Courseiva
Data Ingestion and TransformationmediumMatchingObjective-mapped

DEA-C01 Data Ingestion and Transformation Practice Question

Match each AWS security service to its purpose in data protection.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Managed encryption keys

User and role access control

Audit API activity

Discover and protect sensitive data

Web application firewall

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS KMS: Manage encryption keys for data at rest and in transit

The correct matches are: AWS KMS for encryption key management, AWS IAM for access control, and AWS CloudTrail for API auditing. Common confusions include swapping these services' purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS KMS: Manage encryption keys for data at rest and in transit

    Why this is correct

    AWS KMS (Key Management Service) is used to create and manage encryption keys that protect data at rest and in transit.

  • AWS IAM: Control access to AWS resources through users, groups, and roles

    Why this is correct

    AWS IAM (Identity and Access Management) enables you to control access to AWS services and resources by creating users, groups, and roles with specific permissions.

  • AWS CloudTrail: Record API calls for auditing and compliance

    Why this is correct

    AWS CloudTrail records API activity in your account, providing audit logs for security analysis, compliance, and operational troubleshooting.

  • AWS KMS: Control access to AWS resources through users, groups, and roles

    Why it's wrong here

    Incorrect — AWS KMS is not used for access control; it manages encryption keys. Access control is the function of AWS IAM.

  • AWS IAM: Manage encryption keys for data at rest and in transit

    Why it's wrong here

    Incorrect — AWS IAM does not manage encryption keys; it controls access. Encryption key management is done by AWS KMS.

  • AWS CloudTrail: Manage encryption keys for data at rest and in transit

    Why it's wrong here

    Incorrect — AWS CloudTrail records API calls, not key management. Key management is the role of AWS KMS.

About these practice questions

One of 1,711 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.