DEA-C01 Data Security and Governance Practice Question
A data engineer needs to enforce that all data in an Amazon S3 bucket is encrypted at rest. Which of the following can be used to achieve this? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a bucket policy to deny PutObject if encryption headers are missing
Option C is correct because an S3 bucket policy can include a Deny statement on s3:PutObject that uses a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its aws:kms variant), which blocks any upload request that does not carry the required encryption header, thereby enforcing encryption at rest for newly written objects. Option D is correct because enabling default bucket encryption with SSE-S3 (AES-256) causes Amazon S3 to automatically encrypt every object at rest on write, even when the request specifies no encryption headers, satisfying the requirement without relying on the client. Option A is not correct because AWS CloudTrail only records and logs API activity for auditing; it cannot prevent or enforce encryption of objects. Option B is not correct because VPC endpoints only control network access paths to S3 and have no bearing on whether objects are encrypted at rest. Option E is not correct because AWS KMS generates and manages keys, but merely having KMS keys available does not by itself enforce encryption on the bucket; enforcement requires default encryption or a bucket policy condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudTrail to monitor for unencrypted objects
Why it's wrong here
CloudTrail records API activity for auditing after the fact; it neither encrypts objects nor blocks unencrypted uploads. It is tempting because detecting unencrypted objects sounds like enforcement, and CloudTrail would be correct for evidencing who accessed or modified bucket settings, not for preventing plaintext writes.
- ✗
Use VPC endpoints to restrict access
Why it's wrong here
VPC endpoints control network reachability to S3, not object encryption; data written through them can still be unencrypted. They are tempting because they harden access paths against internet exposure, and would be correct if the requirement were restricting traffic to private connectivity rather than enforcing encryption at rest.
- ✓
Configure a bucket policy to deny PutObject if encryption headers are missing
Why this is correct
A bucket policy with a Deny effect on s3:PutObject conditioned on the absence of encryption headers (for example, s3:x-amz-server-side-encryption) rejects unencrypted uploads at the API layer, satisfying the requirement to enforce encryption at rest for every object written to the bucket.
- ✓
Enable default encryption on the S3 bucket using SSE-S3
Why this is correct
Enabling default encryption with SSE-S3 makes Amazon S3 apply AES-256 server-side encryption automatically to every object written to the bucket, satisfying the encryption-at-rest requirement without per-object configuration. This meets the stem's constraint that all data in the bucket be encrypted, since new uploads inherit the bucket default.
- ✗
Use AWS KMS to generate encryption keys for the bucket
Why it's wrong here
AWS KMS supplies and manages keys, but generating keys alone does not enforce encryption; a bucket policy or default encryption setting must deny unencrypted PUTs. KMS is tempting because SSE-KMS is the encryption mechanism itself, and would be correct where the requirement is customer-managed keys rather than blanket enforcement.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.