Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineering team is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team mandates that both read and write operations use a customer-managed AWS KMS key so they can audit key usage. Which configuration should the data engineer apply to the Glue job to meet this requirement?

⚠ Common exam trap

The trap here is assuming that S3 bucket default encryption or bucket policies alone will force AWS Glue to use a specific customer-managed KMS key for both reads and writes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS Glue Security configuration that enables S3 encryption with the customer-managed KMS key for both reads and writes, and attach it to the job.

The correct approach is to use an AWS Glue Security configuration that specifies the customer-managed KMS key for S3 encryption. This configuration is applied at the job level and ensures that Glue uses the key for both reading and writing data. It provides a centralized way to enforce encryption and enables auditing of key usage. Other methods like bucket policies or default encryption do not guarantee that the Glue job will use the specified key for all operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the S3 bucket with the customer-managed KMS key and rely on Glue to use that default for all operations.

    Why it's wrong here

    Default bucket encryption applies only when objects are written without explicit encryption settings. Glue jobs may specify their own encryption or use SSE-S3, and default encryption does not force the use of a specific KMS key for reads. Moreover, reads do not require encryption settings; the key must be authorized for decryption. This does not meet the requirement to audit key usage for both reads and writes.

  • ✗

    Modify the S3 bucket policy to deny any requests that do not include the aws:SecureTransport condition and require the KMS key in the request headers.

    Why it's wrong here

    While bucket policies can enforce encryption in transit and require specific KMS keys for PutObject, they do not automatically apply a KMS key for Glue reads and writes. The Glue job must be configured to use the key; otherwise, the job's requests may be denied or use the default encryption. This approach alone does not guarantee that Glue uses the customer-managed key.

  • ✗

    Add a job parameter --encryption-type sse-kms and specify the KMS key ARN in the job script, then set the Security configuration to use the same key.

    Why it's wrong here

    Glue job parameters do not include an --encryption-type option for S3; encryption is controlled by the S3 bucket policy and the Security configuration for CloudWatch/S3. Specifying a key only in the script does not enforce KMS encryption for all reads and writes, and the job would fail to apply the key consistently across all data access paths.

  • ✓

    Create an AWS Glue Security configuration that enables S3 encryption with the customer-managed KMS key for both reads and writes, and attach it to the job.

    Why this is correct

    A Glue Security configuration allows you to specify a KMS key for S3 encryption, which Glue uses when reading from and writing to S3. By attaching this configuration to the job, all data access uses the specified customer-managed key, satisfying the audit requirement. This is the intended mechanism for controlling encryption in Glue jobs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.