DEA-C01 Data Security and Governance Practice Question
Network Topology
A data engineer runs the command shown to check the encryption configuration of an S3 bucket. The output shows SSEAlgorithm: AES256. What does this mean?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket uses SSE-S3 with Amazon S3-managed keys
AES256 refers to SSE-S3, where Amazon S3 manages the encryption keys using AES-256. Option B (SSE-KMS) would show 'aws:kms'. Option C (SSE-C) would require the customer to provide keys. Option D (no encryption) is incorrect because encryption is enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The bucket uses SSE-S3 with Amazon S3-managed keys
Why this is correct
SSEAlgorithm AES256 indicates server-side encryption with Amazon S3-managed keys (SSE-S3), where S3 owns and rotates the AES-256 keys. This satisfies the stem's observed output directly: SSE-KMS would report aws:kms, and SSE-C would not appear as a bucket default algorithm.
- ✗
The bucket uses SSE-KMS with a customer-managed key
Why it's wrong here
SSE-KMS responses name the KMS key and show aws:kms as the algorithm, not AES256. It tempts because KMS also uses AES-256 encryption, but the reported algorithm identifies S3-managed keys, so no customer-managed key is referenced here.
- ✗
The bucket uses SSE-C with customer-provided keys
Why it's wrong here
SSE-C requires the customer to supply the key with every request and returns no SSEAlgorithm value of AES256 in this output; the response would instead show the customer key configuration. It tempts because AES256 is the cipher SSE-C uses, but the key-management party differs.
- ✗
The bucket does not have encryption enabled
Why it's wrong here
AES256 indicates SSE-S3, Amazon S3-managed keys, so encryption is enabled; the bucket is not unencrypted. It tempts because AES256 names a cipher rather than a key source, and default encryption can be absent on older buckets, making 'no encryption' a plausible misreading.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.