Courseiva
Data Store Management →mediumMultiple Choice

DEA-C01 Data Store Management Practice Question

A data engineer manages an Amazon S3 data lake that holds sensitive customer transaction logs. Compliance requires that all objects be encrypted at rest with keys that the company rotates every 90 days and fully controls, including the ability to immediately revoke access and audit key usage separately from other AWS accounts. The engineer must choose an encryption method that meets these requirements with minimal operational overhead. Which solution should the engineer implement?

⚠ Common exam trap

The trap here is assuming that any server-side encryption option provides the same level of key control and auditability, when only SSE-KMS with customer managed keys meets the specific rotation and revocation requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use server-side encryption with AWS KMS customer managed keys (SSE-KMS)

The requirement for customer-controlled keys, custom 90-day rotation, immediate revocation, and separate key usage audit points directly to AWS KMS customer managed keys with SSE-KMS. S3 manages the encryption process, so operational overhead remains low, while the key policy and CloudTrail integration provide the necessary control and visibility. Other encryption options either lack customer control or shift too much operational responsibility to the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use server-side encryption with Amazon S3 managed keys (SSE-S3)

    Why it's wrong here

    SSE-S3 uses AES-256 encryption managed entirely by Amazon S3, but the customer does not control the keys, cannot set a custom 90-day rotation schedule, and cannot revoke access independently. It also does not provide a separate key usage audit trail distinct from other accounts. This fails the control and audit requirements of the scenario.

  • ✗

    Use client-side encryption with a customer-provided key stored in AWS Secrets Manager

    Why it's wrong here

    Client-side encryption shifts the responsibility of encrypting and managing keys to the application, increasing operational overhead. While it provides control, it does not integrate natively with S3 for automatic key rotation or provide a centralized audit trail of key usage. It is not the minimal-overhead solution for encrypting all objects in the data lake.

  • ✓

    Use server-side encryption with AWS KMS customer managed keys (SSE-KMS)

    Why this is correct

    SSE-KMS with customer managed keys gives the organization full control over the key, allows a custom rotation period (including 90 days), supports immediate revocation via key policy changes, and logs every key use in AWS CloudTrail. This directly satisfies the compliance requirements with minimal operational overhead because S3 handles encryption transparently.

  • ✗

    Use server-side encryption with customer-provided keys (SSE-C)

    Why it's wrong here

    SSE-C requires the customer to supply the encryption key with every request, and AWS does not store the key. This means no automatic rotation, no separate key usage audit, and higher operational burden because the application must manage key delivery. It does not meet the requirement for minimal overhead and centralized control.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.