Courseiva

DEA-C01 Data Security and Governance Practice Question

A retail company uses Amazon Redshift for its data warehouse. The security team requires that all data in the cluster be encrypted at rest using a hardware security module (HSM) to manage the encryption keys. The data engineer needs to configure the Redshift cluster accordingly. Which action should the data engineer take?

⚠ Common exam trap

The trap here is assuming that AWS KMS or CloudHSM can be used directly for Redshift HSM encryption, when Redshift requires a specific HSM connection configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Redshift cluster to use an HSM for encryption at rest by specifying the HSM connection details and enabling encryption when creating the cluster.

Amazon Redshift supports encryption at rest using an HSM. When creating a cluster, you can choose HSM encryption and provide the HSM connection details. This allows the cluster to use keys stored in a hardware security module, satisfying the security team's requirement. Other options either use KMS or do not encrypt the cluster itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Redshift Spectrum to query data in Amazon S3 that is encrypted with an HSM, and enable encryption for the Redshift cluster with AWS KMS.

    Why it's wrong here

    Redshift Spectrum queries external data in S3 and does not encrypt the Redshift cluster itself. The cluster encryption is separate and must be configured independently. This option does not address the cluster's at-rest encryption with an HSM.

  • ✗

    Enable Redshift encryption at rest with an AWS owned key and use AWS CloudHSM to store the key.

    Why it's wrong here

    AWS owned keys are not customer managed and cannot be stored in CloudHSM. Redshift does not support using CloudHSM directly for cluster encryption; it supports HSM via a classic HSM connection. This option is not valid and does not meet the requirement.

  • ✗

    Enable Redshift encryption at rest using AWS KMS with a customer managed key, and configure the cluster to use an HSM for key storage.

    Why it's wrong here

    Redshift encryption at rest with AWS KMS does not use an HSM for key storage; it uses KMS, which is a managed service. While KMS uses HSMs internally, the customer does not manage the HSM. This option does not meet the requirement for a customer-managed HSM.

  • ✓

    Configure the Redshift cluster to use an HSM for encryption at rest by specifying the HSM connection details and enabling encryption when creating the cluster.

    Why this is correct

    Amazon Redshift supports encryption at rest using a hardware security module (HSM) for key management. When creating or modifying a cluster, you can enable encryption and specify an HSM connection. This meets the requirement for HSM-based encryption. The HSM must be configured with the appropriate keys and network access.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.