Courseiva

CCNA Data Security and Governance Questions

75 of 246 questions · Page 2/4 · Data Security and Governance · Answers revealed

76
MCQmedium

A company uses Amazon RDS for MySQL to store financial data. A compliance requirement mandates that all database connections must be encrypted. Which configuration step is necessary?

A.Set the RDS parameter require_secure_transport to 1.
B.Create the RDS DB instance in a private subnet.
C.Enable encryption for the RDS DB instance at creation time.
D.Configure the VPC security group to only allow traffic from certain IPs.
AnswerA

This is correct. To enforce encrypted connections for RDS MySQL, you must modify the DB parameter group to require SSL/TLS by setting parameters such as 'require_secure_transport' to 1. While the exact parameter name may vary, the intent is to enforce encryption in transit.

Why this answer

For Amazon RDS for MySQL, the parameter require_secure_transport controls whether the DB instance accepts only SSL/TLS-encrypted connections. Setting it to 1 enforces encryption for all client connections, satisfying the compliance mandate. This is the direct, database-level control for connection encryption, distinct from storage encryption or network isolation.

Exam trap

DEA-C01 often tests the confusion between encryption at rest (storage encryption) and encryption in transit (require_secure_transport), leading candidates to pick the storage encryption option for a connection-encryption requirement.

How to eliminate wrong answers

Option B is wrong because placing the DB instance in a private subnet restricts network reachability but does not encrypt connections — clients in the same VPC can still connect without TLS. Option C is wrong because enabling encryption at creation time encrypts data at rest (storage), not data in transit between clients and the database. Option D is wrong because security group rules filter source IPs and ports but do not enforce TLS on the connection itself.

77
MCQhard

A company stores data in Amazon S3 with server-side encryption using AWS KMS (SSE-KMS). The data engineer needs to give a third-party auditor read-only access to the encrypted objects. The auditor has an AWS account. Which strategy should be used?

A.Generate a presigned URL for each object the auditor needs to access.
B.Copy the objects to a new bucket encrypted with SSE-S3 and share that bucket.
C.Grant the auditor's IAM role permission to use the KMS key.
D.Update the S3 bucket policy to allow access from the auditor's account and update the KMS key policy to allow the auditor's account to decrypt.
AnswerD

SSE-KMS objects require both S3 authorisation and KMS decrypt permission, since S3 calls KMS on the reader's behalf. The bucket policy grants object access; the key policy grants kms:Decrypt to the auditor's account, enabling read-only access.

Why this answer

SSE-KMS requires two independent authorizations: the caller must have s3:GetObject on the bucket (via bucket policy or IAM) AND kms:Decrypt on the KMS key (via key policy or IAM). Because the auditor is in a separate AWS account, both the S3 bucket policy and the KMS key policy must explicitly grant the external account access. This is the only option that satisfies both layers for cross-account access.

Exam trap

DEA-C01 often tests the misconception that KMS key policy alone grants access to encrypted S3 objects, when in fact both the S3 bucket policy (for s3:GetObject) and the KMS key policy (for kms:Decrypt) must permit the cross-account principal.

How to eliminate wrong answers

Option A is wrong because presigned URLs are time-limited (max 7 days), impractical for auditing many objects, and still require the signer to have kms:Decrypt — they don't scale for auditor access patterns. Option B is wrong because copying to SSE-S3 removes the CMK requirement, violates the security posture, duplicates data unnecessarily, and SSE-S3 offers no key-level access control or audit trail. Option C is wrong because granting only KMS key permission is insufficient — without an S3 bucket policy or IAM permission for s3:GetObject, the auditor cannot even read the object, and cross-account access requires an explicit resource-based policy.

78
MCQeasy

A data engineer needs to ensure that an Amazon Redshift cluster encrypts data at rest using a customer-managed AWS KMS key. Which configuration step is required?

A.Create a new cluster and select the default AWS managed key for encryption.
B.Create a new cluster and specify a customer-managed KMS key for encryption.
C.Use AWS CloudHSM to generate a key and attach it to the cluster.
D.Enable encryption on the existing cluster by modifying the cluster configuration.
AnswerB

A Redshift cluster's encryption key is fixed at creation time; you cannot swap the KMS key on an existing cluster. Creating a new cluster and specifying the customer-managed KMS key is therefore the required configuration step.

Why this answer

To encrypt an Amazon Redshift cluster with a customer-managed KMS key, you must specify that key at cluster creation time; Redshift does not allow you to change the encryption key of an existing cluster after it is created. The customer-managed key gives you control over key rotation, grants, and audit via CloudTrail, which is required when the default AWS-managed key (aws/redshift) does not satisfy compliance.

Exam trap

DEA-C01 often tests the misconception that you can modify an existing Redshift cluster to add or change encryption — in reality, encryption is fixed at creation and requires snapshot/restore to change.

How to eliminate wrong answers

Option A is wrong because the default AWS-managed key (aws/redshift) does not give the customer control over key policy, rotation, or grants, which is the stated requirement. Option C is wrong because AWS CloudHSM is a separate hardware security module service; Redshift integrates with KMS, not CloudHSM, for at-rest encryption keys. Option D is wrong because Redshift does not support enabling or changing encryption on an existing cluster in place — you must create a new encrypted cluster and migrate data (or restore from a snapshot with encryption).

79
Multi-Selecthard

A data engineer is configuring an AWS Glue ETL job that reads from and writes to an Amazon S3 bucket. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS, and that the job must fail if TLS is not used. Which two actions should the data engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Attach a bucket policy that denies s3:GetObject requests where aws:SecureTransport is false.
B.Enable default encryption on the S3 bucket using SSE-S3.
C.Configure the Glue job to use a VPC endpoint for Amazon S3 and set the endpoint policy to require TLS.
D.Attach a bucket policy that denies s3:PutObject requests where aws:SecureTransport is false.
E.Enable S3 Transfer Acceleration on the bucket.
AnswersA, D

A bucket policy denying s3:GetObject when aws:SecureTransport is false blocks any read request that does not use TLS. This ensures the Glue job cannot read data insecurely and will fail if it attempts a non-TLS connection, satisfying the requirement for encryption in transit on reads.

Why this answer

To enforce TLS for all data in transit between AWS Glue and Amazon S3, you must deny both read and write requests that do not use TLS. Bucket policies that deny s3:GetObject and s3:PutObject when aws:SecureTransport is false accomplish this. Default encryption, VPC endpoint policies, and Transfer Acceleration do not universally enforce TLS for all Glue-to-S3 traffic or cause the job to fail on insecure connections.

Exam trap

The trap here is assuming that enabling default encryption or using a VPC endpoint automatically enforces TLS for all traffic, when only explicit bucket policy denials based on aws:SecureTransport guarantee that insecure requests are rejected.

80
Multi-Selecteasy

A data engineer needs to audit data access in Amazon S3 for compliance. Which TWO services can be used to capture and analyze S3 access logs? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.S3 server access logs
D.Amazon Macie
E.AWS Config
AnswersB, C

AWS CloudTrail records S3 data-plane API calls such as GetObject and PutObject, capturing the identity, source IP and timestamp of each access. This satisfies the audit requirement by providing an analysable event trail for compliance, complementing S3 server access logs.

Why this answer

AWS CloudTrail (B) is correct because it records S3 data events (object-level operations like GetObject and PutObject) and management events, delivering them to CloudTrail logs or CloudWatch Logs for auditing and analysis of who accessed what in S3. S3 server access logs (C) are correct because they provide detailed, best-effort records of every request made to a bucket, including requester, bucket, key, operation, and response codes, which can be stored and analyzed for compliance auditing. Amazon CloudWatch Logs (A) is not a log source for S3 access itself; it only stores and analyzes logs that are delivered to it by other services such as CloudTrail.

Amazon Macie (D) is a data security service that discovers and classifies sensitive data in S3, not a service for capturing S3 access logs. AWS Config (E) tracks resource configuration changes and compliance against rules, not individual S3 data access events.

81
Multi-Selectmedium

A data engineer is preparing an AWS Glue ETL job that reads from and writes to Amazon S3 and must audit every access to sensitive data for compliance. The security team wants to know which principals accessed which objects and when, and also wants to detect anomalous access patterns. Which TWO AWS services should be used together to meet these requirements? (Choose two.)

Select 2 answers
A.Amazon Macie sensitive data discovery jobs
B.Amazon S3 Inventory reports
C.AWS Glue job bookmarks
D.Amazon GuardDuty S3 Protection
E.AWS CloudTrail data events for S3
AnswersD, E

GuardDuty S3 Protection continuously analyzes CloudTrail data and management events to identify anomalous or suspicious S3 access, such as unusual API calls or access from unexpected locations. It surfaces findings that help the security team detect behavior changes rather than only recording raw events. Used alongside CloudTrail data events, it covers both the audit record and the anomaly detection requirement.

Why this answer

CloudTrail data events capture object-level API activity with caller identity, bucket, key, and time, forming the required audit trail for sensitive object access. GuardDuty S3 Protection analyzes that activity to surface anomalous or suspicious access. Together they provide both the detailed record and the detection capability, while inventory, bookmarks, and Macie address classification or processing state rather than access auditing.

Exam trap

The trap here is confusing data classification and inventory services such as Macie or S3 Inventory with access auditing, which requires CloudTrail data events.

82
Multi-Selecthard

A healthcare company stores patient records in an Amazon S3 bucket encrypted with SSE-KMS using a customer managed key. A new AWS Glue ETL job must read these records and write transformed data to another S3 bucket that is also encrypted with the same KMS key. The company's security policy requires that the Glue job's access to the KMS key be least-privilege and auditable. Which TWO actions should the data engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable S3 Block Public Access on both S3 buckets and enable default encryption with SSE-S3 to simplify key management.
B.Grant the Glue service role kms:* permissions on all KMS keys in the account to ensure the job can read and write data without interruption.
C.Attach a key policy to the KMS key that allows the AWS Glue service role to use the key for decrypt and generateDataKey operations, scoped to the specific S3 buckets via encryption context conditions.
D.Use AWS Lake Formation to grant the Glue job fine-grained access to the underlying S3 data and rely on Lake Formation to manage KMS permissions automatically.
E.Create an IAM policy that allows the Glue service role to call kms:Decrypt and kms:GenerateDataKey on the specific KMS key ARN, and attach it to the role.
AnswersC, E

The key policy is the primary access control for a KMS key. Granting the Glue service role only kms:Decrypt and kms:GenerateDataKey, with encryption context conditions that match the bucket ARNs, enforces least privilege and ensures the key can only be used for the intended S3 data. This directly satisfies the auditable, least-privilege requirement for the Glue job.

Why this answer

Access to SSE-KMS encrypted S3 objects requires permissions in both the KMS key policy and the IAM identity policy of the calling principal. The Glue service role must be granted only the necessary KMS operations (Decrypt and GenerateDataKey) on the specific key, with conditions to scope usage. This combination enforces least privilege and provides an auditable trail.

Broad permissions or unrelated services do not meet the security policy.

Exam trap

The trap here is assuming that granting IAM permissions alone or using Lake Formation is sufficient for a Glue job to read SSE-KMS encrypted S3 data, when the KMS key policy must also explicitly allow the role.

83
MCQmedium

A data engineer must ensure that an AWS Glue ETL job can read from an Amazon S3 bucket encrypted with SSE-KMS and write to another S3 bucket also encrypted with SSE-KMS, using a single KMS key. The engineer has created an IAM role for the Glue job with permissions to access both buckets. What additional step is required to allow the Glue job to decrypt and encrypt data using the KMS key?

A.Attach a KMS key policy to the customer managed key that allows the Glue job's IAM role to use the key for encrypt and decrypt operations.
B.Grant the Glue job's IAM role the kms:CreateGrant permission in its identity-based policy.
C.Enable default encryption on both S3 buckets using SSE-S3 instead of SSE-KMS.
D.Modify the S3 bucket policy to allow the Glue job's IAM role to perform kms:Decrypt on the bucket.
AnswerA

KMS key policies are the primary way to control access to customer managed keys. Even if the IAM role has permissions in its identity-based policy, the key policy must also grant access. For a Glue job to use a KMS key, the key policy must explicitly allow the IAM role to perform kms:Decrypt and kms:Encrypt. Without this, the job will fail with access denied.

Why this answer

For a Glue job to use a KMS key for SSE-KMS encryption, both the IAM role's identity-based policy and the KMS key policy must grant the necessary permissions. The key policy is the resource-based policy that controls access to the KMS key. Without an explicit allow in the key policy for the Glue job's IAM role to perform kms:Decrypt and kms:Encrypt, the job cannot use the key, even if the IAM policy allows it.

Exam trap

The trap here is assuming that IAM permissions alone are sufficient to use a KMS key, when the KMS key policy must also grant access.

84
Multi-Selectmedium

A company is designing a data lake on Amazon S3. The security team requires granular access control based on data classifications. Which TWO AWS services can be used together to implement attribute-based access control (ABAC) for objects in S3?

Select 2 answers
A.AWS Secrets Manager
B.AWS Lake Formation
C.Amazon S3 object tags
D.AWS Identity and Access Management (IAM)
E.AWS Key Management Service (KMS)
AnswersC, D

S3 object tags supply the resource-side attributes that ABAC evaluates, letting bucket policies and IAM permissions grant or deny access based on classification tags such as data sensitivity. Combined with IAM, tags form the attribute pair required for tag-based, granular object access control.

Why this answer

Amazon S3 object tags (C) are the attribute source in S3 ABAC: classification labels such as DataClass=Confidential are attached to objects, and IAM policies reference them via conditions like s3:ExistingObjectTag/<key>. AWS Identity and Access Management (D) is the policy engine that evaluates those tag-based conditions in identity and resource policies, granting or denying access according to the object's classification attribute. Together, S3 object tags supply the attributes and IAM enforces attribute-based access control, which is exactly the ABAC pattern required for the data lake.

AWS Secrets Manager (A) stores and rotates secrets such as credentials, not access-control attributes. AWS Lake Formation (B) manages fine-grained permissions over data catalog tables and databases, not S3 object-level ABAC. AWS Key Management Service (E) provides encryption key management and cryptographic operations, not authorization decisions.

85
Multi-Selectmedium

A data engineer needs to ensure that an AWS Glue ETL job can access an Amazon S3 bucket that is encrypted with SSE-KMS. The Glue job runs with an IAM role. The KMS key policy grants access to the account root. Which TWO actions are required to allow the Glue job to read and write data in the bucket? (Choose two.)

Select 2 answers
A.Configure the S3 bucket to use SSE-S3 instead of SSE-KMS.
B.Add s3:GetObject and s3:PutObject permissions to the Glue job's IAM role.
C.Attach an S3 bucket policy that allows the Glue job role to perform s3:GetObject and s3:PutObject.
D.Add kms:Decrypt and kms:GenerateDataKey permissions to the Glue job's IAM role.
E.Add kms:CreateGrant permission to the Glue job's IAM role.
AnswersB, D

The Glue job's IAM role must have s3:GetObject and s3:PutObject permissions to read and write objects in the S3 bucket. These permissions allow the job to perform the necessary S3 operations. Without them, the job cannot access the bucket regardless of KMS permissions. Together with KMS permissions, they enable full access to the encrypted data.

Why this answer

To allow an AWS Glue job to access an S3 bucket encrypted with SSE-KMS, the job's IAM role must have both S3 permissions (s3:GetObject, s3:PutObject) and KMS permissions (kms:Decrypt, kms:GenerateDataKey). These permissions enable the job to read and write objects and to use the KMS key for encryption and decryption. Other options either do not provide the necessary permissions or would change the encryption method, which is not desired.

Exam trap

The trap here is assuming that S3 permissions alone are sufficient for accessing SSE-KMS encrypted objects, overlooking the need for KMS permissions.

86
MCQeasy

A data engineer needs to grant an IAM user the ability to view Amazon CloudWatch Logs log groups and stream log events from a specific log group. Which IAM policy action should be used?

A.logs:DescribeLogGroups and logs:GetLogEvents
B.logs:PutLogEvents
C.logs:CreateLogGroup
D.logs:DeleteLogGroup
AnswerA

The `logs:DescribeLogGroups` action permits listing and viewing log groups, while `logs:GetLogEvents` retrieves individual log events from a specified log group. Together they satisfy both stated requirements: viewing CloudWatch Logs log groups and streaming log events from the specific log group named in the stem.

Why this answer

Viewing log groups requires logs:DescribeLogGroups, and reading/streaming log events from a specific group requires logs:GetLogEvents (or logs:FilterLogEvents for filtered reads). Together these two actions satisfy the read-only requirement. They map directly to the CloudWatch Logs API calls DescribeLogGroups and GetLogEvents.

Exam trap

DEA-C01 often tests the confusion between read actions (DescribeLogGroups, GetLogEvents, FilterLogEvents) and write/admin actions (PutLogEvents, CreateLogGroup, DeleteLogGroup), catching candidates who pick PutLogEvents thinking it 'streams' logs to a viewer.

How to eliminate wrong answers

Option B is wrong because logs:PutLogEvents is a write action that uploads log events to a stream — it grants no read capability and is used by agents/SDKs sending logs. Option C is wrong because logs:CreateLogGroup only creates new log groups and provides no visibility into existing groups or their events. Option D is wrong because logs:DeleteLogGroup is a destructive administrative action that removes log groups entirely, the opposite of read-only access.

87
MCQmedium

A company stores sensitive data in an Amazon S3 bucket. To comply with regulations, all data must be encrypted at rest using server-side encryption. The security team wants to ensure that any attempt to upload an unencrypted object is automatically denied. Which S3 bucket policy condition should be used?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.s3:x-amz-acl
C.s3:x-amz-server-side-encryption
D.s3:x-amz-storage-class
AnswerC

The `s3:x-amz-server-side-encryption` condition key inspects the `x-amz-server-side-encryption` request header, letting the bucket policy deny any PutObject lacking a server-side encryption algorithm. This directly enforces the stem's requirement that unencrypted uploads be automatically rejected, since requests without that header fail the condition.

Why this answer

The bucket policy condition key s3:x-amz-server-side-encryption matches the x-amz-server-side-encryption request header that S3 requires on PUT requests when server-side encryption is specified. By using a Deny effect with a StringNotEquals condition on this key (or Null check), any PutObject request that does not include the encryption header is rejected before the object is written. This enforces encryption at rest at the API layer, regardless of client behavior.

Exam trap

DEA-C01 often tests the confusion between default bucket encryption (which silently encrypts) and a bucket policy condition that explicitly denies unencrypted PUTs — candidates pick the KMS key ID condition thinking it enforces encryption, but only the base x-amz-server-side-encryption key does.

How to eliminate wrong answers

Option A is wrong because s3:x-amz-server-side-encryption-aws-kms-key-id only validates which KMS key is used when SSE-KMS is specified — it does not require that any encryption header be present, so an unencrypted PUT would still pass. Option B is wrong because s3:x-amz-acl controls canned ACLs (private, public-read, etc.) and has nothing to do with encryption enforcement. Option D is wrong because s3:x-amz-storage-class governs storage tier selection (STANDARD, INTELLIGENT_TIERING, GLACIER) and does not enforce encryption.

88
MCQmedium

A team is designing a data lake on S3 and needs to enforce encryption at rest. They want to use server-side encryption with a KMS key that they manage. Which encryption option should they configure on the S3 bucket?

A.SSE-KMS
B.Client-side encryption
C.SSE-S3
D.SSE-C
AnswerA

SSE-KMS encrypts objects at rest using keys held in AWS KMS, and the customer controls those keys through key policies and grants. This satisfies the requirement for server-side encryption with a customer-managed KMS key on the S3 bucket.

Why this answer

SSE-KMS is the correct choice because it provides server-side encryption using a customer-managed KMS key. This allows the team to enforce encryption at rest with their own key, giving them control over key rotation, access policies, and audit trails via AWS CloudTrail, which aligns with the requirement to manage the encryption key themselves.

Exam trap

The trap here is that candidates often confuse SSE-S3 with SSE-KMS, assuming both use customer-managed keys, but SSE-S3 uses AWS-managed keys and does not provide the customer with key management control or audit capabilities.

How to eliminate wrong answers

Option B (Client-side encryption) is wrong because it encrypts data before it is sent to S3, not at rest on the server side, and does not involve configuring encryption on the S3 bucket itself. Option C (SSE-S3) is wrong because it uses an AWS-managed key, not a customer-managed KMS key, so the team would not have control over key management. Option D (SSE-C) is wrong because it requires the customer to provide their own encryption keys in each request, and the bucket configuration does not manage the key; instead, the key is supplied per-object, which is not a bucket-level encryption setting.

89
Multi-Selectmedium

A company uses AWS CloudTrail to log all API calls. The security team wants to ensure that log files are tamper-proof and cannot be deleted. Which TWO actions should the data engineer take? (Choose TWO.)

Select 2 answers
A.Enable CloudTrail log file validation
B.Enable S3 Object Lock on the S3 bucket
C.Enable MFA Delete on the S3 bucket
D.Enable S3 Versioning on the S3 bucket
E.Enable SSE-KMS encryption on the S3 bucket
AnswersA, B

Enabling CloudTrail log file validation generates a digest file for each log, letting you verify integrity via the AWS CLI. This satisfies the tamper-proof constraint: any modification or deletion of delivered log files is detectable through hash comparison, though it does not itself prevent deletion.

Why this answer

Option A is correct because enabling CloudTrail log file validation generates a digitally signed digest file for each log file, allowing you to verify that logs have not been tampered with or modified after delivery. Option B is correct because S3 Object Lock enforces WORM (Write Once Read Many) protection, preventing log files from being deleted or overwritten for a specified retention period, which directly satisfies the tamper-proof and non-deletable requirement. Option C is not correct because MFA Delete only requires multi-factor authentication for deleting objects or changing versioning state; it adds a control but does not make logs inherently tamper-proof or prevent deletion by an authorized MFA holder.

Option D is not correct because S3 Versioning merely preserves prior versions of objects, so deleted or altered logs can still be removed and versioning alone does not prevent deletion. Option E is not correct because SSE-KMS encryption protects data confidentiality at rest but does not prevent log files from being modified or deleted.

90
MCQhard

A data engineer is building an AWS Glue Data Catalog table that references an Amazon S3 bucket containing CSV files. The security team requires that column-level access be restricted so that only specific IAM principals can view the column containing personally identifiable information (PII). The engineer needs to implement this restriction without modifying the underlying data. Which combination of actions should the engineer take?

A.Create an IAM policy that denies access to the S3 prefix containing the PII column.
B.Use AWS Glue Studio to create a transform that masks the PII column and write a new table.
C.Apply an S3 bucket policy that restricts access to objects based on object tags.
D.Use AWS Lake Formation to define column-level permissions on the table and grant access to the specific IAM principals.
AnswerD

AWS Lake Formation provides fine-grained access control, including column-level permissions, on Data Catalog tables. By registering the S3 location with Lake Formation and defining column-level grants, the engineer can restrict access to the PII column for specific principals. This meets the requirement without altering the data and is the recommended approach for column-level security in Glue Data Catalog.

Why this answer

AWS Lake Formation is designed for fine-grained access control on Data Catalog tables, including column-level permissions. It allows granting or denying access to specific columns for specific IAM principals without changing the data. IAM policies, S3 bucket policies, and Glue transforms operate at different levels and cannot achieve column-level restriction on the existing table.

Exam trap

The trap here is confusing object-level S3 permissions or data masking with column-level access control, which requires Lake Formation.

91
MCQhard

A data engineer needs to share a dataset stored in an Amazon S3 bucket with another AWS account. The dataset must remain encrypted at rest using AWS KMS. The data engineer creates a bucket policy that grants the other account access to the bucket. However, the other account reports that objects appear encrypted and they cannot decrypt them. What is the most likely cause?

A.The KMS key policy does not grant the other account the kms:Decrypt permission
B.The bucket policy does not grant the s3:GetObject permission
C.The other account must use the same KMS key to upload objects
D.The objects are encrypted with SSE-S3, which is not supported for cross-account access
AnswerA

Cross-account access requires permissions on both the S3 bucket policy and the KMS key policy. The bucket policy alone grants object access, but decryption fails because the KMS key policy does not authorise the other account's principals to call kms:Decrypt on that customer-managed key.

Why this answer

For cross-account access to KMS-encrypted S3 objects, both the S3 bucket policy and the KMS key policy must grant the necessary permissions. The bucket policy grants s3:GetObject, but decryption requires kms:Decrypt on the KMS key. If the key policy does not allow the other account, the objects cannot be decrypted, even with S3 access.

Exam trap

DEA-C01 often tests the misconception that S3 bucket policies alone are sufficient for cross-account access to KMS-encrypted objects, ignoring the need for KMS key policy permissions.

How to eliminate wrong answers

Option B is wrong because the scenario states the bucket policy grants access, and the objects appear encrypted, indicating S3 access is working but decryption is failing. Option C is wrong because the other account does not need to use the same KMS key to upload; they need decrypt permission to read. Option D is wrong because SSE-S3 does not use KMS and is not the issue here; the objects are encrypted with KMS (SSE-KMS), and cross-account access is supported with proper key policy.

92
MCQmedium

A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket containing sensitive customer records. The security team requires that the job's data be encrypted at rest using a customer managed AWS KMS key, and that the key policy restrict usage to the specific IAM role used by the Glue job. The engineer has already created the KMS key and attached the necessary IAM policy to the Glue job role. What additional step is required to ensure the Glue job can decrypt the S3 data using the customer managed key?

A.Add a KMS key policy statement granting kms:Decrypt and kms:GenerateDataKey permissions to the Glue job's IAM role.
B.Configure the S3 bucket to use SSE-S3 instead of SSE-KMS, because Glue cannot use customer managed keys.
C.Enable AWS CloudTrail logging for the KMS key to allow Glue to decrypt the data.
D.Attach an S3 bucket policy that grants the Glue job role s3:GetObject and s3:PutObject permissions.
AnswerA

The KMS key policy must explicitly allow the Glue job's IAM role to perform kms:Decrypt and kms:GenerateDataKey. Even if the IAM policy on the role grants these actions, the key policy is the primary access control for KMS keys and must also grant them. Without this, the Glue job will receive an AccessDenied error when attempting to read the encrypted S3 objects.

Why this answer

A customer managed KMS key requires that both the IAM policy of the calling principal and the KMS key policy grant the necessary permissions. The IAM policy alone is insufficient; the key policy must explicitly allow the Glue job's IAM role to use the key for decryption and data key generation. Without this key policy statement, the Glue job cannot decrypt the S3 objects.

Exam trap

The trap here is assuming that an IAM policy granting KMS actions is sufficient, when the KMS key policy must also grant those actions for a customer managed key.

93
MCQmedium

A data engineer is building an AWS Glue job that reads a table from the AWS Glue Data Catalog. The table contains columns with customer names, email addresses, and account numbers. The security team wants the job to mask the last four digits of account numbers in the output while leaving other columns unchanged. Which approach should the data engineer use?

A.Use the AWS Glue DataBrew masking recipe and apply it as a transformation step in the Glue job.
B.Apply a DynamicFrame map transformation and call the PII detection transform on the account number column.
C.Use a DynamicFrame map transformation with a custom function that replaces the account number value with a masked version.
D.Enable column-level encryption on the Data Catalog table definition for the account number column.
AnswerC

A DynamicFrame map transformation applies a user-defined function to each record, allowing the job to rewrite only the account number column while leaving other columns untouched. This gives precise control over the masking logic, such as keeping the last four digits. It runs natively inside the Glue job and produces the required masked output.

Why this answer

Masking specific column values during a Glue ETL run is best done with a map transformation that applies a custom function to each record. This keeps the transformation inside the job, gives full control over the masking logic, and leaves other columns unchanged. PII detection, DataBrew recipes, and column-level encryption do not perform value-level masking in this context.

Exam trap

The trap here is confusing PII detection with PII masking; detection identifies sensitive data but does not alter it.

94
MCQhard

A data engineer is using AWS Lake Formation to manage permissions on a Data Catalog table backed by Amazon S3. Analysts query the table with Amazon Athena. The security team wants analysts to see only rows where the region column equals 'EU' and to prevent them from viewing the customer_id column entirely. Which combination of Lake Formation features should the engineer implement?

A.Use AWS Glue DataBrew to create a project that removes the customer_id column and filters to EU rows, then publish the result as a new table for analysts.
B.Define a Lake Formation data filter with a row filter expression region='EU' and exclude the customer_id column, then grant the analysts SELECT on the table with that filter.
C.Attach a tag-based access control policy to the table that grants access only when the analyst's IAM principal carries a tag matching the region value.
D.Create an IAM policy that allows Athena access only to the S3 prefix containing EU data and deny access to the customer_id column in the Data Catalog.
AnswerB

Lake Formation data filters support both row filter expressions and column inclusion or exclusion. A filter with region='EU' limits visible rows, excluding customer_id hides that column, and granting SELECT with the filter enforces both restrictions for Athena queries. This directly matches the stated row and column requirements.

Why this answer

Lake Formation data filters combine row filter expressions with column selection. A row filter of region='EU' restricts visible rows, and excluding customer_id from the filter removes that column from query results. Granting analysts SELECT on the table through the filter applies both restrictions automatically for Athena and other integrated engines without duplicating or transforming the underlying data.

Exam trap

The trap here is assuming that IAM policies or Lake Formation LF-Tags can filter individual data rows, when row-value filtering requires a data filter with a row expression.

95
MCQeasy

A data engineer receives an alert that an AWS KMS key has been scheduled for deletion by mistake. What is the immediate action to prevent the key from being deleted?

A.Cancel the key deletion from the KMS console or API.
B.Create a new KMS key and re-encrypt the data.
C.Wait for the key to be deleted and restore it from backup.
D.Disable the key immediately to stop usage.
AnswerA

Cancelling the scheduled deletion via the KMS console or API immediately halts the pending deletion window, satisfying the stem's requirement to prevent the key from being destroyed. AWS KMS permits cancellation at any point during the mandatory waiting period, restoring the key to a usable state before permanent deletion occurs.

Why this answer

When a KMS key is scheduled for deletion, the deletion can be canceled from the AWS KMS console or via the CancelKeyDeletion API during the pending deletion period. This immediate action restores the key to its previous state and prevents it from being deleted. Option B is incorrect because creating a new key does not cancel the deletion of the existing key.

Option C is incorrect because deleted KMS keys cannot be restored; the default waiting period of 7–30 days exists specifically to allow cancellation. Option D is incorrect because disabling the key does not affect the deletion schedule.

96
MCQeasy

Refer to the exhibit. An IAM policy is attached to a user. What is the security implication of this policy?

A.The policy only allows read access.
B.The policy is invalid because it uses asterisks.
C.The policy is too restrictive.
D.The policy grants excessive permissions, violating least privilege.
AnswerD

The policy's Action element includes wildcard permissions such as "s3:*" across all resources, so the attached user can perform any S3 operation on every bucket in the account. This exceeds the task's requirement, directly breaching the least-privilege constraint by granting far broader access than necessary.

Why this answer

The policy, which grants full S3 access to all resources, violates the principle of least privilege by providing excessive permissions. Option A is incorrect because the policy does not only allow read access; it allows all actions. Option B is incorrect because the use of asterisks is valid syntax in IAM policies.

Option C is incorrect because the policy is overly permissive, not restrictive.

97
MCQmedium

A company uses AWS Glue to process sensitive data stored in S3. The security team requires that all data be encrypted at rest using customer-managed KMS keys. The data engineers are encountering 'Access Denied' errors when running Glue ETL jobs. What is the most likely cause?

A.The Glue service role does not have kms:Decrypt and kms:Encrypt permissions for the KMS key.
B.The KMS key policy does not allow the AWS Glue service to use the key.
C.The Glue Data Catalog is encrypted with a different KMS key.
D.The S3 bucket policy denies access to the Glue service role.
AnswerA

Correct. The Glue service role must have kms:Decrypt and kms:Encrypt permissions for the KMS key to read/write encrypted data from S3.

Why this answer

To decrypt S3 objects encrypted with a customer-managed KMS key, the AWS Glue job's service role must have kms:Decrypt and kms:Encrypt permissions in its IAM policy, and the KMS key policy must grant that role access. The most likely cause of the Access Denied error is missing KMS permissions on the Glue service role (A). Option B is a possible KMS key policy denial, but it is less likely than missing IAM KMS permissions in this scenario and is not as direct.

Option C is irrelevant because Data Catalog encryption uses a different key and does not prevent S3 object access. Option D would be an S3 bucket policy denial, not a KMS 'Access Denied'; the issue here is KMS permissions.

98
MCQmedium

A data engineer manages an AWS Glue Data Catalog used by Amazon Athena analysts. The security team wants column-level restrictions so that analysts querying a specific table cannot view the values in a cardholder_name column, while still being able to query all other columns. The analysts connect through Athena using an IAM role. Which approach meets this requirement with the LEAST operational overhead?

A.Enable AWS CloudTrail data events on the table and alert when cardholder_name is queried.
B.Create a separate Athena view that omits cardholder_name and grant the analysts access only to that view.
C.Define an IAM policy that denies the glue:GetTable action for the cardholder_name column and attach it to the analysts' role.
D.Create an AWS Lake Formation data filter that excludes the cardholder_name column, then grant the analysts' IAM role SELECT on the table with that data filter applied.
AnswerD

Lake Formation data filters restrict column visibility at the catalog level, so Athena queries referencing the excluded column fail while all other columns remain readable. Granting SELECT with the filter attached enforces the restriction centrally without duplicating tables or rewriting queries, which is the least-overhead method for column-level governance.

Why this answer

Column-level access control in the Glue Data Catalog is provided by Lake Formation data filters, which can include or exclude specific columns and are attached to grants. Granting the analysts' role SELECT with a filter that excludes cardholder_name lets all other columns remain queryable through Athena while the restricted column is inaccessible. IAM policies, views, and CloudTrail do not enforce column-level prevention centrally.

Exam trap

The trap here is assuming IAM policies can restrict access at the column level, when Glue Catalog column restrictions are enforced by Lake Formation data filters attached to grants.

99
MCQmedium

A data engineer manages an AWS Glue ETL job that processes sensitive customer records stored in Amazon S3. The security team mandates that all data at rest in the S3 bucket be encrypted with AWS KMS keys, and that the Glue job have the minimum permissions necessary to read and write data. The engineer creates a KMS key and configures the S3 bucket to use SSE-KMS with that key. Which additional step is required to allow the Glue job to access the encrypted data?

A.Attach an IAM policy to the Glue job's execution role that allows kms:Decrypt and kms:GenerateDataKey on the KMS key.
B.Modify the S3 bucket policy to grant the Glue service principal kms:Decrypt and kms:GenerateDataKey permissions.
C.Enable default encryption on the S3 bucket using SSE-S3 instead of SSE-KMS to avoid KMS permission complexity.
D.Create a VPC endpoint for KMS and attach it to the Glue job's subnet to allow KMS traffic.
AnswerA

The Glue job's execution role must have explicit permissions to use the KMS key for both reading (kms:Decrypt) and writing (kms:GenerateDataKey) encrypted objects. Without these permissions, the job cannot decrypt source data or encrypt output. This is the minimum required step to enable access while adhering to least privilege.

Why this answer

For an AWS Glue job to read and write SSE-KMS encrypted S3 objects, its execution role must have IAM permissions for kms:Decrypt and kms:GenerateDataKey on the specific KMS key. S3 bucket policies do not control KMS key access, and switching encryption types would violate requirements. VPC endpoints address network connectivity, not authorization.

Exam trap

The trap here is assuming that S3 bucket policies or network configurations can grant KMS permissions, when actually KMS key access requires IAM policies or KMS key policies.

100
MCQmedium

An organization wants to audit all API calls made to AWS services for compliance. Which AWS service should be used to capture and store these API calls?

A.AWS CloudTrail
B.AWS Config
C.Amazon VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail records every API call to AWS services as an event, capturing the caller identity, timestamp, source IP and request details, then delivering logs to Amazon S3 for retention. This directly satisfies the compliance audit requirement to capture and store all API activity across the account.

Why this answer

AWS CloudTrail records API activity across AWS services, capturing who made each call, from which IP, when, and with what parameters, and delivers the events to S3 and/or CloudWatch Logs for auditing. It is the canonical service for compliance auditing of API calls. AWS Config, VPC Flow Logs, and CloudWatch Logs serve different observability purposes.

Exam trap

The trap is confusing 'audit API calls' with 'track resource configuration changes' (AWS Config) or 'capture network traffic' (VPC Flow Logs); candidates who do not distinguish control-plane API auditing from configuration history or flow telemetry pick the wrong service.

How to eliminate wrong answers

Option B is wrong because AWS Config records resource configuration state and changes over time, not the API call history itself; it answers 'what does this resource look like now and how did it change,' not 'who called this API.' Option C is wrong because VPC Flow Logs capture IP traffic metadata (source/destination, ports, bytes, accept/reject) at the ENI, subnet, or VPC level, which is network telemetry, not AWS API auditing. Option D is wrong because CloudWatch Logs is a log storage and analysis service; it can receive CloudTrail events but is not itself the audit capture mechanism, and it does not natively record API calls without CloudTrail.

101
MCQeasy

A company needs to encrypt data in transit between an EC2 instance and an S3 bucket. Which method should be used?

A.Use HTTPS endpoints
B.Use plain HTTP
C.Use an IPsec VPN
D.Server-side encryption (SSE)
AnswerA

HTTPS endpoints encrypt traffic using TLS between the EC2 instance and S3, directly satisfying the in-transit encryption requirement. AWS supports HTTPS for all S3 API operations, so requests to the REST endpoint are secured without extra configuration. This protects data crossing the network, unlike at-rest options such as SSE-KMS.

Why this answer

HTTPS endpoints encrypt data in transit between EC2 and S3 using TLS/SSL, ensuring confidentiality and integrity over the public internet. S3 supports HTTPS natively on its REST endpoints, and the AWS SDKs default to HTTPS, making this the simplest and most secure method for encrypting data in motion.

Exam trap

The trap here is confusing encryption in transit (HTTPS) with encryption at rest (SSE), leading candidates to select server-side encryption even though it does not protect data during network transfer.

How to eliminate wrong answers

Option B is wrong because plain HTTP transmits data in cleartext, exposing it to interception and tampering, which violates encryption-in-transit requirements. Option C is wrong because an IPsec VPN encrypts traffic between networks but is unnecessary and overly complex for direct EC2-to-S3 communication, which can be secured via HTTPS without additional infrastructure. Option D is wrong because server-side encryption (SSE) protects data at rest within S3, not data in transit between EC2 and S3.

102
Drag & Dropmedium

Order the steps to migrate an on-premises database to Amazon RDS using AWS DMS.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, create the replication instance. Then configure endpoints, create the migration task, start it, and finally validate the migrated data.

103
MCQmedium

A company stores sensitive customer data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key. However, when a data engineer attempts to upload an object using the AWS CLI, the upload fails with an access denied error. The engineer has s3:PutObject permission on the bucket. Which additional permission is most likely missing?

A.kms:CreateKey
B.kms:Decrypt
C.s3:PutObjectAcl
D.kms:GenerateDataKey
AnswerD

Uploading with a customer-managed KMS key requires kms:GenerateDataKey to obtain a data key for envelope encryption. s3:PutObject alone is insufficient; without that KMS permission, the request fails with AccessDenied even though the S3 action is allowed.

Why this answer

When S3 encrypts an object with SSE-KMS using a customer-managed key, the caller must have kms:GenerateDataKey permission on that KMS key so S3 can obtain a data key to encrypt the object. The s3:PutObject permission alone authorizes the S3 API call but does not grant the KMS operation needed to produce the encryption key, so the upload fails with AccessDenied. Granting kms:GenerateDataKey on the CMK resolves the failure.

Exam trap

DEA-C01 often tests the confusion between encrypt-time and decrypt-time KMS permissions, so the trap is selecting kms:Decrypt for an upload failure when the actual missing permission is kms:GenerateDataKey.

How to eliminate wrong answers

Option A is wrong because kms:CreateKey is only needed to create a new KMS key, not to use an existing customer-managed key for encryption. Option B is wrong because kms:Decrypt is required for reading/decrypting objects, not for uploading/encrypting them — it would be the missing permission for a download failure, not an upload failure. Option C is wrong because s3:PutObjectAcl only controls the ability to set an object's ACL, which is unrelated to KMS encryption and would not cause an encryption-related AccessDenied.

104
MCQeasy

A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that the KMS key can only be used from within the company's VPC. Which policy element should be added to the KMS key policy?

A.Set the Principal element to restrict access to the VPC.
B.Add a condition using aws:SourceIp to allow only IP addresses from the VPC.
C.Add a condition using aws:SourceVpc to allow only requests from the VPC.
D.Add a condition using kms:ViaService to allow only via VPC endpoints.
AnswerC

Adding an `aws:SourceVpc` condition to the KMS key policy restricts key usage to requests originating from the specified VPC endpoint, satisfying the requirement that the key only be usable from within the company's VPC. This condition evaluates the VPC ID of the source, blocking access from outside the VPC.

Why this answer

The correct approach is to add a condition using the aws:SourceVpc condition key in the KMS key policy. This condition evaluates the VPC ID from which the request originates, allowing you to restrict key usage to requests that come through a VPC endpoint within your VPC. When a request is made to KMS through a VPC endpoint, the aws:SourceVpc condition key is populated with the VPC ID, enabling precise control.

This ensures that the KMS key can only be used from within the specified VPC, meeting the security team's requirement.

Exam trap

The trap here is confusing the Principal element with condition keys, or mistakenly using aws:SourceIp or kms:ViaService instead of aws:SourceVpc. Candidates often think that restricting by IP or by service is sufficient to restrict to a VPC, but only aws:SourceVpc directly validates the VPC origin.

How to eliminate wrong answers

Option A is wrong because the Principal element in a policy specifies who (which AWS identities) can access the resource, not from where the request originates; it cannot restrict access based on VPC. Option B is wrong because aws:SourceIp checks the source IP address of the request, which for requests through a VPC endpoint is the private IP of the endpoint, not the VPC itself; moreover, IP addresses can change and are not a reliable way to restrict to a VPC. Option D is wrong because kms:ViaService is used to restrict usage to requests made through specific AWS services (e.g., s3.amazonaws.com), not to restrict to a VPC; it does not validate the VPC origin.

105
Multi-Selecthard

A company wants to implement least privilege access for its data lake on S3. Which THREE practices should be followed? (Choose THREE.)

Select 3 answers
A.Grant s3:* to all users for simplicity
B.Use S3 bucket policies for cross-account access
C.Use S3 access points to enforce network policies
D.Disable S3 Block Public Access to allow flexibility
E.Use IAM policies to grant specific permissions to users and roles
AnswersB, C, E

S3 bucket policies are resource-based and evaluate the bucket owner's permissions, so they grant cross-account principals access without sharing long-lived IAM credentials. This satisfies least privilege by scoping access to specific buckets or prefixes, and by letting the data lake owner retain control over who may read or write.

Why this answer

Option B is correct because S3 bucket policies are resource-based policies that explicitly define which principals (including cross-account identities) may perform which s3: actions on the bucket, allowing tightly scoped cross-account access instead of broad grants. Option C is correct because S3 access points provide dedicated endpoints with their own access point policies and can be restricted to a VPC via network origin controls, enforcing network-level least privilege for data lake access. Option E is correct because IAM policies attached to users and roles grant only the specific S3 actions and resources needed, which is the core mechanism for implementing least privilege.

Option A is incorrect because granting s3:* violates least privilege by allowing all S3 operations. Option D is incorrect because disabling S3 Block Public Access increases exposure risk and does not support least privilege.

106
MCQmedium

A data engineer needs to implement encryption for data at rest in an Amazon S3 bucket that stores sensitive financial records. The company's security policy requires that the encryption keys be managed by the company and rotated annually. The data engineer wants to use AWS Key Management Service (AWS KMS) to meet these requirements. Which solution should the data engineer implement?

A.Use client-side encryption with a customer-provided key stored in AWS Secrets Manager, and manually rotate the key annually.
B.Use server-side encryption with Amazon S3 managed keys (SSE-S3) and enable automatic key rotation.
C.Use server-side encryption with customer-provided keys (SSE-C) and rotate the keys by re-uploading objects with new keys annually.
D.Use server-side encryption with AWS KMS customer managed keys (SSE-KMS) and configure automatic key rotation for the KMS key.
AnswerD

SSE-KMS with customer managed keys allows the company to create and manage KMS keys. AWS KMS supports automatic annual rotation of customer managed keys, which aligns with the security policy. This solution provides the required control over key management and rotation, and it encrypts data at rest in S3 using KMS keys.

Why this answer

SSE-KMS with customer managed keys enables the company to control KMS keys and configure automatic annual rotation. This meets the security policy for company-managed keys and rotation, while providing seamless encryption for S3 objects.

Exam trap

The trap here is confusing SSE-S3 with SSE-KMS; SSE-S3 uses Amazon-managed keys and does not provide customer control over key management or rotation.

107
MCQhard

A data engineer is designing a data lake on Amazon S3 that contains personally identifiable information (PII). The compliance team requires that all access to the data be logged and that any attempt to delete or modify data be detected and alerted. The engineer enables AWS CloudTrail data events for the S3 bucket and configures Amazon CloudWatch alarms. Which additional AWS service should the engineer use to automatically detect and remediate unauthorized changes to the S3 bucket's ACLs or policies?

A.AWS Trusted Advisor with S3 bucket permissions checks.
B.AWS Config with managed rules and automatic remediation.
C.Amazon Macie with custom data identifiers.
D.Amazon GuardDuty with S3 protection.
AnswerB

AWS Config can monitor S3 bucket ACLs and policies for changes, evaluate them against desired configurations, and trigger automatic remediation using AWS Systems Manager Automation documents. This provides continuous detection and enforcement, aligning with the requirement to detect and remediate unauthorized changes.

Why this answer

AWS Config is designed to assess, audit, and evaluate configurations of AWS resources. With managed rules for S3, it can detect changes to ACLs and policies, and trigger automatic remediation via SSM Automation. Other services like Macie, Trusted Advisor, and GuardDuty focus on data classification, recommendations, or threat detection, not configuration compliance and remediation.

Exam trap

The trap here is confusing threat detection or data classification services with configuration compliance and remediation, which are the core capabilities of AWS Config.

108
MCQhard

A data engineer needs to grant an IAM role used by an AWS Lambda function permission to read encrypted data from an Amazon S3 bucket. The data is encrypted with a customer-managed AWS KMS key. The engineer wants to follow the principle of least privilege. Which combination of actions should the engineer include in the IAM policy for the Lambda execution role?

A.s3:GetObject on the bucket and kms:Decrypt on the KMS key.
B.s3:GetObject on the bucket and kms:GenerateDataKey on the KMS key.
C.s3:GetObject on the bucket and kms:CreateGrant on the KMS key.
D.s3:GetObject on the bucket and kms:Encrypt on the KMS key.
AnswerA

To read an encrypted object from S3, the Lambda function needs s3:GetObject permission on the object and kms:Decrypt permission on the KMS key used to encrypt the object. Without kms:Decrypt, S3 cannot decrypt the object for the caller. This combination follows least privilege by granting only the necessary actions for reading the specific data.

Why this answer

The Lambda function requires s3:GetObject to retrieve the object and kms:Decrypt to decrypt the data key used by S3 server-side encryption with KMS. These permissions are the minimal set needed to read the encrypted object. Other KMS actions like Encrypt, GenerateDataKey, or CreateGrant do not provide decryption capability and would not allow the function to read the data.

Exam trap

The trap here is confusing KMS actions, such as using kms:Encrypt or kms:GenerateDataKey instead of kms:Decrypt for reading encrypted data.

109
MCQeasy

A data engineer is using AWS Glue to process data stored in Amazon S3. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has verified that the Glue job uses the AWS Glue Data Catalog and that the S3 bucket policy allows access. What should the engineer do to ensure that the Glue job enforces TLS when reading from and writing to S3?

A.Attach an IAM policy to the Glue job role that denies requests where the aws:SecureTransport condition is false.
B.Configure the Glue job to use the --enable-tls parameter.
C.Enable S3 default encryption on the bucket to enforce TLS.
D.Use an S3 VPC endpoint with a policy that allows only TLS connections.
AnswerA

By attaching an IAM policy that denies S3 actions when aws:SecureTransport is false, any request made over HTTP (non-TLS) will be denied. This enforces TLS for all S3 access, including from AWS Glue. This is a best practice for ensuring encryption in transit. The Glue job will then only be able to access S3 over HTTPS, meeting the security requirement.

Why this answer

To enforce TLS for AWS Glue access to S3, an IAM policy denying requests when aws:SecureTransport is false is the most direct method. This condition key evaluates to true for HTTPS requests and false for HTTP. By denying when false, all non-TLS requests are blocked.

This applies to any principal using the role, including AWS Glue, ensuring encryption in transit.

Exam trap

The trap here is thinking that S3 default encryption or a non-existent Glue parameter enforces TLS, when the correct approach is an IAM policy condition on aws:SecureTransport.

110
MCQeasy

A company is using Amazon S3 to store log files. The security team requires that all data be encrypted in transit. Which of the following ensures encryption in transit for S3?

A.Use HTTPS (SSL/TLS) when accessing S3 endpoints.
B.Use Amazon S3 Transfer Acceleration.
C.Enable client-side encryption before uploading to S3.
D.Use server-side encryption with S3 managed keys (SSE-S3).
AnswerA

HTTPS (SSL/TLS) encrypts data between the client and S3 endpoints, directly satisfying the in-transit encryption requirement. Server-side encryption options such as SSE-S3 or SSE-KMS protect data at rest only, leaving network traffic exposed. Enforcing TLS via bucket policies that deny non-secure transport further guarantees this.

Why this answer

Encryption in transit for Amazon S3 is ensured by using HTTPS (SSL/TLS) when accessing S3 endpoints. HTTPS encrypts data as it travels between the client and S3, protecting it from eavesdropping. This is the standard method to enforce encryption in transit for S3, and it can be enforced via bucket policies that deny requests not using HTTPS.

Exam trap

DEA-C01 often tests the confusion between encryption at rest and encryption in transit, leading candidates to select server-side encryption options that only protect data at rest.

How to eliminate wrong answers

Option B is wrong because Amazon S3 Transfer Acceleration speeds up uploads by using AWS edge locations, but it does not provide encryption in transit; it still relies on HTTPS for encryption. Option C is wrong because client-side encryption encrypts data at rest before uploading, but it does not encrypt data in transit; the data is already encrypted when it leaves the client, but the transmission itself may not be secure unless HTTPS is used. Option D is wrong because server-side encryption with S3 managed keys (SSE-S3) encrypts data at rest, not in transit; it does not protect data during transmission.

111
MCQhard

A data engineer is designing a data lake on Amazon S3. The compliance team requires that objects be automatically deleted after 7 years. Additionally, objects must be transitioned to Amazon S3 Glacier Instant Retrieval after 30 days to reduce costs. Which S3 lifecycle policy configuration meets these requirements?

A.Transition to Glacier Instant Retrieval after 30 days, then expire after 90 days.
B.Transition to Glacier Instant Retrieval after 30 days, then expire after 2555 days.
C.Transition to Glacier Deep Archive after 30 days, then expire after 7 years.
D.Transition to S3 Standard-IA after 30 days, then expire after 7 years.
AnswerB

The lifecycle rule transitions objects to Glacier Instant Retrieval at day 30, meeting the cost requirement, and expires them at day 2555, which equals seven years. Both the transition and retention constraints in the stem are satisfied by this single rule.

Why this answer

The requirement is to transition objects to Glacier Instant Retrieval after 30 days and delete them after 7 years. 7 years equals 2555 days (7 × 365). Option B correctly specifies transition after 30 days and expiration after 2555 days. This meets both the cost optimization and compliance retention requirements.

Exam trap

The trap is miscalculating 7 years in days (2555) or confusing Glacier Instant Retrieval with Glacier Deep Archive, leading to wrong storage class or expiration values.

How to eliminate wrong answers

Option A is wrong because expiring after 90 days does not meet the 7-year retention requirement. Option C is wrong because it transitions to Glacier Deep Archive instead of Glacier Instant Retrieval, and Deep Archive has retrieval times of hours, not instant. Option D is wrong because it transitions to S3 Standard-IA instead of Glacier Instant Retrieval, which does not meet the specified storage class requirement.

112
MCQhard

A data engineer needs to share a dataset stored in an S3 bucket with a partner AWS account. The partner should be able to read the data without needing to authenticate with the engineer's account. The engineer must not share any secret keys. Which approach should be used?

A.Write a bucket policy that grants access to the partner account's IAM role.
B.Generate presigned URLs and share them with the partner.
C.Make the bucket publicly readable.
D.Create an IAM user with access keys and share them with the partner.
AnswerA

A bucket policy granting the partner account's IAM role read access satisfies the cross-account, credential-free requirement: the partner's principals assume their own roles, and AWS evaluates the resource-based policy, so no secret keys or authentication in the engineer's account are needed.

Why this answer

A bucket policy granting read access to the partner account's IAM role is the correct approach because it enables cross-account access without sharing credentials. The partner's IAM role assumes its own identity, and the bucket policy explicitly authorizes that principal, so no secret keys are exchanged. This is the standard AWS cross-account access pattern for S3 data sharing.

Exam trap

DEA-C01 often tests whether candidates default to presigned URLs or public buckets for cross-account sharing, when the correct pattern is a bucket policy granting the partner principal access without credential sharing.

How to eliminate wrong answers

Option B is wrong because presigned URLs are time-limited and tied to the signer's credentials; they are unsuitable for ongoing dataset access and expire, requiring regeneration. Option C is wrong because making the bucket publicly readable exposes data to the entire internet, violating least privilege and likely compliance requirements. Option D is wrong because sharing IAM user access keys violates AWS best practices, cannot be audited per-user, and creates long-lived credentials that are hard to rotate.

113
MCQeasy

A data engineer needs to audit all AWS KMS key usage events for the past 90 days to verify compliance. Which AWS service should be used?

A.VPC Flow Logs
B.AWS CloudTrail
C.AWS Config
D.Amazon Inspector
AnswerB

AWS CloudTrail records KMS API calls such as Encrypt, Decrypt and GenerateDataKey, capturing the identity, timestamp and key involved. This gives the 90-day audit trail of key usage events needed to verify compliance, which KMS alone does not provide.

Why this answer

(AWS CloudTrail). AWS CloudTrail logs all API calls made to AWS KMS, including key usage events, and retains event history for the past 90 days by default, making it suitable for auditing. Option A (VPC Flow Logs) captures network traffic, not API calls.

Option C (AWS Config) tracks resource configuration changes, not API calls. Option D (Amazon Inspector) performs vulnerability assessments, not API logging.

114
MCQmedium

A data engineer is setting up cross-account access to an encrypted S3 bucket. The bucket uses a customer-managed KMS key. The engineer has configured the bucket policy and the IAM role in the source account. The target account still gets access denied errors when trying to read objects. What is the most likely cause?

A.The KMS key policy does not grant the target account's IAM role the kms:Decrypt permission.
B.The S3 bucket has Object Ownership set to BucketOwnerPreferred.
C.The bucket policy does not allow the target account's root user.
D.The VPC Endpoint policy blocks access from the target account.
AnswerA

S3 access to KMS-encrypted objects requires permissions on both the bucket policy and the KMS key policy. Because the key is customer-managed, its key policy must explicitly grant the target account's IAM role kms:Decrypt; otherwise KMS denies the request despite correct IAM and bucket configuration.

Why this answer

For cross-account access to an S3 bucket encrypted with a customer-managed KMS key, the KMS key policy must explicitly grant the target account's IAM role the kms:Decrypt permission. Without this, the target account will get access denied errors even if the bucket policy and IAM role are correctly configured. Option B is incorrect because Object Ownership does not affect cross-account read access.

Option C is incorrect because the bucket policy only needs to allow the target account's IAM role, not the root user. Option D is incorrect because VPC Endpoint policies are not relevant to this cross-account access issue.

115
MCQhard

A data engineer stores raw customer records in an Amazon S3 bucket and runs an AWS Glue job that writes curated Parquet files to a second bucket. The governance team requires that the curated data carry a verifiable record of which job run produced it and that any modification to a curated file be detectable. The engineer must also prove that the curated dataset has not been altered since a nightly baseline. Which combination of AWS features should the engineer use?

A.Enable AWS CloudTrail data events on the curated bucket and use AWS Glue job bookmarks to record the last processed run in the Data Catalog.
B.Compute an SHA-256 checksum per curated file, store the checksums and Glue job run IDs in a manifest, and use that manifest to verify the files against the nightly baseline.
C.Enable S3 Versioning on the curated bucket and configure an S3 event notification to write each version ID to an Amazon DynamoDB table keyed by the Glue job run ID.
D.Enable S3 Object Lock in governance mode on the curated bucket and attach a retention period equal to the nightly baseline interval.
AnswerB

A per-file SHA-256 checksum recorded alongside the Glue job run ID gives both provenance and tamper evidence. Recomputing checksums and comparing them with the stored manifest detects any byte-level change to a curated file, and the run ID ties each file to the job execution that produced it, which is exactly what the governance team requires.

Why this answer

Provenance and tamper evidence require linking each curated file to the job run that created it and being able to prove the bytes have not changed. A manifest that pairs a Glue job run ID with a per-file SHA-256 checksum delivers both. Comparing the nightly recomputed checksums against the baseline manifest surfaces any alteration, while versioning, CloudTrail, and Object Lock address adjacent concerns but not content integrity.

Exam trap

The trap here is treating S3 Versioning or CloudTrail logging as proof of integrity, when only a content digest compared against a trusted baseline can reveal that file bytes were altered.

116
MCQhard

A data engineer manages an AWS Lake Formation governed data lake. Analysts query tables through Amazon Athena and must see only rows where the region column equals their assigned region, while column-level restrictions must also hide a national ID column. The engineer grants table SELECT to the analysts' IAM role in Lake Formation. What should the engineer configure next?

A.Attach an IAM policy to the analysts' role that denies access to the national ID column and uses a condition on the region tag.
B.Create separate Athena views for each region and revoke direct table access, relying on view definitions for the row and column limits.
C.Enable Amazon Athena workgroup query result reuse and rely on Athena to mask the national ID column automatically.
D.Create a Lake Formation data filter that includes a row filter expression on region and excludes the national ID column, then grant SELECT with that data filter to the role.
AnswerD

Lake Formation data filters support both row-level filter expressions and column inclusion or exclusion in a single grant. Granting SELECT with the data filter applies the row predicate and hides the excluded column for that principal, which is exactly the granular control the scenario requires without duplicating tables.

Why this answer

Lake Formation data filters are the mechanism for combining row-level expressions with column inclusion or exclusion in a single SELECT grant. Granting the filter to the analysts' IAM role enforces both restrictions on the governed table, so analysts see only their region rows and never the national ID column, without duplicating tables or views.

Exam trap

The trap here is believing that IAM policies can enforce row or column restrictions on Lake Formation tables, when those controls live in Lake Formation grants.

117
MCQhard

A company needs to share a dataset stored in an S3 bucket with a partner account. The dataset contains sensitive information, so the company wants to ensure that the partner account can only access the data using a specific VPC endpoint in the partner's account. Which S3 bucket policy condition key should be used?

A.aws:SourceVpc
B.aws:SourceArn
C.aws:SourceIp
D.aws:SourceVpce
AnswerD

The `aws:SourceVpce` condition key restricts access to requests arriving through a named VPC endpoint, satisfying the requirement that the partner reach the bucket only via their specific endpoint. Because it evaluates the endpoint ID itself, requests from any other endpoint or the public internet are denied, even if the partner's IAM permissions allow S3 access.

Why this answer

The aws:SourceVpce condition key restricts access to a specific VPC endpoint, ensuring the partner can only access the data through that endpoint. Option A is wrong because aws:SourceVpc restricts to a VPC, not a VPC endpoint. Option B is wrong because aws:SourceArn restricts to a resource ARN, not a network endpoint.

Option C is wrong because aws:SourceIp restricts to an IP address, which does not meet the requirement.

118
Multi-Selectmedium

A company uses S3 to store sensitive data. Which TWO S3 features can be used to protect data at rest?

Select 2 answers
A.S3 Versioning
B.Server-Side Encryption with S3 Managed Keys (SSE-S3)
C.Server-Side Encryption with AWS KMS (SSE-KMS)
D.S3 Transfer Acceleration
E.S3 Object Lock
AnswersB, C

SSE-S3 encrypts objects at rest using AES-256, with Amazon S3 managing the key material and rotation automatically. This satisfies the stem's data-at-rest protection requirement without the company provisioning or maintaining keys in AWS KMS, removing key-management overhead entirely.

Why this answer

SSE-S3 (option B) is correct because it encrypts objects at rest using AES-256 with keys fully managed by Amazon S3, directly protecting stored data without any customer key management. SSE-KMS (option C) is also correct because it encrypts objects at rest using AWS KMS customer master keys, adding key control, audit trails via CloudTrail, and separation of duties. S3 Versioning (A) only keeps multiple variants of an object to aid recovery; it does not encrypt data.

S3 Transfer Acceleration (D) speeds up uploads/downloads over AWS edge locations and is a transfer optimization, not encryption at rest. S3 Object Lock (E) enforces WORM retention to prevent deletion or modification, which is immutability, not encryption.

119
MCQhard

A data engineer manages an AWS Glue Data Catalog shared across teams. Analysts in one team must be able to query only the sales database and its tables, while another team owns the marketing database. The engineer wants permissions managed centrally in Lake Formation and wants the analysts to be able to create their own temporary tables but not alter the sales tables. Which combination of Lake Formation grants should the engineer apply?

A.Grant ALL on the sales database to the analysts and rely on IAM policies to restrict which tables they can alter.
B.Grant SELECT on the sales tables and DESCRIBE on the sales database, and grant ALL on the marketing database to the analysts.
C.Grant DESCRIBE and SELECT on the sales database and tables, and grant ALTER on the sales database so analysts can create temporary tables there.
D.Grant DESCRIBE and SELECT on the sales database and its tables to the analysts, and grant CREATE_TABLE on a separate scratch database for their temporary tables.
AnswerD

Granting DESCRIBE and SELECT on the sales database and tables lets analysts discover and query that data without altering it, since ALTER and DROP are separate permissions not granted. CREATE_TABLE on a dedicated scratch database allows them to build temporary tables without touching the sales database. This least-privilege combination satisfies both query access and safe self-service while keeping marketing data inaccessible.

Why this answer

Least privilege in Lake Formation separates read permissions from modification and creation rights. DESCRIBE and SELECT on the sales database and tables allow discovery and querying, while withholding ALTER and DROP prevents changes to production tables. CREATE_TABLE on a dedicated scratch database lets analysts build temporary tables safely, keeping marketing data and the sales schema protected and centrally governed.

Exam trap

The trap here is granting ALL or ALTER on a database to enable temporary tables, which also hands analysts the ability to modify or drop production tables.

120
MCQeasy

A data engineer wants to ensure that only users with a specific tag (e.g., "Department": "DataEngineering") can access an S3 bucket. How can this be enforced?

A.Use a bucket policy with aws:PrincipalTag condition
B.Use S3 object tags and a bucket policy condition
C.Attach an IAM policy to each user with the tag
D.Use S3 Object Lambda to check user tags
AnswerA

A bucket policy with the `aws:PrincipalTag` condition key evaluates the tag attached to the calling principal's identity, so only users tagged `Department: DataEngineering` satisfy the condition and gain access. This directly enforces the stem's tag-based restriction at the resource, without relying on group membership or role naming.

Why this answer

S3 bucket policies support condition keys like aws:PrincipalTag, which allow access control based on tags attached to IAM principals (users or roles). Option A is correct because it uses aws:PrincipalTag in the bucket policy to restrict access to users with the specific tag. Option B is incorrect because S3 object tags are for objects, not principals, and cannot be used to filter users.

Option C is incorrect because attaching an IAM policy to each user is less scalable and does not leverage the bucket policy's centralized control. Option D is incorrect because S3 Object Lambda is for modifying data during retrieval, not for access control decisions.

Exam trap

Be careful not to confuse principal tags with resource tags. The condition 'aws:PrincipalTag' checks the requester's IAM user/role tags, while 's3:ExistingObjectTag' checks tags on the S3 object itself. This question tests the distinction.

121
MCQhard

A company uses Amazon RDS for PostgreSQL with encryption at rest using AWS KMS. The company needs to share a database snapshot with a different AWS account. What must be done to allow the target account to restore the snapshot?

A.Copy the snapshot to the target account's region and share it
B.Create an IAM role in the source account that allows cross-account snapshot access
C.Share the snapshot and update the KMS key policy to allow the target account to use the key
D.Disable encryption on the snapshot before sharing
AnswerC

Sharing an encrypted RDS snapshot requires the target account to decrypt it, so the KMS key policy must grant that account kms:Decrypt and kms:CreateGrant. Without this key-policy change, the shared snapshot cannot be restored, because the target account lacks permission to use the customer-managed key.

Why this answer

Cross-account snapshot sharing of an encrypted snapshot requires both sharing the snapshot and granting the target account permission to use the KMS key via the key policy. Option A is incorrect because copying does not grant the necessary key access. Option B is incorrect because IAM roles are not used for this purpose; KMS key policies are the mechanism for cross-account access.

Option D is incorrect because encryption cannot be disabled on an existing encrypted snapshot.

122
MCQmedium

A data engineer is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team requires that all data be encrypted at rest and that the job use a customer-managed KMS key for encryption. The engineer configures the job with `--encryption-type sse-kms` and a KMS key ID. However, the job fails with an access denied error when writing to S3. The IAM role used by the Glue job has permissions to read and write the S3 buckets but has no KMS permissions. Which additional IAM permissions are required for the Glue job role to successfully write encrypted data?

A.kms:Decrypt and kms:DescribeKey on the KMS key
B.kms:ReEncryptFrom and kms:ReEncryptTo on the KMS key
C.kms:CreateGrant and kms:ListKeys on the KMS key
D.kms:Encrypt and kms:GenerateDataKey on the KMS key
AnswerD

When Glue writes data to S3 using SSE-KMS, the service must call AWS KMS to generate a data key and encrypt it. The Glue job role needs kms:Encrypt and kms:GenerateDataKey permissions on the customer-managed KMS key. Without these, the write operation fails with access denied. These permissions allow the job to encrypt the data key and use it for SSE-KMS.

Why this answer

To write data to Amazon S3 with SSE-KMS, the Glue job role must have permissions to use the KMS key for encryption. Specifically, kms:Encrypt and kms:GenerateDataKey are required to create and encrypt the data key used for server-side encryption. Without these, the S3 PutObject operation fails with access denied.

The other options either relate to reading (Decrypt) or administrative tasks (CreateGrant, ReEncrypt) that do not satisfy the encryption requirement for writing.

Exam trap

The trap here is assuming that S3 write permissions alone are sufficient for SSE-KMS encryption, forgetting that the KMS key policy and IAM role must also grant encryption permissions.

123
MCQmedium

A data engineer is responsible for an Amazon Redshift cluster that stores financial data. The security team requires that all connections to the cluster from outside the VPC use SSL, and that the cluster's audit logs capture connection and user activity. The engineer has already enabled audit logging to Amazon S3. Which additional configuration should the engineer apply to meet the SSL requirement?

A.Set the Redshift cluster parameter 'require_ssl' to true in the parameter group associated with the cluster.
B.Attach an IAM policy to the Redshift cluster that denies connections without the 'aws:SecureTransport' condition.
C.Create a VPC endpoint for Redshift and require that all clients use the endpoint's private IP address.
D.Enable Redshift Spectrum and configure it to use SSL for all external table access.
AnswerA

The require_ssl parameter in a Redshift parameter group enforces SSL for all connections to the cluster. When set to true, clients that do not use SSL are rejected. This is the standard cluster-level setting for meeting encryption-in-transit requirements, and it applies to connections from outside the VPC as well as inside, ensuring consistent enforcement.

Why this answer

The require_ssl parameter in the Redshift parameter group is the correct way to enforce SSL for all connections to the cluster. When set to true, any client that attempts to connect without SSL is rejected. This directly meets the security team's requirement for encrypted connections from outside the VPC and works alongside audit logging, which the engineer has already enabled.

Exam trap

The trap here is confusing IAM policies and VPC endpoints with database-level SSL enforcement, when Redshift uses a cluster parameter for this purpose.

124
MCQeasy

A data engineer needs to grant an IAM user access to query a specific table in Amazon Athena, but the user should not be able to view other tables in the same database. Which method should the engineer use?

A.Attach an IAM policy that allows athena:StartQueryExecution and restrict the query by table name
B.Use AWS Lake Formation to grant SELECT permission on the specific table to the user
C.Apply an S3 bucket policy that restricts access to the table's underlying data
D.Create a separate Athena workgroup with a query limit that only allows queries on that table
AnswerB

Lake Formation provides table-level grants within a database, so granting SELECT on the single table lets the user query it while other tables remain inaccessible. Athena alone cannot enforce such granular per-table restrictions through IAM policies.

Why this answer

AWS Lake Formation provides fine-grained access control at the table and column level, so granting SELECT permission on the specific table to the IAM user restricts them to that table while denying access to others in the same database. This is the intended service for table-level Athena permissions. It integrates with the Glue Data Catalog to enforce permissions at query time.

Exam trap

DEA-C01 often tests whether candidates know that IAM policies cannot filter by table name in Athena, so they pick an IAM policy or S3 bucket policy instead of Lake Formation for table-level access control.

How to eliminate wrong answers

Option A is wrong because an IAM policy allowing athena:StartQueryExecution cannot restrict queries by table name — IAM does not evaluate SQL content, so the user could query any table in the database. Option C is wrong because an S3 bucket policy restricts access to the underlying data objects, but Athena queries run under the user's or workgroup's role and the policy cannot express 'this table only' at the SQL level; it also does not prevent metadata access to other tables. Option D is wrong because an Athena workgroup controls query limits, encryption, and output location, not table-level permissions, so it cannot restrict which tables a user can query.

125
MCQmedium

A data engineer is setting up an AWS Glue job that reads from an Amazon Kinesis Data Stream and writes to an Amazon S3 bucket. The security team requires that all data in transit be encrypted using TLS, and that the Glue job must use a VPC endpoint to access Kinesis and S3. Which configuration ensures compliance?

A.Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false, and enable Kinesis Data Stream encryption in transit.
B.Enable default encryption on the S3 bucket and enable Kinesis Data Stream encryption at rest.
C.Configure the Glue job to use a VPC connection and create VPC endpoints for Kinesis and S3 with policies that enforce TLS.
D.Use AWS Glue job bookmarks and enable S3 Transfer Acceleration.
AnswerC

Using a VPC connection for the Glue job and creating VPC endpoints for Kinesis and S3 ensures that traffic goes through the endpoints. Endpoint policies can enforce TLS by denying requests where aws:SecureTransport is false. This meets the requirement for TLS and use of VPC endpoints.

Why this answer

To meet both TLS encryption in transit and VPC endpoint usage, the Glue job must run within a VPC using a VPC connection, and VPC endpoints for Kinesis and S3 must be created with policies that enforce TLS. This ensures all traffic goes through the endpoints and is encrypted. Other options either address only encryption at rest or do not include VPC endpoints.

Exam trap

The trap here is focusing only on encryption at rest or TLS without ensuring the use of VPC endpoints, which is an explicit requirement in the scenario.

126
MCQmedium

A data engineer is building an AWS Lambda function that processes records from an Amazon Kinesis data stream. The Lambda function needs to read from the stream and write processed data to an Amazon S3 bucket. The security team requires that all data in transit be encrypted using TLS, and that the Lambda function authenticate to Kinesis and S3 using temporary credentials. Which combination of configurations should the engineer use?

A.Store long-term IAM user access keys in Lambda environment variables, and use them to sign requests to Kinesis and S3 over HTTPS.
B.Assign an IAM role to the Lambda function with permissions for Kinesis and S3, and use the AWS SDK for Python (Boto3) to read and write data, relying on the SDK's default TLS.
C.Configure the Lambda function to use AWS KMS to encrypt the data before sending it to Kinesis and S3, and use an IAM role for authentication.
D.Use Amazon Cognito identity pools to provide temporary credentials to the Lambda function, and enable TLS on the Kinesis and S3 clients.
AnswerB

Lambda functions assume an IAM role that provides temporary credentials automatically. The AWS SDKs use TLS by default for all service communications, including Kinesis and S3. This setup meets the requirements for temporary credentials and encryption in transit. No additional configuration is needed for TLS; it is enforced by the SDK endpoints.

Why this answer

AWS Lambda functions use an IAM role to obtain temporary credentials automatically. The AWS SDKs, such as Boto3, use TLS for all API calls by default, ensuring encryption in transit. This combination satisfies both the authentication and encryption requirements without manual key management.

Other options either use long-term credentials, confuse encryption at rest with in transit, or use an inappropriate identity service.

Exam trap

The trap here is thinking that TLS must be explicitly configured or that KMS encryption is needed for data in transit.

127
MCQhard

A company has multiple AWS accounts and wants to centrally manage permissions and access to data lakes. They have enabled AWS Organizations and want to use a single set of policies that apply to all accounts. Which policy type should be used at the organization level?

A.IAM policies
B.KMS key policies
C.S3 bucket policies
D.Service control policies (SCPs)
AnswerD

SCPs are the only AWS Organizations policy type that sets permission guardrails inherited by every member account, centrally restricting what principals can do. Applied at the organisation or OU level, they satisfy the requirement for one policy set governing all accounts.

Why this answer

Service Control Policies (SCPs) are used in AWS Organizations to centrally manage permissions across accounts. Option A (IAM policies) are attached to IAM users/roles within an account, not across accounts. Option B (KMS key policies) control access to KMS keys.

Option C (S3 bucket policies) are specific to S3 buckets.

128
Multi-Selectmedium

Which TWO actions should a data engineer take to protect sensitive data in an Amazon S3 bucket from being accessed by unauthorized users? (Select TWO.)

Select 2 answers
A.Create a VPC endpoint for S3
B.Enable S3 server access logging
C.Add a bucket policy with a Deny effect for unauthorized principals
D.Enable AWS CloudTrail for the bucket
E.Enable S3 Block Public Access
AnswersC, E

A bucket policy with a Deny effect explicitly overrides any Allow granted elsewhere, including IAM policies, so unauthorised principals are blocked regardless of other permissions. This directly satisfies the requirement to prevent access by unauthorised users.

Why this answer

Option C is correct because an S3 bucket policy with an explicit Deny effect overrides any Allow in IAM or bucket policies, so it reliably blocks the specified unauthorized principals from accessing the sensitive objects. Option E is correct because S3 Block Public Access settings prevent public ACLs and public bucket policies from exposing the bucket, closing off the most common accidental data-exposure path. Options A, B, and D do not restrict access: a VPC endpoint only controls how traffic reaches S3 (not who is authorized), server access logging only records requests after they occur, and CloudTrail only provides audit logging of API activity rather than preventing unauthorized access.

129
Multi-Selecteasy

A data engineer needs to securely store database credentials for an RDS instance. Which TWO AWS services can be used?

Select 2 answers
A.AWS KMS
B.AWS Secrets Manager
C.AWS IAM
D.AWS CloudFormation
E.AWS Systems Manager Parameter Store
AnswersB, E

AWS Secrets Manager stores and rotates RDS credentials natively, with built-in rotation via Lambda and fine-grained IAM and KMS encryption. It satisfies the requirement to securely store database credentials rather than embedding them in code or configuration files.

Why this answer

AWS Secrets Manager (B) is correct because it is purpose-built to store, rotate, and retrieve secrets such as RDS database credentials, and it natively integrates with RDS for automatic credential rotation. AWS Systems Manager Parameter Store (E) is also correct because it can store database credentials as SecureString parameters, which are encrypted with AWS KMS, allowing the data engineer to retrieve them securely at runtime. AWS KMS (A) only provides encryption keys and cryptographic operations; it does not itself store credentials or secrets.

AWS IAM (C) manages identities, roles, and permissions, not secret values. AWS CloudFormation (D) is an infrastructure-as-code provisioning service and is not designed to store or retrieve database credentials.

Exam trap

DEA-C01 often tests the confusion between KMS (encryption keys) and Secrets Manager/Parameter Store (credential storage), and between IAM (permissions) and actual secret storage services.

130
MCQmedium

A company uses AWS Glue to catalog data in Amazon S3. The data includes personally identifiable information (PII). The security team requires that PII be masked when queried by users who are not data owners. Which AWS service should be used to enforce this requirement?

A.Use Amazon Macie to automatically redact PII from S3 objects.
B.Use IAM policies with condition keys to restrict access based on tags.
C.Use AWS Lake Formation to define column-level security and data masking.
D.Use Amazon S3 Object Lambda to transform data on the fly.
AnswerC

AWS Lake Formation enforces column-level security and data masking through its permissions model, filtering PII columns for non-owner users at query time. This satisfies the requirement that PII be masked for users who are not data owners, without duplicating data or altering the underlying S3 objects.

Why this answer

AWS Lake Formation allows you to define column-level security and data masking policies on tables cataloged in the AWS Glue Data Catalog. You can grant or deny access to specific columns and apply masking to sensitive columns like PII for users who are not data owners, enforcing the requirement at query time. This is the native AWS service for fine-grained access control on data lakes.

Exam trap

DEA-C01 often tests the misconception that Macie or S3 Object Lambda can enforce masking, when Lake Formation is the service designed for column-level security and data masking in a Glue catalog.

How to eliminate wrong answers

Option A is wrong because Amazon Macie identifies and alerts on sensitive data but does not redact or mask PII in S3 objects; it is a discovery and classification service, not an enforcement mechanism. Option B is wrong because IAM policies with condition keys can restrict access to S3 objects based on tags, but they cannot perform column-level masking or redact PII within query results. Option D is wrong because S3 Object Lambda can transform data on the fly, but it requires custom code and does not provide a declarative, centrally managed masking policy like Lake Formation; it is more complex and less integrated with the Glue catalog.

131
MCQmedium

A data engineer is configuring cross-account access so that an analytics AWS account can read objects from a data-lake S3 bucket in a producer account. The objects are encrypted with SSE-KMS using a customer managed key in the producer account. The engineer has already added a bucket policy granting s3:GetObject to the analytics account's IAM role. Reads still fail with AccessDenied. Which additional change is required?

A.Add s3:GetObjectVersion to the analytics role's IAM policy and include the s3:ExistingObjectTag condition in the bucket policy.
B.Enable S3 Block Public Access on the data-lake bucket and re-run the cross-account read.
C.Change the bucket's default encryption to SSE-S3 so that cross-account readers no longer need KMS permissions.
D.Attach an IAM policy to the analytics role allowing kms:Decrypt and kms:DescribeKey, and update the KMS key policy to allow the analytics account role to use the key.
AnswerD

SSE-KMS decryption requires two independent grants: the caller's identity policy must allow kms:Decrypt (and typically kms:DescribeKey), and the KMS key policy must permit that principal to use the key. The bucket policy alone only authorizes the S3 object read. Because the key lives in the producer account, its key policy must explicitly trust the analytics account role, otherwise KMS denies the data key unwrap and S3 returns AccessDenied.

Why this answer

Reading SSE-KMS objects across accounts needs authorization on both sides: the identity must be allowed kms:Decrypt and the KMS key policy must trust that identity. A bucket policy granting s3:GetObject is necessary but not sufficient, because S3 calls KMS to unwrap the object's data key, and KMS independently evaluates its key policy. Both the identity policy and key policy must permit the analytics role.

Exam trap

The trap here is assuming that a bucket policy granting s3:GetObject is enough for cross-account reads, when SSE-KMS also requires identity permissions and key-policy trust.

132
MCQmedium

A data engineer needs to share a dataset stored in Amazon S3 with another AWS account. The bucket policy currently grants access only to the owning account. What is the simplest way to grant cross-account access?

A.Add a bucket policy that grants access to the other account's IAM role
B.Set the object ACL to public-read
C.Use an S3 access control list (ACL) to grant access to the other account
D.Create an IAM role in the other account and attach a policy to it
AnswerA

Adding a bucket policy that names the other account's IAM role as principal grants cross-account access directly, satisfying the requirement to share the S3 dataset without extra infrastructure. S3 evaluates the resource-based policy against the requesting role, so no role switching, trust policy, or intermediate service is needed — the simplest mechanism available.

Why this answer

A bucket policy is the simplest and most direct way to grant cross-account access because it is a resource-based policy attached to the S3 bucket that can explicitly name the other account's IAM role or account ID as a principal. This avoids the need to create roles or modify ACLs, and it works even when ACLs are disabled (the default for new buckets).

Exam trap

DEA-C01 often tests the confusion between ACLs and bucket policies, and the misconception that creating a role in the other account is sufficient — candidates forget that the resource owner must also grant permission via a bucket policy.

How to eliminate wrong answers

Option B is wrong because setting an object ACL to public-read grants access to everyone on the internet, not just the other AWS account, creating a serious security exposure. Option C is wrong because S3 ACLs are legacy access controls that cannot grant permissions to IAM roles in another account — they only support canonical user IDs and predefined groups, and ACLs are disabled by default on modern buckets. Option D is wrong because creating an IAM role in the other account only defines an identity; without a bucket policy or cross-account trust, that role has no permission to access the bucket in the owning account.

133
MCQmedium

A data engineer must give an AWS Lambda function temporary credentials to read objects from a specific Amazon S3 prefix. The function runs in a VPC and accesses S3 through a gateway VPC endpoint. The security team forbids long-lived access keys on the function. What should the data engineer configure?

A.Store an IAM user's access key ID and secret access key in Lambda environment variables and rotate them monthly.
B.Attach an IAM role to the Lambda function with an S3 read policy scoped to the prefix, and add an S3 bucket policy restricting access to the gateway VPC endpoint.
C.Use the Lambda function's reserved concurrency setting to limit access, and allow S3 access through the VPC endpoint policy only.
D.Create an IAM user and store the credentials in AWS Secrets Manager, then call the secret at runtime from Lambda.
AnswerB

Lambda assumes an execution role and receives temporary credentials through the environment, so no static keys are stored. Scoping the policy to the prefix and adding a bucket policy that allows access only through the specified VPC endpoint enforces least privilege and ensures traffic stays on the private path.

Why this answer

Lambda execution roles supply temporary credentials automatically, eliminating static keys while allowing a policy scoped to the required prefix. Combining that with a bucket policy that permits access only through the gateway VPC endpoint keeps the data path private and prevents access from outside the approved network route.

Exam trap

The trap here is assuming that storing credentials in Secrets Manager or environment variables removes the risk of long-lived keys, when only role-based temporary credentials satisfy the requirement.

134
MCQeasy

A data engineer needs to audit data access events in Amazon S3. Which AWS service should be used to record and monitor API calls for S3 buckets?

A.AWS CloudTrail
B.AWS Config
C.Amazon Macie
D.Amazon GuardDuty
AnswerA

AWS CloudTrail records S3 data events such as GetObject and PutObject, capturing the identity, source IP and timestamp of each API call. Enabling data-event logging on the buckets satisfies the audit requirement, which S3 server access logs alone cannot match for API-level detail.

Why this answer

AWS CloudTrail records API activity across AWS services, including S3 data-plane and management-plane events, capturing who made each request, from where, and when. For auditing data access to S3 buckets, CloudTrail (with S3 data events enabled) is the authoritative service. It integrates with CloudWatch Logs and S3 for long-term retention and analysis.

Exam trap

DEA-C01 often tests the confusion between CloudTrail (API audit logging) and AWS Config (configuration compliance tracking), since both provide visibility into account activity but serve fundamentally different purposes.

How to eliminate wrong answers

Option B is wrong because AWS Config evaluates resource configuration compliance and tracks configuration changes over time, but it does not record individual API calls or data-access events. Option C is wrong because Amazon Macie discovers and classifies sensitive data in S3 (e.g., PII) using machine learning; it is a data-security posture tool, not an API audit log. Option D is wrong because Amazon GuardDuty is a threat-detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious behavior — it consumes audit data rather than being the source of it.

135
Matchingmedium

Match each AWS storage class to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Frequent access, low latency

Auto-moves data between tiers

Archive retrieval in minutes to hours

Lowest cost, 12-hour retrieval

Infrequent access, single AZ

Why these pairings

Correct matches: S3 Standard for frequently accessed data, S3 Intelligent-Tiering for automatic cost optimization, and S3 Glacier for archival. Common confusions involve mixing up Standard-IA and Glacier Deep Archive definitions.

136
MCQmedium

A data engineer is configuring an Amazon Redshift cluster to encrypt data at rest. The company policy requires that encryption keys be stored in AWS CloudHSM. Which integration should the engineer use to meet this requirement?

A.Use AWS KMS with a customer managed key.
B.Configure Redshift to use an HSM for encryption.
C.Enable encryption using the AWS Redshift SSL/TLS feature.
D.Use Redshift automatic key rotation.
AnswerB

Configuring Redshift with a hardware security module directly satisfies the CloudHSM key-storage mandate, since Redshift supports HSM connections for at-rest encryption via CloudHSM. This keeps keys inside the dedicated HSM rather than AWS-managed KMS, meeting the policy's explicit key custody constraint.

Why this answer

Amazon Redshift supports encryption at rest using either AWS KMS or a hardware security module (HSM) via CloudHSM. When company policy mandates that encryption keys be stored in AWS CloudHSM, the engineer must configure Redshift to use an HSM connection for encryption, which is the only option that satisfies the CloudHSM key storage requirement.

Exam trap

The trap here is confusing encryption in transit (SSL/TLS) with encryption at rest, and assuming AWS KMS keys are stored in CloudHSM when they are actually stored in AWS-managed HSMs.

How to eliminate wrong answers

Option A is wrong because AWS KMS with a customer managed key stores keys in KMS-managed HSMs, not in the customer's dedicated AWS CloudHSM cluster, so it fails the policy requirement. Option C is wrong because SSL/TLS encrypts data in transit, not data at rest, and does not address key storage. Option D is wrong because automatic key rotation is a key lifecycle feature, not a key storage mechanism, and does not involve CloudHSM.

137
MCQeasy

A company wants to enforce that all data written to an S3 bucket is encrypted with a customer-managed AWS KMS key. The data engineer has created the KMS key and attached an S3 bucket policy. However, users are still able to upload objects without specifying the KMS key. What is the most likely cause?

A.The S3 bucket policy does not include a condition that denies s3:PutObject without the correct encryption
B.The S3 bucket has default encryption enabled with SSE-S3
C.The KMS key policy does not grant the users kms:Encrypt permission
D.The IAM role for the users does not have s3:PutObject permission
AnswerA

The bucket policy lacks a Deny statement with the `s3:PutObject` action and a `StringNotEquals` condition on `s3:x-amz-server-side-encryption` (and the KMS key ARN), so uploads without the customer-managed key are never refused. Without an explicit deny, S3 permits unencrypted or default-encrypted writes despite the policy.

Why this answer

The most likely cause is that the S3 bucket policy does not include a condition that denies s3:PutObject requests unless the correct encryption (e.g., aws:kms with the specific key) is specified. Without an explicit deny condition, users can still upload objects using the default encryption or no encryption if their IAM permissions allow it. The bucket policy must enforce the encryption requirement by denying non-compliant uploads.

Exam trap

DEA-C01 often tests the difference between default encryption and policy-enforced encryption. Candidates may think that enabling default encryption is sufficient, but it only applies when no encryption is specified, so users can still upload without the KMS key if they don't specify encryption.

How to eliminate wrong answers

Option B is wrong because default encryption with SSE-S3 would not prevent users from uploading without specifying a KMS key; it would just encrypt with SSE-S3 if no encryption is specified. Option C is wrong because the KMS key policy granting kms:Encrypt is necessary for users to use the key, but if they are not specifying the key, the issue is not the key policy. Option D is wrong because if the IAM role lacked s3:PutObject, users would not be able to upload at all, not just without the KMS key.

138
MCQeasy

A company stores sensitive financial data in Amazon S3 and requires that all data be encrypted at rest using customer-managed keys. A data engineer configures the S3 bucket to use SSE-KMS with a customer-managed KMS key. The security team now wants to audit all API calls that use the KMS key to decrypt data. Which AWS service should the engineer use to capture and review these KMS API calls?

A.AWS Config
B.AWS Trusted Advisor
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail logs all API activity, including KMS operations such as Decrypt, Encrypt, and GenerateDataKey. By enabling CloudTrail, the engineer can capture and review these calls for auditing. CloudTrail is the standard service for auditing API activity across AWS services.

Why this answer

AWS CloudTrail is the service that records API activity in your AWS account, including KMS operations. By enabling CloudTrail, you can audit who used the KMS key and when. AWS Config, CloudWatch Logs, and Trusted Advisor do not provide the same level of API call logging for KMS.

Exam trap

The trap here is assuming that AWS Config or CloudWatch Logs automatically capture API calls, when actually CloudTrail is the dedicated service for API auditing.

139
MCQeasy

A data engineer needs to restrict access to an S3 bucket so that only users from a specific AWS account can read objects. Which S3 bucket policy element should be used?

A.Action
B.Principal
C.Resource
D.Condition
AnswerB

The Principal element names the AWS account permitted to read objects, directly satisfying the cross-account restriction. Bucket policies evaluate Principal against the requesting identity, so specifying the trusted account's ARN grants access solely to its users, excluding all other accounts.

Why this answer

The Principal element in an S3 bucket policy specifies the AWS account, user, or role that the policy applies to. By setting the Principal to a specific AWS account ID, only users from that account can read objects. Option A is wrong because the Action element specifies the allowed or denied operations (e.g., s3:GetObject), not the account.

Option C is wrong because the Resource element identifies the bucket or objects, not the requester. Option D is wrong because the Condition element adds additional constraints (e.g., IP address), but it is not the primary element for specifying the allowed account; Principal is the correct element for that purpose.

140
Multi-Selecteasy

A company wants to audit API calls made to its Amazon S3 buckets. Which AWS services can be used to achieve this? (Choose TWO.)

Select 2 answers
A.IAM Access Analyzer
B.AWS Config
C.VPC Flow Logs
D.AWS CloudTrail
E.Amazon S3 server access logs
AnswersD, E

AWS CloudTrail records API activity in the account, including S3 management and, with data events, object-level calls. It logs the identity, time and source of each request, providing the API audit trail the company requires.

Why this answer

AWS CloudTrail (D) is correct because it records S3 data events such as GetObject, PutObject, and DeleteObject, providing an audit trail of API calls made to S3 buckets when data events are enabled. Amazon S3 server access logs (E) are also correct because they capture detailed records of requests made to a bucket, including the requester, bucket name, request time, request action, response status, and error code, which directly supports auditing API calls. IAM Access Analyzer (A) is not correct here because it identifies resource policies that grant external access, not a log of API calls.

AWS Config (B) tracks resource configuration changes and compliance, not individual S3 API request activity. VPC Flow Logs (C) capture IP traffic metadata for network interfaces, not S3 API-level operations.

141
MCQmedium

A company stores sensitive data in Amazon S3 and uses AWS KMS customer-managed keys for encryption. The security team wants to monitor and audit all KMS API calls that involve the key, including who used the key and when. They also want to receive alerts if the key is used by an unauthorized principal. Which AWS service should the data engineer use to meet these requirements?

A.Amazon GuardDuty with KMS protection, and AWS Lambda functions to remediate unauthorized access.
B.AWS CloudTrail with KMS key usage logs, and AWS Security Hub for automated alerts on unauthorized access.
C.AWS CloudTrail with KMS key usage logs, and Amazon CloudWatch alarms based on CloudTrail metrics.
D.AWS Config with KMS key configuration rules, and Amazon SNS notifications for noncompliance.
AnswerC

AWS CloudTrail captures all KMS API calls as events, including the identity of the caller, time, and key ID. These events can be delivered to an S3 bucket and also to CloudWatch Logs. By creating metric filters and CloudWatch alarms, you can alert on unauthorized usage patterns. This provides both auditing and alerting, meeting the requirements.

Why this answer

AWS CloudTrail logs all KMS API calls, providing a detailed audit trail. To receive alerts on unauthorized usage, you can create CloudWatch metric filters on CloudTrail logs and set up CloudWatch alarms. This combination meets both the auditing and alerting requirements.

Other services like AWS Config, GuardDuty, or Security Hub do not provide the same level of detailed API call logging and direct alerting for KMS usage.

Exam trap

The trap here is confusing configuration compliance (AWS Config) or threat detection (GuardDuty) with API-level auditing and alerting, which CloudTrail and CloudWatch provide.

142
MCQhard

A company uses AWS Lake Formation to manage access to data in a data lake. A new data engineer has been granted SELECT permission on a table but receives an 'AccessDeniedException' when querying via Amazon Athena. The table is registered in Lake Formation and the data is encrypted with SSE-KMS. Which of the following is the MOST likely cause?

A.The table's resource-based policy does not include the engineer's IAM role.
B.The S3 bucket policy denies access to the engineer's IAM role.
C.The AWS Glue Data Catalog has not been granted permission to the engineer's role.
D.The IAM role used by Athena does not have kms:Decrypt permission on the KMS key.
AnswerD

Lake Formation grants table-level SELECT, but Athena still requires underlying AWS Lake Formation and KMS permissions for encrypted data. Without kms:Decrypt on the SSE-KMS key, Athena cannot read the encrypted objects, producing AccessDeniedException. The stem specifies SSE-KMS encryption, so the missing KMS decrypt permission is the most likely cause.

Why this answer

The IAM role used by Athena does not have kms:Decrypt permission on the KMS key. When data is encrypted with SSE-KMS, Athena's IAM role requires kms:Decrypt to read the data from S3. Even if Lake Formation grants SELECT permission, the query fails without KMS access.

Option A is incorrect because Lake Formation does not use resource-based policies on tables; it uses LF-Tags or resource links to grant permissions. Option B is incorrect because while an S3 bucket policy could block access, the most likely issue with encrypted data is missing KMS permissions. Option C is incorrect because the Glue Data Catalog does not enforce data access; Lake Formation is the service that manages fine-grained access.

143
Multi-Selecthard

A data engineer is building a governed data lake in AWS Lake Formation. The security team wants to detect sensitive data such as credit card numbers in newly registered S3 tables and automatically apply column-level access restrictions to those columns. Which TWO actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Create an EventBridge rule that invokes an AWS Lambda function to apply Lake Formation column-level grants or LF-Tags based on the Macie findings.
B.Enable AWS CloudTrail data events on the S3 bucket and use them to identify objects containing credit card numbers.
C.Use Amazon Macie to run sensitive data discovery jobs against the S3 bucket and publish findings to Amazon EventBridge.
D.Configure an AWS Glue crawler with a custom classifier to detect credit card number patterns and tag the columns in the Data Catalog.
E.Configure S3 Block Public Access on the bucket and require SSE-KMS encryption for all objects.
AnswersA, C

An EventBridge rule matching Macie findings can trigger a Lambda function that calls Lake Formation APIs to restrict columns or attach LF-Tags. This automates the response so newly detected sensitive columns receive restrictive permissions without manual review, satisfying the automatic restriction requirement.

Why this answer

Amazon Macie performs sensitive data discovery on S3 objects and emits findings that can flow through EventBridge, providing the detection layer. A Lambda function triggered by those findings can then apply Lake Formation column-level grants or LF-Tags, automating enforcement so sensitive columns are restricted as data is registered and classified.

Exam trap

The trap here is assuming CloudTrail or Glue classifiers detect sensitive values in object contents, when content inspection belongs to Macie.

144
MCQeasy

A data engineer needs to grant an IAM user read-only access to an S3 bucket named 'data-lake'. Which IAM policy statement should be used?

A.{"Effect":"Allow","Action":["s3:PutObject","s3:DeleteObject"],"Resource":"arn:aws:s3:::data-lake/*"}
B.{"Effect":"Allow","Action":"s3:*","Resource":"*"}
C.{"Effect":"Allow","Action":["s3:ListBucket","s3:GetObject"],"Resource":["arn:aws:s3:::data-lake","arn:aws:s3:::data-lake/*"]}
D.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::data-lake"}
AnswerC

The policy pairs bucket-level `s3:ListBucket` with object-level `s3:GetObject`, mapping each action to the correct ARN: `arn:aws:s3:::data-lake` for the bucket itself and `arn:aws:s3:::data-lake/*` for its objects. This satisfies the read-only requirement, since listing needs bucket scope while retrieval needs object scope.

Why this answer

It allows ListBucket on the bucket and GetObject on objects, enabling read-only access. Option A is wrong because it grants write actions (PutObject, DeleteObject). Option B is wrong because it allows all S3 actions (s3:*).

Option D is wrong because it only allows ListBucket, not GetObject.

145
MCQmedium

A company stores sensitive data in Amazon Redshift. The security team requires that all data in the cluster be encrypted at rest using a customer managed key in AWS KMS, and that the key be rotated annually. The data engineer needs to configure the Redshift cluster accordingly. Which action should the engineer take?

A.Use Redshift Spectrum to query data in S3 that is encrypted with SSE-KMS, and enable key rotation on the S3 bucket's default key.
B.Enable Redshift cluster encryption using AWS KMS and set the cluster parameter require_ssl to true.
C.Enable Redshift cluster encryption using AWS KMS and create a scheduled AWS Lambda function that calls kms:RotateKey on the key annually.
D.Enable Redshift cluster encryption using AWS KMS and select the customer managed key. Configure automatic key rotation for the KMS key with a 365-day rotation period.
AnswerD

Amazon Redshift supports encryption at rest with AWS KMS customer managed keys. When creating or modifying a cluster, you can choose a customer managed key. Separately, in AWS KMS, you can enable automatic rotation for that key with a custom period, such as 365 days. This meets both the encryption and rotation requirements. The key rotation is a property of the KMS key, not the Redshift cluster.

Why this answer

To encrypt a Redshift cluster at rest with a customer managed KMS key, you enable encryption on the cluster and select the key. To rotate the key annually, you enable automatic rotation on that KMS key with a 365-day period. These are separate configurations but together satisfy the requirements.

Exam trap

The trap here is confusing encryption in transit (SSL) with encryption at rest, or assuming that key rotation is configured on the Redshift cluster rather than in KMS.

146
MCQmedium

A company uses AWS Glue to process sensitive customer data stored in S3. The security team requires that all data be encrypted at rest using a customer-managed KMS key and that access to the key be auditable. Which solution meets these requirements?

A.Encrypt the data client-side before uploading to S3.
B.Configure the S3 bucket to use SSE-KMS with a customer-managed KMS key and enable CloudTrail for KMS events.
C.Enable default SSE-S3 encryption on the S3 bucket.
D.Use SSE-C with a customer-provided key.
AnswerB

SSE-KMS with a customer-managed key encrypts S3 objects at rest under your own key policy, satisfying the customer-managed requirement. CloudTrail captures every KMS API call, including Decrypt and GenerateDataKey, delivering the auditable key-access trail the security team demands. SSE-S3 cannot provide either control.

Why this answer

SSE-KMS with a customer-managed KMS key provides encryption at rest and, when combined with CloudTrail logging for KMS events, offers full auditability of key usage. Option A (client-side encryption) does not encrypt data at rest within S3; it encrypts before upload. Option C (SSE-S3) uses AWS-managed keys, which do not allow customer audit of key access.

Option D (SSE-C) relies on customer-provided keys that are not managed by KMS and cannot be audited via CloudTrail.

147
MCQhard

A company has a data lake in Amazon S3 with millions of objects. The security team wants to enforce that all objects are encrypted with a specific customer-managed KMS key. The data engineer configures an S3 bucket policy to deny PutObject if the encryption is not set to that key. However, some existing objects are not encrypted with that key. What is the most efficient way to remediate the existing objects?

A.Use S3 Cross-Region Replication to replicate objects to a new bucket with the correct encryption.
B.Write a script using the AWS SDK to iterate over all objects and re-upload them with the correct encryption.
C.Use S3 Batch Operations to copy objects in the same bucket with the new encryption settings.
D.Use S3 Object Lambda to dynamically encrypt objects on read.
AnswerC

S3 Batch Operations applies a single job across millions of objects, performing a copy-in-place that rewrites each object under the specified KMS key. This remediates existing objects at scale without custom scripts or per-object API calls, meeting the requirement that all objects use the customer-managed key.

Why this answer

S3 Batch Operations is designed to perform bulk actions (like copying objects) across millions of objects efficiently, and it supports specifying new encryption settings during the copy. By copying objects in the same bucket with the desired KMS key, the existing objects are re-encrypted with the customer-managed key, satisfying the bucket policy requirement. This is the most efficient, server-side, managed approach for large-scale remediation.

Exam trap

The trap is choosing a custom SDK script or replication — but S3 Batch Operations is the managed, scalable solution for bulk object remediation, and replication does not fix encryption on existing objects in place.

How to eliminate wrong answers

Option A is wrong because Cross-Region Replication replicates objects to a different bucket/region and does not remediate encryption on existing objects in the current bucket; it also incurs cross-region data transfer costs and does not change the original objects. Option B is wrong because writing a custom SDK script to iterate and re-upload millions of objects is inefficient, error-prone, and requires managing concurrency and throttling — S3 Batch Operations is purpose-built for this. Option D is wrong because S3 Object Lambda transforms data on read for specific use cases (e.g., redaction) and does not change the stored encryption of existing objects.

148
MCQhard

A company uses AWS Lake Formation to manage data lake permissions. The data engineer notices that a user with SELECT permission on a table can also query the underlying data in Amazon S3 directly. How can the engineer enforce that access to the S3 data is only through Lake Formation?

A.Use S3 Access Points with a policy that restricts access to only Lake Formation
B.Grant the user permissions only through Lake Formation and remove any IAM policies that allow direct S3 access to the data location
C.Enable S3 Block Public Access on the bucket
D.Change the S3 bucket policy to deny all access except from Lake Formation
AnswerB

Lake Formation permissions govern only requests routed through Lake Formation; direct S3 GETs are authorised by IAM. Removing IAM policies that permit s3:GetObject on the data location closes that bypass, so the user's only viable path to the data is via Lake Formation's credential vending.

Why this answer

Lake Formation permissions are enforced only when the caller accesses data through a Lake Formation-integrated engine (Athena, Redshift Spectrum, EMR, Glue). If the user also has IAM permissions on the underlying S3 path, they can bypass Lake Formation entirely by reading S3 directly. The fix is to remove those direct S3 IAM permissions so the only path to the data is through Lake Formation-governed services.

Exam trap

The trap is assuming that granting Lake Formation permissions automatically overrides or supersedes IAM — in reality IAM and Lake Formation are additive, and any direct S3 IAM allow defeats LF governance.

How to eliminate wrong answers

Option A is wrong because S3 Access Points do not by themselves prevent a user with existing IAM s3:GetObject permissions on the bucket from reading the data; they add an access path, not a restriction. Option C is wrong because S3 Block Public Access only blocks public/anonymous access and does nothing about an authenticated IAM principal with explicit allow. Option D is wrong because a bucket policy denying all except Lake Formation would also break other legitimate access and is not how Lake Formation enforcement is designed — Lake Formation uses its own permission model layered on top of IAM, not a blanket bucket-policy deny.

149
MCQhard

A company is using Amazon EMR to process data stored in Amazon S3. The S3 bucket is configured with a bucket policy that denies access unless the request includes a specific tag. The EMR cluster's IAM role has s3:GetObject permission. However, the EMR job fails to read data from S3. What is the most likely cause?

A.The bucket policy is not attached to the EMR role.
B.The EMR cluster is not in the same account as the S3 bucket.
C.The IAM role does not have a condition that matches the required tag.
D.The EMR role does not have s3:GetObject permission.
AnswerC

The bucket policy requires a tag, and the role must have a matching condition.

Why this answer

The bucket policy denies access unless the request includes a specific tag. Even though the EMR cluster's IAM role has s3:GetObject permission, the IAM role does not have a condition key (e.g., aws:RequestTag) that matches the required tag. Therefore, the request is denied by the bucket policy, causing the EMR job to fail.

Exam trap

AWS often tests the interaction between IAM policies and S3 bucket policies, specifically that a bucket policy with a deny condition can override IAM permissions, and candidates mistakenly think the issue is missing IAM permissions rather than a missing condition in the request.

How to eliminate wrong answers

Option A is wrong because bucket policies are attached to the S3 bucket, not to IAM roles; the policy is already configured on the bucket. Option B is wrong because cross-account access is possible with proper permissions, and the question does not indicate a different account; the failure is due to the tag condition, not account mismatch. Option D is wrong because the question explicitly states the IAM role has s3:GetObject permission, so the failure is not due to missing permission.

150
MCQhard

A company is using Amazon EMR with Kerberos authentication. They want to ensure that data in transit between EMR cluster nodes is encrypted. Which configuration should be applied?

A.Use VPC peering to connect the cluster nodes.
B.Configure the EMR cluster to use in-transit encryption.
C.Enable S3 server-side encryption for the cluster's output data.
D.Enable EBS encryption on the cluster instances.
AnswerB

EMR security configurations enable in-transit encryption using TLS for inter-node communication, plus encryption of data within the cluster. This satisfies the requirement to encrypt data moving between EMR cluster nodes, which at-rest encryption and Kerberos alone do not provide.

Why this answer

In-transit encryption on Amazon EMR is enabled through a security configuration that specifies a PEM certificate and, optionally, a TLS certificate provider, which encrypts traffic between cluster nodes and to the EMR service. This is the only option that directly addresses data in transit between nodes.

Exam trap

The trap is confusing encryption at rest (EBS, S3 SSE) with encryption in transit; candidates often pick EBS or S3 encryption because they sound like security controls but do not secure node-to-node traffic.

How to eliminate wrong answers

Option A is wrong because VPC peering only provides network connectivity between VPCs; it does not encrypt traffic. Option C is wrong because S3 server-side encryption protects data at rest in S3, not data moving between EMR nodes. Option D is wrong because EBS encryption protects volumes at rest on the cluster instances, not network traffic.

← PreviousPage 2 of 4 · 246 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Data Security and Governance questions.