Courseiva
Data Store Management →hardMultiple Choice

DEA-C01 Data Store Management Practice Question

A data engineering team is designing a data lake on Amazon S3. They need to store raw data in its original format and transformed data in Parquet. The data is accessed by multiple analytics services, including Amazon Athena and Amazon Redshift Spectrum. Compliance requirements mandate that all data be encrypted at rest with AWS KMS and that the encryption keys be rotated every 90 days. Which S3 bucket configuration meets these requirements?

⚠ Common exam trap

The trap is that candidates assume SSE-S3 or default encryption meets the 90-day rotation requirement because AWS rotates keys automatically, but they overlook that SSE-S3 key rotation is not configurable—it follows AWS-managed rotation, which is not guaranteed every 90 days. SSE-KMS with a customer-managed key is the only option that allows a custom rotation schedule, even though it may require additional automation beyond the automatic yearly rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSE-KMS with a customer-managed KMS key that has automatic key rotation enabled.

SSE-KMS with a customer-managed KMS key allows you to implement custom key rotation, such as every 90 days, by creating new keys and updating the bucket policy or key alias. AWS KMS automatic key rotation for customer-managed keys occurs yearly, not every 90 days, but you can achieve a 90-day rotation schedule manually or through automation (e.g., AWS Lambda). SSE-C requires manual key management and does not integrate with AWS services like Amazon Athena. SSE-S3 does not support configurable rotation, and the default encryption option (C) does not meet compliance if rotation is required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use SSE-KMS with a customer-managed KMS key that has automatic key rotation enabled.

    Why this is correct

    SSE-KMS with automatic rotation meets compliance requirements.

  • ✗

    Use SSE-C with client-managed keys and rotate them manually.

    Why it's wrong here

    SSE-C requires manual key rotation and does not use KMS.

  • ✗

    Use a bucket policy to enforce encryption and rely on default S3 encryption.

    Why it's wrong here

    Bucket policies do not encrypt data; they only enforce encryption.

  • ✗

    Use SSE-S3 with default encryption enabled.

    Why it's wrong here

    SSE-S3 does not support customer-managed key rotation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.