DEA-C01 Data Security and Governance Practice Question
A data engineer is using AWS Glue to transform data stored in Amazon S3. The security team requires that data in transit between AWS Glue and Amazon S3 be encrypted. The engineer wants to ensure that all connections use TLS. Which action should the engineer take to enforce encryption in transit for AWS Glue jobs accessing S3?
⚠ Common exam trap
Many candidates confuse encryption at rest settings like SSE-S3 or VPC endpoints with encryption in transit, which requires TLS enforcement via bucket policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
Enforcing encryption in transit for S3 is done by adding a bucket policy that denies requests when aws:SecureTransport is false. This ensures that all clients, including AWS Glue, must use HTTPS/TLS when accessing the bucket. Other options either address encryption at rest or do not enforce TLS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSL/TLS for the Glue connection and set the require_ssl parameter to true in the JDBC URL.
Why it's wrong here
The require_ssl parameter is used for JDBC connections to databases, not for S3 access. AWS Glue connections to S3 are made via the S3 API, which uses HTTPS by default. This action would not affect S3 data transfers and is irrelevant to the requirement.
- ✓
Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
Why this is correct
To enforce encryption in transit for S3, a bucket policy can deny any requests that do not use TLS, by checking the aws:SecureTransport condition key. This ensures that all access, including from AWS Glue, must use HTTPS. This is the standard method to require encryption in transit for S3.
- ✗
Configure the Glue job to use a VPC endpoint for S3 and enable encryption on the endpoint.
Why it's wrong here
A VPC endpoint for S3 can be used for private connectivity, but it does not enforce encryption in transit; it only keeps traffic within the AWS network. Encryption in transit still relies on TLS. VPC endpoints do not have an encryption setting to enable; they support HTTPS and HTTP, but the bucket policy is needed to enforce HTTPS.
- ✗
Set the Glue job parameter --encryption-mode to SSE-S3.
Why it's wrong here
The --encryption-mode parameter is used to specify server-side encryption for data written by Glue to S3, not for encryption in transit. SSE-S3 encrypts data at rest, not in transit. This would not meet the requirement for encryption in transit.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.