at rest.
- ✗
Hardware security module (HSM) encryption
Why it's wrong here
HSM encryption provides additional security by storing keys in a dedicated hardware appliance, but it requires significant administrative overhead to configure and maintain. It is typically used for strict compliance requirements and is not the simplest option. The scenario prioritizes minimal overhead, so HSM is not appropriate.
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.