DEA-C01 Data Security and Governance Practice Question
A data engineer needs to grant an AWS Glue ETL job access to read data from an Amazon S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs with an IAM role. Which action must the engineer take to allow the Glue job to decrypt the data?
⚠ Common exam trap
The trap here is assuming that granting s3:GetObject in a bucket policy is sufficient for reading SSE-KMS encrypted objects, when in fact the requester also needs explicit KMS permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a policy to the Glue job's IAM role that allows kms:Decrypt and kms:GenerateDataKey on the specific KMS key.
To allow an AWS Glue job to read SSE-KMS encrypted data from S3, the IAM role associated with the Glue job must have permissions to use the KMS key for decryption. Specifically, the role needs kms:Decrypt and kms:GenerateDataKey permissions on the key. S3 bucket policies alone do not grant KMS access, and changing encryption to SSE-S3 or using access points does not satisfy the requirement to use SSE-KMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable default encryption on the S3 bucket using SSE-S3 instead of SSE-KMS, which eliminates the need for KMS permissions.
Why it's wrong here
Changing the encryption to SSE-S3 would remove the need for KMS permissions, but it would also change the encryption method for all objects, which may not be acceptable if the requirement is to use SSE-KMS with a customer managed key. The scenario specifies SSE-KMS, so switching to SSE-S3 does not meet the requirement and may violate compliance.
- ✓
Attach a policy to the Glue job's IAM role that allows kms:Decrypt and kms:GenerateDataKey on the specific KMS key.
Why this is correct
For a Glue job to read SSE-KMS encrypted data, its IAM role must have permissions to use the KMS key for decryption. The required permissions are kms:Decrypt and kms:GenerateDataKey (for some operations). Attaching a policy with these actions on the specific key resource grants the necessary access. Without these permissions, the Glue job will fail with access denied errors.
- ✗
Use an S3 Access Point with a policy that allows the Glue job's IAM role to access objects, and configure the access point to use a different KMS key.
Why it's wrong here
An S3 Access Point can have its own policy, but it does not bypass the need for KMS permissions. The Glue job's IAM role still needs kms:Decrypt on the KMS key used to encrypt the objects. Configuring a different key does not help and may complicate access. The core requirement is to grant KMS permissions to the role.
- ✗
Modify the S3 bucket policy to allow the Glue job's IAM role to perform s3:GetObject, and rely on S3 to decrypt the data automatically.
Why it's wrong here
S3 does not automatically decrypt data for the requester; the requester must have permissions to use the KMS key. A bucket policy granting s3:GetObject only allows access to the encrypted object, but decryption requires KMS permissions. Without kms:Decrypt, the Glue job cannot read the plaintext data, resulting in an access denied error.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.