DEA-C01 Data Store Management Practice Question
A data engineer manages an Amazon S3 data lake that holds sensitive customer transaction logs. Compliance requires that all objects be encrypted at rest with keys that the company rotates every 90 days and fully controls, including the ability to immediately revoke access and audit key usage separately from other AWS accounts. The engineer must choose an encryption method that meets these requirements with minimal operational overhead. Which solution should the engineer implement?
⚠ Common exam trap
The trap here is assuming that any server-side encryption option provides the same level of key control and auditability, when only SSE-KMS with customer managed keys meets the specific rotation and revocation requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use server-side encryption with AWS KMS customer managed keys (SSE-KMS)
The requirement for customer-controlled keys, custom 90-day rotation, immediate revocation, and separate key usage audit points directly to AWS KMS customer managed keys with SSE-KMS. S3 manages the encryption process, so operational overhead remains low, while the key policy and CloudTrail integration provide the necessary control and visibility. Other encryption options either lack customer control or shift too much operational responsibility to the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use server-side encryption with Amazon S3 managed keys (SSE-S3)
Why it's wrong here
SSE-S3 uses AES-256 encryption managed entirely by Amazon S3, but the customer does not control the keys, cannot set a custom 90-day rotation schedule, and cannot revoke access independently. It also does not provide a separate key usage audit trail distinct from other accounts. This fails the control and audit requirements of the scenario.
- ✗
Use client-side encryption with a customer-provided key stored in AWS Secrets Manager
Why it's wrong here
Client-side encryption shifts the responsibility of encrypting and managing keys to the application, increasing operational overhead. While it provides control, it does not integrate natively with S3 for automatic key rotation or provide a centralized audit trail of key usage. It is not the minimal-overhead solution for encrypting all objects in the data lake.
- ✓
Use server-side encryption with AWS KMS customer managed keys (SSE-KMS)
Why this is correct
SSE-KMS with customer managed keys gives the organization full control over the key, allows a custom rotation period (including 90 days), supports immediate revocation via key policy changes, and logs every key use in AWS CloudTrail. This directly satisfies the compliance requirements with minimal operational overhead because S3 handles encryption transparently.
- ✗
Use server-side encryption with customer-provided keys (SSE-C)
Why it's wrong here
SSE-C requires the customer to supply the encryption key with every request, and AWS does not store the key. This means no automatic rotation, no separate key usage audit, and higher operational burden because the application must manage key delivery. It does not meet the requirement for minimal overhead and centralized control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.