DEA-C01 Data Store Management Practice Question
A data engineering team is designing a data lake on Amazon S3. They need to store raw data in its original format and transformed data in Parquet. The data is accessed by multiple analytics services, including Amazon Athena and Amazon Redshift Spectrum. Compliance requirements mandate that all data be encrypted at rest with AWS KMS and that the encryption keys be rotated every 90 days. Which S3 bucket configuration meets these requirements?
⚠ Common exam trap
The trap is that candidates assume SSE-S3 or default encryption meets the 90-day rotation requirement because AWS rotates keys automatically, but they overlook that SSE-S3 key rotation is not configurable—it follows AWS-managed rotation, which is not guaranteed every 90 days. SSE-KMS with a customer-managed key is the only option that allows a custom rotation schedule, even though it may require additional automation beyond the automatic yearly rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SSE-KMS with a customer-managed KMS key that has automatic key rotation enabled.
SSE-KMS with a customer-managed KMS key allows you to implement custom key rotation, such as every 90 days, by creating new keys and updating the bucket policy or key alias. AWS KMS automatic key rotation for customer-managed keys occurs yearly, not every 90 days, but you can achieve a 90-day rotation schedule manually or through automation (e.g., AWS Lambda). SSE-C requires manual key management and does not integrate with AWS services like Amazon Athena. SSE-S3 does not support configurable rotation, and the default encryption option (C) does not meet compliance if rotation is required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use SSE-KMS with a customer-managed KMS key that has automatic key rotation enabled.
Why this is correct
SSE-KMS with automatic rotation meets compliance requirements.
- ✗
Use SSE-C with client-managed keys and rotate them manually.
Why it's wrong here
SSE-C requires manual key rotation and does not use KMS.
- ✗
Use a bucket policy to enforce encryption and rely on default S3 encryption.
Why it's wrong here
Bucket policies do not encrypt data; they only enforce encryption.
- ✗
Use SSE-S3 with default encryption enabled.
Why it's wrong here
SSE-S3 does not support customer-managed key rotation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.