DEA-C01 Data Security and Governance Practice Question
A data engineer must give an AWS Glue ETL job access to an S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs under an IAM role. The security team wants the least-privilege permissions required for the job to read and write objects in that bucket. Which TWO actions must be included in the IAM role's policy? (Choose two.)
⚠ Common exam trap
The trap here is forgetting that SSE-KMS adds KMS permissions on top of S3 permissions, so an S3-only policy will still fail with AccessDenied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kms:Decrypt on the customer managed key.
Reading SSE-KMS encrypted objects requires kms:Decrypt on the key, and writing them requires kms:GenerateDataKey so S3 can obtain a fresh data key per object. These two KMS actions, combined with the appropriate s3:GetObject and s3:PutObject permissions, give the Glue job the minimum cryptographic access it needs without granting administrative key management capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kms:ListKeys on the customer managed key.
Why it's wrong here
kms:ListKeys returns a list of key ARNs in the account and is a discovery action, not a cryptographic one. It does not allow decryption or data key generation, so it cannot help the Glue job read or write encrypted objects. The job already knows the key ARN from its configuration, making this action irrelevant and outside least privilege.
- ✓
kms:Decrypt on the customer managed key.
Why this is correct
When S3 objects are encrypted with SSE-KMS, reading an object requires the caller to have kms:Decrypt on the key that protects the object. The Glue job role must include this action or S3 returns AccessDenied during the read. Without it, the job cannot decrypt the data even if it has s3:GetObject.
- ✓
kms:GenerateDataKey on the customer managed key.
Why this is correct
Writing an SSE-KMS encrypted object requires the caller to obtain a data key from KMS, which is granted by kms:GenerateDataKey. This action lets S3 request a new data key for each object the Glue job writes. Omitting it causes write failures with AccessDenied even when s3:PutObject is allowed.
- ✗
kms:ScheduleKeyDeletion on the customer managed key.
Why it's wrong here
kms:ScheduleKeyDeletion allows a principal to schedule destruction of a KMS key. This is a highly privileged administrative action that has nothing to do with reading or writing S3 objects. Including it would violate least privilege and could allow the Glue job role to destroy the key protecting the data, which is the opposite of the security team's intent.
- ✗
kms:CreateGrant on the customer managed key.
Why it's wrong here
kms:CreateGrant is used when a service needs to create a grant on a key so it can use the key on behalf of the caller, such as for AWS services that manage encryption independently. S3 does not need the caller to create a grant for normal SSE-KMS reads and writes. Granting this action would exceed least privilege and is unnecessary for the Glue job's access.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.