DEA-C01 Data Operations and Support Practice Question
A data engineer needs to ensure that sensitive data stored in Amazon S3 is encrypted at rest. Which TWO options meet this requirement? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often confuse encryption in transit (SSL/TLS) with encryption at rest, or they mistakenly think network controls like VPCs or access controls like MFA Delete provide data encryption, when they only address different security domains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
Options A (SSE-KMS) and B (SSE-S3) are correct because both are server-side encryption mechanisms that encrypt S3 objects at rest: SSE-KMS uses AWS KMS customer master keys (CMKs) to generate and manage data keys, while SSE-S3 uses AES-256 keys fully managed by Amazon S3. Both satisfy the requirement that sensitive data stored in S3 be encrypted at rest, and each is applied per-object when the object is written to the bucket. Option C is incorrect because a VPC only controls network-level access to S3 (via endpoints and policies) and does not encrypt data at rest. Option D is incorrect because MFA Delete only adds an authentication requirement for deleting objects or changing versioning state; it provides no encryption. Option E is incorrect because SSL/TLS encrypts data in transit, not at rest, and client-side encryption is a separate approach not represented by that option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
Why this is correct
SSE-KMS encrypts objects at rest using keys managed in AWS KMS, satisfying the encryption-at-rest requirement. It provides envelope encryption with an independent data key per object, plus audit trails via CloudTrail and granular access control through key policies — unlike SSE-S3, which offers no separate key permissions or key-usage auditing.
- ✓
Server-Side Encryption with S3-Managed Keys (SSE-S3)
Why this is correct
SSE-S3 encrypts each object with a unique AES-256 data key, itself encrypted by a regularly rotated root key managed entirely by Amazon S3. This satisfies the at-rest encryption requirement without the engineer provisioning or managing any keys, since AWS handles the full key lifecycle transparently.
- ✗
Using a VPC to restrict network access
Why it's wrong here
A VPC restricts network reachability to S3 endpoints but leaves objects stored unencrypted on disk, so it does not satisfy encryption at rest. VPC endpoints and network controls are the right choice when the requirement is keeping S3 traffic off the public internet or limiting which resources can reach a bucket.
- ✗
Enabling MFA Delete on the S3 bucket
Why it's wrong here
MFA Delete protects against unauthorised deletion or versioning changes of S3 objects; it does not encrypt object data at rest. It is the correct control when the requirement is preventing accidental or malicious permanent deletion of versioned objects, which is a durability and integrity concern rather than a confidentiality one.
- ✗
Client-Side Encryption with SSL/TLS
Why it's wrong here
SSL/TLS encrypts data in transit between the client and S3; client-side encryption is the mechanism that protects data at rest, and the option conflates the two. TLS is correct when the requirement is protecting data on the wire from interception, not when objects must be unreadable in the bucket itself.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.