Courseiva
Data Operations and Support →mediumMultiple Select

DEA-C01 Data Operations and Support Practice Question

A data engineer needs to ensure that sensitive data stored in Amazon S3 is encrypted at rest. Which TWO options meet this requirement? (Choose TWO.)

⚠ Common exam trap

Watch out — candidates often confuse encryption in transit (SSL/TLS) with encryption at rest, or they mistakenly think network controls like VPCs or access controls like MFA Delete provide data encryption, when they only address different security domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)

Options A (SSE-KMS) and B (SSE-S3) are correct because both are server-side encryption mechanisms that encrypt S3 objects at rest: SSE-KMS uses AWS KMS customer master keys (CMKs) to generate and manage data keys, while SSE-S3 uses AES-256 keys fully managed by Amazon S3. Both satisfy the requirement that sensitive data stored in S3 be encrypted at rest, and each is applied per-object when the object is written to the bucket. Option C is incorrect because a VPC only controls network-level access to S3 (via endpoints and policies) and does not encrypt data at rest. Option D is incorrect because MFA Delete only adds an authentication requirement for deleting objects or changing versioning state; it provides no encryption. Option E is incorrect because SSL/TLS encrypts data in transit, not at rest, and client-side encryption is a separate approach not represented by that option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)

    Why this is correct

    SSE-KMS encrypts objects at rest using keys managed in AWS KMS, satisfying the encryption-at-rest requirement. It provides envelope encryption with an independent data key per object, plus audit trails via CloudTrail and granular access control through key policies — unlike SSE-S3, which offers no separate key permissions or key-usage auditing.

  • ✓

    Server-Side Encryption with S3-Managed Keys (SSE-S3)

    Why this is correct

    SSE-S3 encrypts each object with a unique AES-256 data key, itself encrypted by a regularly rotated root key managed entirely by Amazon S3. This satisfies the at-rest encryption requirement without the engineer provisioning or managing any keys, since AWS handles the full key lifecycle transparently.

  • ✗

    Using a VPC to restrict network access

    Why it's wrong here

    A VPC restricts network reachability to S3 endpoints but leaves objects stored unencrypted on disk, so it does not satisfy encryption at rest. VPC endpoints and network controls are the right choice when the requirement is keeping S3 traffic off the public internet or limiting which resources can reach a bucket.

  • ✗

    Enabling MFA Delete on the S3 bucket

    Why it's wrong here

    MFA Delete protects against unauthorised deletion or versioning changes of S3 objects; it does not encrypt object data at rest. It is the correct control when the requirement is preventing accidental or malicious permanent deletion of versioned objects, which is a durability and integrity concern rather than a confidentiality one.

  • ✗

    Client-Side Encryption with SSL/TLS

    Why it's wrong here

    SSL/TLS encrypts data in transit between the client and S3; client-side encryption is the mechanism that protects data at rest, and the option conflates the two. TLS is correct when the requirement is protecting data on the wire from interception, not when objects must be unreadable in the bucket itself.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.