Courseiva

DEA-C01 Data Security and Governance Practice Question

A healthcare company stores patient records in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A new AWS Glue ETL job must read these records and write transformed data to another S3 bucket that is also encrypted with the same KMS key. The company's security policy requires that the Glue job's access to the KMS key be least-privilege and auditable. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that granting IAM permissions alone or using Lake Formation is sufficient for a Glue job to read SSE-KMS encrypted S3 data, when the KMS key policy must also explicitly allow the role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a key policy to the KMS key that allows the AWS Glue service role to use the key for decrypt and generateDataKey operations, scoped to the specific S3 buckets via encryption context conditions.

Access to SSE-KMS encrypted S3 objects requires permissions in both the KMS key policy and the IAM identity policy of the calling principal. The Glue service role must be granted only the necessary KMS operations (Decrypt and GenerateDataKey) on the specific key, with conditions to scope usage. This combination enforces least privilege and provides an auditable trail. Broad permissions or unrelated services do not meet the security policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable S3 Block Public Access on both S3 buckets and enable default encryption with SSE-S3 to simplify key management.

    Why it's wrong here

    Block Public Access and SSE-S3 do not grant the Glue job access to the existing SSE-KMS encrypted data. Switching to SSE-S3 would change the encryption method and remove the customer managed key controls required by the security policy. This action does not address the need for least-privilege KMS access and is therefore incorrect.

  • ✗

    Grant the Glue service role kms:* permissions on all KMS keys in the account to ensure the job can read and write data without interruption.

    Why it's wrong here

    Granting kms:* on all keys violates the least-privilege requirement. It would allow the Glue role to manage, delete, or use any key in the account, far exceeding what is needed. The security policy explicitly requires scoped, auditable access, so broad permissions are inappropriate and would fail an audit.

  • ✓

    Attach a key policy to the KMS key that allows the AWS Glue service role to use the key for decrypt and generateDataKey operations, scoped to the specific S3 buckets via encryption context conditions.

    Why this is correct

    The key policy is the primary access control for a KMS key. Granting the Glue service role only kms:Decrypt and kms:GenerateDataKey, with encryption context conditions that match the bucket ARNs, enforces least privilege and ensures the key can only be used for the intended S3 data. This directly satisfies the auditable, least-privilege requirement for the Glue job.

  • ✗

    Use AWS Lake Formation to grant the Glue job fine-grained access to the underlying S3 data and rely on Lake Formation to manage KMS permissions automatically.

    Why it's wrong here

    Lake Formation manages permissions for data catalog resources and can enforce cell-level security, but it does not automatically grant KMS permissions for SSE-KMS encrypted S3 objects. The Glue job still needs explicit KMS permissions in the key policy and IAM policy. Relying solely on Lake Formation would not satisfy the encryption access requirement.

  • ✓

    Create an IAM policy that allows the Glue service role to call kms:Decrypt and kms:GenerateDataKey on the specific KMS key ARN, and attach it to the role.

    Why this is correct

    An IAM identity-based policy attached to the Glue service role is required in addition to the key policy. It grants the role permission to call the necessary KMS operations on the specific key ARN, ensuring the role can decrypt source objects and encrypt output objects. This works with the key policy to provide least-privilege, auditable access.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.