Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to enforce that all data in an Amazon S3 bucket is encrypted at rest. Which of the following can be used to achieve this? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a bucket policy to deny PutObject if encryption headers are missing

Option C is correct because an S3 bucket policy can include a Deny statement on s3:PutObject that uses a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its aws:kms variant), which blocks any upload request that does not carry the required encryption header, thereby enforcing encryption at rest for newly written objects. Option D is correct because enabling default bucket encryption with SSE-S3 (AES-256) causes Amazon S3 to automatically encrypt every object at rest on write, even when the request specifies no encryption headers, satisfying the requirement without relying on the client. Option A is not correct because AWS CloudTrail only records and logs API activity for auditing; it cannot prevent or enforce encryption of objects. Option B is not correct because VPC endpoints only control network access paths to S3 and have no bearing on whether objects are encrypted at rest. Option E is not correct because AWS KMS generates and manages keys, but merely having KMS keys available does not by itself enforce encryption on the bucket; enforcement requires default encryption or a bucket policy condition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudTrail to monitor for unencrypted objects

    Why it's wrong here

    CloudTrail records API activity for auditing after the fact; it neither encrypts objects nor blocks unencrypted uploads. It is tempting because detecting unencrypted objects sounds like enforcement, and CloudTrail would be correct for evidencing who accessed or modified bucket settings, not for preventing plaintext writes.

  • ✗

    Use VPC endpoints to restrict access

    Why it's wrong here

    VPC endpoints control network reachability to S3, not object encryption; data written through them can still be unencrypted. They are tempting because they harden access paths against internet exposure, and would be correct if the requirement were restricting traffic to private connectivity rather than enforcing encryption at rest.

  • ✓

    Configure a bucket policy to deny PutObject if encryption headers are missing

    Why this is correct

    A bucket policy with a Deny effect on s3:PutObject conditioned on the absence of encryption headers (for example, s3:x-amz-server-side-encryption) rejects unencrypted uploads at the API layer, satisfying the requirement to enforce encryption at rest for every object written to the bucket.

  • ✓

    Enable default encryption on the S3 bucket using SSE-S3

    Why this is correct

    Enabling default encryption with SSE-S3 makes Amazon S3 apply AES-256 server-side encryption automatically to every object written to the bucket, satisfying the encryption-at-rest requirement without per-object configuration. This meets the stem's constraint that all data in the bucket be encrypted, since new uploads inherit the bucket default.

  • ✗

    Use AWS KMS to generate encryption keys for the bucket

    Why it's wrong here

    AWS KMS supplies and manages keys, but generating keys alone does not enforce encryption; a bucket policy or default encryption setting must deny unencrypted PUTs. KMS is tempting because SSE-KMS is the encryption mechanism itself, and would be correct where the requirement is customer-managed keys rather than blanket enforcement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.