DEA-C01 Data Security and Governance Practice Question
A data engineer must ensure that an AWS Glue ETL job can read from an Amazon S3 bucket encrypted with SSE-KMS and write to another S3 bucket also encrypted with SSE-KMS, using a single KMS key. The engineer has created an IAM role for the Glue job with permissions to access both buckets. What additional step is required to allow the Glue job to decrypt and encrypt data using the KMS key?
⚠ Common exam trap
The trap here is assuming that IAM permissions alone are sufficient to use a KMS key, when the KMS key policy must also grant access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a KMS key policy to the customer managed key that allows the Glue job's IAM role to use the key for encrypt and decrypt operations.
For a Glue job to use a KMS key for SSE-KMS encryption, both the IAM role's identity-based policy and the KMS key policy must grant the necessary permissions. The key policy is the resource-based policy that controls access to the KMS key. Without an explicit allow in the key policy for the Glue job's IAM role to perform kms:Decrypt and kms:Encrypt, the job cannot use the key, even if the IAM policy allows it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach a KMS key policy to the customer managed key that allows the Glue job's IAM role to use the key for encrypt and decrypt operations.
Why this is correct
KMS key policies are the primary way to control access to customer managed keys. Even if the IAM role has permissions in its identity-based policy, the key policy must also grant access. For a Glue job to use a KMS key, the key policy must explicitly allow the IAM role to perform kms:Decrypt and kms:Encrypt. Without this, the job will fail with access denied.
- ✗
Grant the Glue job's IAM role the kms:CreateGrant permission in its identity-based policy.
Why it's wrong here
kms:CreateGrant allows an entity to create grants for a KMS key, but it does not by itself grant permission to use the key for encrypt/decrypt. The key policy must still allow the role to use the key. Moreover, CreateGrant is not required for basic encrypt/decrypt operations. The missing piece is the key policy allowing the role to use the key.
- ✗
Enable default encryption on both S3 buckets using SSE-S3 instead of SSE-KMS.
Why it's wrong here
Switching to SSE-S3 would remove the need for KMS permissions, but the requirement explicitly states the buckets are encrypted with SSE-KMS. Changing encryption type is not a valid solution and would violate the security requirement. The question asks for an additional step to allow the Glue job to use the KMS key, not to change encryption.
- ✗
Modify the S3 bucket policy to allow the Glue job's IAM role to perform kms:Decrypt on the bucket.
Why it's wrong here
S3 bucket policies control access to S3 resources, not KMS keys. KMS permissions are managed through KMS key policies and IAM policies. A bucket policy cannot grant kms:Decrypt; that action is evaluated by KMS. Thus, adding kms:Decrypt to an S3 bucket policy has no effect on the Glue job's ability to use the KMS key.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.