Drag steps to the numbered slots on the right, or tap a step then tap a slot.
DEA-C01 Data Security and Governance Practice Question
Arrange the steps to implement data encryption at rest for an Amazon Redshift cluster using AWS KMS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Create a KMS key. Step 2: Launch a new Amazon Redshift cluster. Step 3: Enable encryption and specify the KMS key during launch. Step 4: Verify that the cluster is encrypted at rest.
First, create the KMS key. Then launch a new encrypted cluster, specify the key, configure, and verify encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Create a KMS key. Step 2: Launch a new Amazon Redshift cluster. Step 3: Enable encryption and specify the KMS key during launch. Step 4: Verify that the cluster is encrypted at rest.
Why this is correct
This is the correct order because you must first create or have a KMS key available. Then you launch a new cluster (encrypted clusters must be created from scratch; existing clusters cannot be encrypted in place). During launch, you enable encryption and select the KMS key. Finally, you verify encryption by checking the cluster properties or using a query to confirm the cluster is encrypted.
- ✗
Step 1: Launch a new Amazon Redshift cluster. Step 2: Create a KMS key. Step 3: Enable encryption and specify the KMS key. Step 4: Verify encryption.
Why it's wrong here
This is incorrect because you cannot launch an encrypted cluster without a KMS key. If you launch a cluster without encryption first, you cannot later enable encryption on that existing cluster. You would need to take a snapshot and restore it as an encrypted cluster, which is a different process.
- ✗
Step 1: Create a KMS key. Step 2: Verify encryption. Step 3: Launch a new Amazon Redshift cluster. Step 4: Enable encryption and specify the KMS key.
Why it's wrong here
This is incorrect because you cannot verify encryption before the cluster is launched and encryption is enabled. Verification is the final step after the cluster is created and encryption is configured.
- ✗
Step 1: Specify the KMS key. Step 2: Create a KMS key. Step 3: Launch a new Amazon Redshift cluster. Step 4: Verify encryption.
Why it's wrong here
This is incorrect because you cannot specify a KMS key before it exists. You must create the key first, then reference it when launching the cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,711 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.