DEA-C01 Data Security and Governance Practice Question
A retail company uses Amazon Redshift for its data warehouse. The security team requires that all data in the cluster be encrypted at rest using a hardware security module (HSM) to manage the encryption keys. The data engineer needs to configure the Redshift cluster accordingly. Which action should the data engineer take?
⚠ Common exam trap
The trap here is assuming that AWS KMS or CloudHSM can be used directly for Redshift HSM encryption, when Redshift requires a specific HSM connection configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Redshift cluster to use an HSM for encryption at rest by specifying the HSM connection details and enabling encryption when creating the cluster.
Amazon Redshift supports encryption at rest using an HSM. When creating a cluster, you can choose HSM encryption and provide the HSM connection details. This allows the cluster to use keys stored in a hardware security module, satisfying the security team's requirement. Other options either use KMS or do not encrypt the cluster itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Redshift Spectrum to query data in Amazon S3 that is encrypted with an HSM, and enable encryption for the Redshift cluster with AWS KMS.
Why it's wrong here
Redshift Spectrum queries external data in S3 and does not encrypt the Redshift cluster itself. The cluster encryption is separate and must be configured independently. This option does not address the cluster's at-rest encryption with an HSM.
- ✗
Enable Redshift encryption at rest with an AWS owned key and use AWS CloudHSM to store the key.
Why it's wrong here
AWS owned keys are not customer managed and cannot be stored in CloudHSM. Redshift does not support using CloudHSM directly for cluster encryption; it supports HSM via a classic HSM connection. This option is not valid and does not meet the requirement.
- ✗
Enable Redshift encryption at rest using AWS KMS with a customer managed key, and configure the cluster to use an HSM for key storage.
Why it's wrong here
Redshift encryption at rest with AWS KMS does not use an HSM for key storage; it uses KMS, which is a managed service. While KMS uses HSMs internally, the customer does not manage the HSM. This option does not meet the requirement for a customer-managed HSM.
- ✓
Configure the Redshift cluster to use an HSM for encryption at rest by specifying the HSM connection details and enabling encryption when creating the cluster.
Why this is correct
Amazon Redshift supports encryption at rest using a hardware security module (HSM) for key management. When creating or modifying a cluster, you can enable encryption and specify an HSM connection. This meets the requirement for HSM-based encryption. The HSM must be configured with the appropriate keys and network access.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.