DEA-C01 Data Security and Governance Practice Question
A data engineer needs to ensure that an AWS Glue ETL job can access an Amazon S3 bucket that is encrypted with SSE-KMS. The Glue job runs with an IAM role. The KMS key policy grants access to the account root. Which TWO actions are required to allow the Glue job to read and write data in the bucket? (Choose two.)
⚠ Common exam trap
The trap here is assuming that S3 permissions alone are sufficient for accessing SSE-KMS encrypted objects, overlooking the need for KMS permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add s3:GetObject and s3:PutObject permissions to the Glue job's IAM role.
To allow an AWS Glue job to access an S3 bucket encrypted with SSE-KMS, the job's IAM role must have both S3 permissions (s3:GetObject, s3:PutObject) and KMS permissions (kms:Decrypt, kms:GenerateDataKey). These permissions enable the job to read and write objects and to use the KMS key for encryption and decryption. Other options either do not provide the necessary permissions or would change the encryption method, which is not desired.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the S3 bucket to use SSE-S3 instead of SSE-KMS.
Why it's wrong here
Changing the encryption method to SSE-S3 would remove the KMS dependency, but it does not meet the requirement to use SSE-KMS. The scenario specifies that the bucket is encrypted with SSE-KMS, and the goal is to allow access while maintaining that encryption. Switching to SSE-S3 would violate the security requirement and is not a valid solution.
- ✓
Add s3:GetObject and s3:PutObject permissions to the Glue job's IAM role.
Why this is correct
The Glue job's IAM role must have s3:GetObject and s3:PutObject permissions to read and write objects in the S3 bucket. These permissions allow the job to perform the necessary S3 operations. Without them, the job cannot access the bucket regardless of KMS permissions. Together with KMS permissions, they enable full access to the encrypted data.
- ✗
Attach an S3 bucket policy that allows the Glue job role to perform s3:GetObject and s3:PutObject.
Why it's wrong here
While an S3 bucket policy can grant permissions, the Glue job's IAM role must also have the necessary permissions. In AWS, access is granted only if both the IAM policy and the resource-based policy allow it. However, the bucket policy alone does not grant KMS permissions, which are also required. Therefore, this action alone is insufficient and not one of the two required actions.
- ✓
Add kms:Decrypt and kms:GenerateDataKey permissions to the Glue job's IAM role.
Why this is correct
The Glue job's IAM role must have permissions to use the KMS key for decryption and data key generation. Without kms:Decrypt, the job cannot read encrypted objects; without kms:GenerateDataKey, it cannot write new objects with SSE-KMS. These permissions are essential for the job to interact with the KMS-encrypted S3 bucket.
- ✗
Add kms:CreateGrant permission to the Glue job's IAM role.
Why it's wrong here
kms:CreateGrant is used to create grants that allow other principals to use a KMS key. It is not required for a Glue job to use a KMS key for encryption and decryption. The job needs kms:Decrypt and kms:GenerateDataKey, not kms:CreateGrant. Adding this permission would not enable the job to access the encrypted data and is unnecessary.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.