A data engineer is designing a data pipeline that processes sensitive personal data. The data is ingested via Amazon Kinesis Data Firehose and stored in Amazon S3. The pipeline must ensure that the data is encrypted at rest and in transit. The engineer also needs to audit access to the data. Which combination of services meets these requirements?
SSE-S3 encrypts objects at rest, HTTPS secures data in transit from Firehose to S3, and CloudTrail records API activity for auditing. Together these three satisfy the encryption and access-audit requirements for the sensitive personal data pipeline.
Why this answer
Option C correctly combines S3 server-side encryption (SSE-S3) for data at rest, HTTPS (TLS) for data in transit, and AWS CloudTrail for auditing access. SSE-S3 provides AES-256 encryption managed by S3, HTTPS ensures secure ingestion and retrieval, and CloudTrail logs all API calls to S3, enabling audit trails. This meets all three requirements: encryption at rest, encryption in transit, and auditability.
Exam trap
DEA-C01 often tests the confusion between services that provide auditing (CloudTrail) versus monitoring (CloudWatch) or compliance (Config), and between encryption mechanisms for data at rest (SSE-S3, SSE-KMS) versus in transit (TLS/HTTPS).
How to eliminate wrong answers
Option A is wrong because Kinesis Data Analytics is an analytics service, not an encryption mechanism for in-transit data; in-transit encryption for Firehose is handled by HTTPS/TLS, not Kinesis Data Analytics. Option B is wrong because Amazon CloudWatch Logs is for monitoring and logging application/system metrics, not for auditing access to S3 data; auditing requires CloudTrail. Option D is wrong because AWS Config is a configuration compliance service, not an audit trail for data access; CloudTrail is the correct service for auditing access.