Courseiva
Data Security and GovernancehardMultiple ChoiceObjective-mapped

DEA-C01 Data Security and Governance Practice Question

A data engineering team uses AWS Glue ETL jobs to process data from an S3 data lake and load it into an Amazon Redshift cluster. The security policy mandates that all data in transit between AWS Glue and Redshift must be encrypted using TLS. The team uses a JDBC connection. Currently, the connection is failing with an SSL-related error. Which configuration change should the team make to ensure encrypted connectivity?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Update the JDBC connection string to include ssl=true and sslmode=require.

To enforce TLS encryption for JDBC connections to Amazon Redshift, the connection string must include ssl=true and often sslmode=require. This is a client-side configuration that tells the JDBC driver to use SSL. Option A is incorrect because security groups control network access, not encryption. Option C is incorrect because server-side encryption on S3 secures data at rest, not data in transit. Option D is incorrect because setting require_ssl=ON in the cluster parameter group enforces SSL on the server side, but the client (Glue) must still specify ssl=true in the JDBC URL to establish an encrypted connection. Therefore, the correct change is option B.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Modify the Redshift security group to allow inbound traffic on port 5439 from the Glue subnet.

    Why it's wrong here

    Network access, not encryption.

  • Update the JDBC connection string to include ssl=true and sslmode=require.

    Why this is correct

    Ensures the JDBC driver uses SSL encryption.

  • Enable server-side encryption on the S3 bucket using AWS KMS.

    Why it's wrong here

    For data at rest in S3, not in transit.

  • Set the Redshift cluster parameter group to require_ssl=ON.

    Why it's wrong here

    This forces SSL on Redshift server side; but the JDBC driver may still not use SSL without the URL parameter.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.