Courseiva

DEA-C01 Data Security and Governance Practice Question

Network Topology
aws s3api get-bucket-encryptionbucket example-bucketRefer to the exhibit.Output:"ServerSideEncryptionConfiguration": {"Rules": ["ApplyServerSideEncryptionByDefault": {"SSEAlgorithm": "AES256"

A data engineer runs the command shown to check the encryption configuration of an S3 bucket. The output shows SSEAlgorithm: AES256. What does this mean?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket uses SSE-S3 with Amazon S3-managed keys

AES256 refers to SSE-S3, where Amazon S3 manages the encryption keys using AES-256. Option B (SSE-KMS) would show 'aws:kms'. Option C (SSE-C) would require the customer to provide keys. Option D (no encryption) is incorrect because encryption is enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The bucket uses SSE-S3 with Amazon S3-managed keys

    Why this is correct

    SSEAlgorithm AES256 indicates server-side encryption with Amazon S3-managed keys (SSE-S3), where S3 owns and rotates the AES-256 keys. This satisfies the stem's observed output directly: SSE-KMS would report aws:kms, and SSE-C would not appear as a bucket default algorithm.

  • ✗

    The bucket uses SSE-KMS with a customer-managed key

    Why it's wrong here

    SSE-KMS responses name the KMS key and show aws:kms as the algorithm, not AES256. It tempts because KMS also uses AES-256 encryption, but the reported algorithm identifies S3-managed keys, so no customer-managed key is referenced here.

  • ✗

    The bucket uses SSE-C with customer-provided keys

    Why it's wrong here

    SSE-C requires the customer to supply the key with every request and returns no SSEAlgorithm value of AES256 in this output; the response would instead show the customer key configuration. It tempts because AES256 is the cipher SSE-C uses, but the key-management party differs.

  • ✗

    The bucket does not have encryption enabled

    Why it's wrong here

    AES256 indicates SSE-S3, Amazon S3-managed keys, so encryption is enabled; the bucket is not unencrypted. It tempts because AES256 names a cipher rather than a key source, and default encryption can be absent on older buckets, making 'no encryption' a plausible misreading.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.