Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to ensure that all objects written to an S3 bucket are encrypted with SSE-KMS using a specific customer managed key, and that any upload without that encryption is rejected. The engineer has created the bucket and the KMS key. Which approach will enforce this requirement at the bucket level?

⚠ Common exam trap

The trap here is assuming that setting default encryption on the bucket is sufficient to enforce a specific encryption method for all uploads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a bucket policy that denies s3:PutObject requests where the s3:x-amz-server-side-encryption header is not aws:kms or the s3:x-amz-server-side-encryption-aws-kms-key-id does not match the specified key.

To enforce that every object is uploaded with a specific SSE-KMS key, a bucket policy must explicitly deny s3:PutObject requests that do not carry the required encryption headers. Default encryption only applies when no encryption is specified, and it cannot reject requests that specify a different method. The policy approach is the only one that guarantees non-compliant uploads are denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Block Public Access on the bucket.

    Why it's wrong here

    S3 Block Public Access prevents public access to the bucket and its objects, but it does not control encryption. It cannot enforce encryption headers or reject uploads that lack proper encryption. This option is unrelated to the encryption requirement and would not prevent an object from being uploaded without SSE-KMS, so it fails to meet the scenario's goal.

  • ✗

    Use an S3 Lifecycle rule to transition objects to S3 Glacier with encryption.

    Why it's wrong here

    Lifecycle rules manage object storage class transitions and expiration, not upload-time encryption enforcement. They cannot inspect or reject incoming PUT requests. Even if Glacier uses encryption, the object would already have been stored unencrypted or with the wrong key before transition. This does not satisfy the need to reject non-compliant uploads at the time of write.

  • ✓

    Add a bucket policy that denies s3:PutObject requests where the s3:x-amz-server-side-encryption header is not aws:kms or the s3:x-amz-server-side-encryption-aws-kms-key-id does not match the specified key.

    Why this is correct

    A bucket policy with a Deny effect on s3:PutObject can evaluate conditions on request headers such as s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id. This explicitly blocks uploads that do not use the required encryption method and key. This is the only option that enforces rejection of non-compliant uploads at the bucket level, satisfying the requirement.

  • ✗

    Configure the bucket's default encryption to use SSE-KMS with the customer managed key.

    Why it's wrong here

    Setting default encryption only applies encryption to objects that are uploaded without explicit encryption information. It does not reject uploads that specify a different encryption method or no encryption; the object will still be encrypted with the default key. This does not meet the requirement to reject non-compliant uploads. A bucket policy is needed to deny requests that do not include the required encryption headers.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.