Courseiva

CCNA Data Security Governance Questions

75 of 246 questions · Page 1/4 · Data Security Governance topic · Answers revealed

1
MCQmedium

A data engineer is configuring an AWS Glue job that reads from an Amazon RDS for MySQL database and writes to Amazon S3. The security team requires that the data be encrypted in transit between AWS Glue and Amazon RDS. Which action should the engineer take to meet this requirement?

A.Attach an IAM policy to the Glue job role that allows rds:DescribeDBInstances and rds:Connect, which enforces SSL.
B.Configure the AWS Glue connection to use SSL by setting the JDBC URL with the sslMode=REQUIRED parameter and providing the RDS root certificate.
C.Use AWS Glue's built-in encryption context to encrypt the data before writing to RDS.
D.Enable encryption at rest on the RDS instance, which automatically encrypts data in transit as well.
AnswerB

For JDBC connections to RDS for MySQL, encryption in transit is enabled by setting sslMode=REQUIRED in the JDBC URL and providing the RDS CA certificate for validation. This ensures that the connection between AWS Glue and RDS is encrypted using SSL/TLS. This is the standard method to enforce encryption in transit for Glue JDBC connections.

Why this answer

To encrypt data in transit between AWS Glue and Amazon RDS for MySQL, the JDBC connection must be configured to use SSL. Setting sslMode=REQUIRED in the JDBC URL and providing the RDS root certificate ensures that the connection is encrypted and the server certificate is validated. This is the correct approach for meeting the encryption in transit requirement.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, or assuming that IAM policies can enforce SSL for database connections.

2
MCQmedium

A data engineer manages an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another S3 bucket. Both buckets are encrypted with SSE-KMS using customer managed keys. The Glue job execution role has permissions to read from the source bucket and write to the target bucket, and has kms:Decrypt permission on the source key, but the job fails with an error indicating it cannot write to the target bucket due to encryption. What is the MOST likely cause?

A.The Glue job execution role lacks kms:GenerateDataKey permission on the target bucket's KMS key.
B.The Glue job execution role lacks s3:PutObjectAcl permission on the target bucket.
C.The target S3 bucket's default encryption uses SSE-S3 instead of SSE-KMS, causing a conflict.
D.The Glue job execution role lacks kms:Decrypt permission on the target bucket's KMS key.
AnswerA

When writing to an SSE-KMS encrypted S3 bucket, the writer must call kms:GenerateDataKey to obtain a data key for encryption. Without this permission, the write fails. The role already has read access and decrypt permission on the source key, but the target key requires GenerateDataKey to encrypt the data.

Why this answer

Writing to an SSE-KMS encrypted S3 bucket requires the kms:GenerateDataKey permission on the KMS key used for the target bucket. The Glue job role already has read and decrypt permissions on the source, but lacks the necessary permission to encrypt data for the target. Without GenerateDataKey, the S3 PutObject operation fails.

Exam trap

The trap here is assuming that kms:Decrypt is sufficient for both reading and writing encrypted data, when in fact writing requires kms:GenerateDataKey.

3
MCQhard

A data engineer notices that an S3 bucket policy allows access to a user from another AWS account, but the access is being denied. What could be the reason?

A.The bucket policy does not include KMS permissions
B.The other account's IAM user does not have permissions to access the bucket
C.S3 does not support cross-account access
D.The bucket is in a different region
AnswerB

Cross-account S3 access requires both the bucket policy to allow the principal and the principal's own IAM identity policy to permit the S3 action. The bucket policy alone is insufficient, so the missing identity-based permission causes the denial.

Why this answer

For cross-account S3 access to succeed, both the bucket policy (resource-based policy) and the IAM user policy (identity-based policy) in the other account must grant the necessary permissions. Option B is correct because even if the bucket policy allows access from the other account, the IAM user in that account must have an explicit IAM policy that permits the S3 action (e.g., s3:GetObject) on the bucket. Without this, the request is denied by the other account's own IAM evaluation.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the requesting account's IAM user must also have explicit permissions, which is a classic AWS cross-account authorization nuance.

How to eliminate wrong answers

Option A is wrong because KMS permissions are only required if the bucket uses SSE-KMS encryption; the question does not mention encryption, and a missing KMS permission would cause a different error (e.g., AccessDenied with KMS key context). Option C is wrong because S3 fully supports cross-account access via bucket policies and ACLs, as documented in the AWS S3 User Guide. Option D is wrong because S3 is a global service and cross-region access is allowed; region does not inherently block cross-account access.

4
MCQhard

A company has a multi-account AWS environment with a centralized data lake in the Security account. Data producers in other accounts use AWS Glue to write data to S3 buckets in the Security account. The Security account uses AWS Lake Formation to manage permissions. The data engineer is setting up cross-account access so that users in the Producer account can query the data using Athena in their own account. The engineer has registered the S3 buckets and Data Catalog tables in Lake Formation. The IAM roles in the Producer account have the necessary permissions. However, when a user in the Producer account tries to query the table, they get an AccessDenied error. The error message indicates that the principal is not authorized to perform lakeformation:GetTable on the resource. What is the most likely cause?

A.The Glue Data Catalog resource policy is missing a statement to allow cross-account access.
B.The S3 bucket policy does not allow the Producer account's IAM role to read the data.
C.The KMS key policy does not allow the Producer account's IAM role to decrypt objects.
D.The Lake Formation permissions in the Security account do not include a grant to the Producer account's IAM role.
AnswerD

Cross-account Lake Formation access requires two grants: the resource owner grants permissions to the external principal, and the recipient account grants its role access. The Security account never granted the Producer role, so lakeformation:GetTable fails despite correct IAM permissions.

Why this answer

The error explicitly states the principal is not authorized to perform lakeformation:GetTable, which is a Lake Formation permission check, not an S3, KMS, or Glue resource policy check. In Lake Formation cross-account access, the data owner (Security account) must grant table and data location permissions directly to the external IAM principal (the Producer account's role) using the Lake Formation GrantPermissions API or console. Without this explicit grant, Lake Formation denies the GetTable call before any S3 or KMS access is even attempted.

Since the IAM roles already have the necessary permissions, the missing piece is the Lake Formation grant in the Security account.

Exam trap

DEA-C01 often tests the misconception that IAM policies alone are sufficient for cross-account Lake Formation access, when in fact Lake Formation requires an explicit grant to the external principal, and the error message's mention of lakeformation:GetTable is the key clue that distinguishes it from S3 or KMS issues.

How to eliminate wrong answers

Option A is wrong because the Glue Data Catalog resource policy is not the authorization mechanism when Lake Formation manages the catalog; Lake Formation intercepts and authorizes Glue API calls (including GetTable) via its own permission model, so a Glue resource policy would not resolve a lakeformation:GetTable denial. Option B is wrong because the error occurs at the Lake Formation authorization stage, before any S3 data access is attempted; an S3 bucket policy issue would produce an S3 AccessDenied on GetObject, not a lakeformation:GetTable error. Option C is wrong because KMS decryption happens only after Lake Formation authorizes the table access and returns temporary credentials; a KMS key policy problem would surface as a KMS AccessDenied or decryption failure during data retrieval, not during the GetTable call.

5
MCQeasy

A company wants to audit all data access events in their S3 buckets, including who accessed objects and from which IP address. Which AWS service should be used to capture these events?

A.AWS CloudTrail with data events enabled
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon S3 Server Access Logs
AnswerA

CloudTrail data events record object-level S3 operations, capturing the requester's identity and source IP address for every GetObject and PutObject call. Management events alone omit these object reads, so enabling data events satisfies the audit requirement for who accessed which object and from where.

Why this answer

AWS CloudTrail with data events enabled captures object-level S3 operations (GetObject, PutObject, DeleteObject) along with the identity of the caller and the source IP address, which is exactly what is needed for a full data access audit. Management events alone do not capture object reads/writes, so data events must be explicitly turned on.

Exam trap

DEA-C01 often tests the difference between CloudTrail management events and data events — candidates who assume default CloudTrail captures object reads miss that data events must be explicitly enabled for S3 object-level auditing.

How to eliminate wrong answers

Option B is wrong because CloudWatch Logs is a log aggregation and monitoring service — it does not natively capture S3 data access events unless CloudTrail or S3 access logs are routed to it. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not individual object access events. Option D is wrong because S3 Server Access Logs capture request details but are delivered on a best-effort basis, do not include IAM identity context the way CloudTrail does, and lack the same fidelity for security auditing.

6
MCQeasy

A company needs to audit all API calls made in their AWS account, including actions performed by the root user. Which AWS service should be used?

A.VPC Flow Logs
B.AWS CloudTrail
C.Amazon CloudWatch Logs
D.AWS Config
AnswerB

CloudTrail records API activity as management and data events, capturing the identity, source IP, timestamp and request details for every call, including root user actions. This satisfies the requirement to audit all API calls across the account.

Why this answer

AWS CloudTrail records all API calls made in an AWS account, including root user actions, for auditing and compliance. Option A is incorrect because VPC Flow Logs capture network traffic metadata, not API calls. Option C is incorrect because Amazon CloudWatch Logs stores log data but does not natively capture API calls; it can ingest logs from other sources.

Option D is incorrect because AWS Config tracks configuration changes to AWS resources, not API calls.

7
MCQhard

A company stores regulated records in an Amazon S3 bucket and must prove that individual objects cannot be deleted or overwritten for 365 days after creation, even by the account root user. The compliance team also needs to retain the ability to delete the bucket itself after the retention window expires. Which configuration meets these requirements?

A.Enable S3 Versioning and apply an S3 Object Lock default retention rule in compliance mode with a 365-day period.
B.Enable S3 Object Lock in governance mode with a 365-day retention period and grant s3:BypassGovernanceRetention to the security team.
C.Apply a bucket policy that denies s3:DeleteObject and s3:PutObject to all principals for 365 days using a date condition.
D.Enable S3 Versioning and add a lifecycle rule that transitions objects to S3 Glacier Deep Archive after 365 days.
AnswerA

Object Lock in compliance mode prevents any principal, including the root user, from deleting or overwriting a protected object version until the retain-until date passes. A default retention rule applies the 365-day period automatically to new objects. Because the lock protects object versions rather than the bucket, the bucket can still be removed once all versions age out and are deleted.

Why this answer

S3 Object Lock in compliance mode provides write-once-read-many protection that no principal, including the root user, can override before the retention date. A default retention rule applies the period automatically to newly created object versions. Since the lock applies to object versions, the bucket itself can still be deleted after retention lapses and versions are removed.

Exam trap

The trap here is confusing governance mode with compliance mode, when only compliance mode is immune to privileged deletion and retention changes.

8
MCQmedium

A data engineer is building an AWS Lake Formation governed data lake. The security team wants to grant a group of analysts access to only the non-sensitive columns of a table in the Data Catalog, while denying access to columns containing Social Security numbers. The analysts use Amazon Athena to query the data. Which Lake Formation permission model should the data engineer use?

A.Grant table-level SELECT permission to the analysts and rely on Athena to hide the sensitive columns.
B.Use an IAM policy that denies athena:GetQueryResults for queries that reference the sensitive column.
C.Create a separate Data Catalog table that contains only non-sensitive columns and grant access to that table.
D.Grant column-level SELECT permission on the non-sensitive columns and exclude the Social Security number column.
AnswerD

Lake Formation supports column-level permissions, allowing you to grant SELECT on specific columns of a table. By granting only the non-sensitive columns, the analysts can query those columns in Athena while the Social Security number column remains inaccessible. This directly implements the least-privilege requirement without duplicating data.

Why this answer

Lake Formation column-level permissions let you grant SELECT on a subset of columns in a Data Catalog table. Analysts can then query the permitted columns through Athena, and any attempt to select the Social Security number column is denied. Duplicating tables or using broad IAM denies does not achieve the same precise, least-privilege control.

Exam trap

The trap here is thinking that table-level SELECT plus Athena behavior hides sensitive columns, when table-level access exposes every column.

9
MCQmedium

A data engineer is troubleshooting an issue where an AWS Glue ETL job fails when trying to read data from an S3 bucket encrypted with SSE-KMS. The job has an IAM role that includes `kms:Decrypt` permission. What is the most likely reason for the failure?

A.The IAM role does not have s3:GetObject permission
B.The KMS key policy does not allow the Glue job to use the key
C.The S3 bucket is in a different AWS region than the Glue job
D.The Glue job is not configured to use the KMS key for decryption
AnswerB

Correct. The most likely cause is that the KMS key policy does not grant the Glue job's IAM role permission to use the key. Even with kms:Decrypt in the role, the key policy must allow it.

Why this answer

Even if the IAM role has `kms:Decrypt` permission, the KMS key policy must also allow the Glue job's role to use the key. KMS key policies are resource-based policies that control access to the key, and if they do not explicitly grant permission to the Glue job's role, the decrypt operation will fail. This is a common oversight when using SSE-KMS with services like AWS Glue.

Exam trap

DEA-C01 often tests the dual requirement of IAM policies and KMS key policies for accessing encrypted data, and candidates may overlook the key policy.

How to eliminate wrong answers

Option A is wrong because the question states the job has an IAM role that includes `kms:Decrypt` permission, but it does not mention s3:GetObject; however, the failure is specifically about reading data encrypted with SSE-KMS, and the most likely reason is the KMS key policy, not missing S3 permissions. Option C is wrong because S3 and Glue can be in different regions, but cross-region access is possible if configured; it is not the most likely reason for failure. Option D is wrong because the Glue job does not need to be configured to use the KMS key for decryption; the S3 service handles decryption on behalf of the job if permissions are correct.

10
MCQeasy

A data engineer needs to ensure that an Amazon Redshift cluster encrypts all data at rest. Which setting must be enabled when creating the cluster?

A.Enable automated snapshots
B.Enable encryption
C.Enable SSL/TLS
D.Enable VPC
AnswerB

Enabling encryption on the cluster applies AWS KMS-backed encryption to all data at rest, including the cluster's storage volumes and snapshots. This directly satisfies the stem's requirement that the Redshift cluster encrypt all data at rest, and it is the setting exposed during cluster creation.

Why this answer

Amazon Redshift encryption at rest is enabled during cluster creation by selecting the encryption option. Option A is incorrect because enabling automated snapshots is for backup and recovery, not encryption. Option C is incorrect because SSL/TLS ensures encryption in transit, not at rest.

Option D is incorrect because VPC is for network isolation, not encryption.

11
MCQhard

A data engineer is troubleshooting an Amazon Redshift cluster that is not allowing connections from a specific IP range. The engineer verified that the cluster's security group allows inbound traffic from the IP range. What is the next step to resolve the issue?

A.Modify the Redshift cluster parameter group to enable public accessibility.
B.Verify that the cluster's security group is attached to the Redshift cluster.
C.Check the IAM role associated with the Redshift cluster.
D.Check the network ACL (NACL) associated with the Redshift cluster's subnet.
AnswerD

Security groups are stateful and evaluated after subnet-level filtering; a restrictive NACL on the cluster's subnet silently drops inbound traffic before it reaches the security group. Checking the NACL is therefore the correct next diagnostic step.

Why this answer

Even if the security group allows inbound traffic from a specific IP range, the network ACL (NACL) associated with the Redshift cluster's subnet can block traffic at the subnet level. NACLs are stateless and can override security group rules. Option A is incorrect because modifying the cluster parameter group does not control network-level access; public accessibility is a separate setting.

Option B is incorrect because the engineer already verified the security group, but even if it is correctly attached, the NACL could still block traffic. Option C is incorrect because IAM roles control authentication and authorization, not network connectivity.

12
Multi-Selectmedium

A company uses Amazon Redshift to store customer data. The security team requires that all queries are logged for auditing purposes. Which step should be taken to meet this requirement? (Select ONE.)

Select 1 answer
A.Enable AWS CloudTrail database audit logging.
B.Use AWS CloudTrail to log Redshift API calls.
C.Enable logging on the Redshift security group.
D.Enable VPC Flow Logs for the Redshift cluster.
E.Enable Amazon Redshift audit logging to an S3 bucket.
AnswersE

Audit logging captures connection, user, and query activity, then delivers it to Amazon S3 for durable retention. This directly satisfies the security team's requirement that all queries are logged for auditing, since S3 provides the persistent, reviewable store auditors need.

Why this answer

The requirement is to log all queries for auditing. Amazon Redshift's native audit logging captures connection logs, user activity logs, and query logs, and can be exported to an S3 bucket. This is the only step that directly logs SQL queries.

AWS CloudTrail does not log SQL queries; it logs management API calls (e.g., CreateCluster, ModifyCluster). Therefore, only Option E meets the requirement.

Exam trap

The trap is that many candidates assume AWS CloudTrail can log SQL queries, but it only logs API calls. The correct answer is solely Amazon Redshift's native audit logging.

13
MCQeasy

A data engineer stores sensitive records in an Amazon S3 bucket. The security team wants to guarantee that every object is encrypted before it is written to disk and that the bucket automatically rejects any unencrypted PUT request, regardless of which IAM principal sends it. Which configuration should the data engineer apply?

A.Enable S3 Block Public Access at the account level so that only encrypted objects can be uploaded.
B.Enable default bucket encryption with SSE-S3 and rely on the S3 console warning for unencrypted uploads.
C.Configure an S3 Lifecycle rule to transition objects to S3 Glacier Instant Retrieval, which encrypts data at rest.
D.Attach a bucket policy that denies s3:PutObject when the request lacks the s3:x-amz-server-side-encryption condition key.
AnswerD

A bucket policy with a Deny effect and the s3:x-amz-server-side-encryption condition key rejects any PUT that does not carry a server-side encryption header. This enforces encryption at the bucket level for every principal, including the root account, and works with SSE-S3, SSE-KMS, or DSSE-KMS. It directly satisfies the requirement to block unencrypted writes.

Why this answer

The only mechanism that blocks an unencrypted PUT before the object is stored is a bucket policy using a Deny effect with the s3:x-amz-server-side-encryption condition key. Default encryption and console warnings are passive safeguards that cannot stop an explicit unencrypted request from an SDK or CLI. Block Public Access and lifecycle rules address different concerns entirely.

Exam trap

The trap here is assuming that enabling default bucket encryption prevents unencrypted uploads, when it only supplies encryption for requests that omit the header.

14
Multi-Selecthard

A data engineer is designing a data lake on Amazon S3 that will store sensitive financial data. The security team requires that access to the data be audited, that data be encrypted at rest with customer-managed keys, and that the engineer be able to identify which IAM principals accessed specific objects. Which TWO AWS services or features should the engineer use to meet these requirements? (Choose two.)

Select 2 answers
A.AWS CloudTrail data events for S3
B.Amazon S3 server access logging
C.Amazon Macie for sensitive data discovery
D.AWS KMS customer managed keys with SSE-KMS
E.AWS Secrets Manager for storing encryption keys
AnswersA, D

AWS CloudTrail data events capture object-level API activity, such as GetObject and PutObject, including the identity of the caller and the object accessed. This provides the audit trail required to identify which IAM principals accessed specific objects. Management events alone do not log object-level access, so data events are necessary for this granular auditing.

Why this answer

CloudTrail data events provide the necessary audit trail for object-level access, identifying IAM principals. SSE-KMS with customer managed keys satisfies the encryption at rest requirement with customer-managed keys. Together, they meet the auditing and encryption needs.

Exam trap

The trap here is confusing server access logging with CloudTrail data events; while both log access, CloudTrail data events are integrated with IAM and CloudTrail Lake for easier analysis of principal activity.

15
MCQeasy

A company stores raw customer records in an Amazon S3 bucket and processes them with AWS Glue. A governance requirement states that a specific tag named DataClass must exist on every catalog table, and any table missing that tag must not be queryable. Where should the data engineer enforce this requirement with the least operational effort?

A.Enable AWS CloudTrail data events on the S3 bucket and alert when untagged tables are queried.
B.Write an AWS Lambda function that scans the Data Catalog hourly and deletes any table missing the DataClass tag.
C.Attach an IAM policy to all analyst roles that denies glue:GetTable unless the table has the DataClass tag.
D.Use AWS Lake Formation tag-based access control by defining an LF-Tag and granting table permissions only when the DataClass tag value matches.
AnswerD

Lake Formation tag-based access control lets an LF-Tag named DataClass be attached to catalog resources, and permissions are granted based on tag values rather than per-table grants. Tables without the required tag value receive no matching grant, so they are not queryable, which enforces the rule centrally with minimal ongoing effort.

Why this answer

Lake Formation tag-based access control centralizes permission decisions on tags instead of individual tables. Defining an LF-Tag named DataClass and granting access only for matching tag values means any table lacking the required tag value has no applicable grant and is therefore not queryable, satisfying the governance rule with minimal administrative effort.

Exam trap

The trap here is assuming IAM can evaluate Glue Data Catalog tags in a policy condition, when tag-based enforcement belongs to Lake Formation.

16
MCQmedium

A data engineer is designing a data lake on S3 and needs to ensure that data is encrypted at rest using customer-managed KMS keys. The engineer also needs to audit all access to the KMS keys. Which combination of services should be used?

A.SSE-KMS with AWS CloudTrail
B.SSE-C with CloudWatch Logs
C.SSE-KMS with S3 Inventory
D.SSE-S3 with S3 server access logs
AnswerA

SSE-KMS encrypts S3 objects with customer-managed KMS keys, satisfying the encryption-at-rest requirement. CloudTrail records every KMS API call, including Encrypt, Decrypt and GenerateDataKey, delivering the key-access audit trail. Together they meet both constraints: customer-managed keys plus auditable key usage.

Why this answer

SSE-KMS allows customer-managed KMS keys, and AWS CloudTrail logs all KMS API calls (e.g., Decrypt, GenerateDataKey), enabling auditing. Option B is incorrect because SSE-C uses customer-provided encryption keys, not KMS, and CloudWatch Logs is for application logs, not KMS access. Option C is incorrect because S3 Inventory provides object metadata but does not audit KMS access.

Option D is incorrect because SSE-S3 uses AWS-managed keys, not customer-managed, and S3 server access logs do not capture KMS API calls.

17
Multi-Selecteasy

A data engineer needs to enforce that all data in an Amazon S3 bucket is encrypted at rest. Which of the following can be used to achieve this? (Choose TWO.)

Select 2 answers
A.Use AWS CloudTrail to monitor for unencrypted objects
B.Use VPC endpoints to restrict access
C.Configure a bucket policy to deny PutObject if encryption headers are missing
D.Enable default encryption on the S3 bucket using SSE-S3
E.Use AWS KMS to generate encryption keys for the bucket
AnswersC, D

A bucket policy with a Deny effect on s3:PutObject conditioned on the absence of encryption headers (for example, s3:x-amz-server-side-encryption) rejects unencrypted uploads at the API layer, satisfying the requirement to enforce encryption at rest for every object written to the bucket.

Why this answer

Option C is correct because an S3 bucket policy can include a Deny statement on s3:PutObject that uses a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its aws:kms variant), which blocks any upload request that does not carry the required encryption header, thereby enforcing encryption at rest for newly written objects. Option D is correct because enabling default bucket encryption with SSE-S3 (AES-256) causes Amazon S3 to automatically encrypt every object at rest on write, even when the request specifies no encryption headers, satisfying the requirement without relying on the client. Option A is not correct because AWS CloudTrail only records and logs API activity for auditing; it cannot prevent or enforce encryption of objects.

Option B is not correct because VPC endpoints only control network access paths to S3 and have no bearing on whether objects are encrypted at rest. Option E is not correct because AWS KMS generates and manages keys, but merely having KMS keys available does not by itself enforce encryption on the bucket; enforcement requires default encryption or a bucket policy condition.

18
MCQeasy

A company wants to securely store database credentials used by a Lambda function. Which AWS service should be used to store and rotate the credentials automatically?

A.AWS CloudHSM
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Systems Manager Parameter Store
AnswerB

Secrets Manager natively stores credentials and performs scheduled rotation via Lambda, satisfying the automatic rotation requirement. Unlike Systems Manager Parameter Store, it includes built-in rotation for RDS, Redshift and DocumentDB, so no custom rotation logic is needed.

Why this answer

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating secrets such as database credentials, API keys, and OAuth tokens. It natively integrates with Amazon RDS, Redshift, and DocumentDB to rotate credentials on a schedule using Lambda rotation functions. Lambda functions can retrieve secrets at runtime via the Secrets Manager API or the AWS Parameters and Secrets Lambda Extension, avoiding hardcoded credentials.

Exam trap

DEA-C01 often tests the confusion between Secrets Manager and SSM Parameter Store — candidates pick Parameter Store because it is cheaper, forgetting that only Secrets Manager provides native automatic rotation for database credentials.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM is a dedicated hardware security module for cryptographic key operations and PKI, not a secrets store with built-in rotation for database credentials. Option C is wrong because KMS manages encryption keys used to encrypt data — it does not store or rotate application secrets like database passwords. Option D is wrong because Systems Manager Parameter Store can store SecureString parameters, but it lacks native automatic rotation for RDS/database credentials (rotation must be custom-built with Lambda and EventBridge).

19
MCQmedium

A company uses AWS Glue to run ETL jobs on data stored in S3. The data is encrypted with SSE-KMS. The Glue job fails with an 'AccessDenied' error when trying to read the data. What is the MOST likely cause?

A.The S3 bucket policy denies access to the Glue service role.
B.The AWS Glue Data Catalog does not have permission to the table.
C.The IAM role used by Glue does not have kms:Decrypt permission on the KMS key.
D.The Glue job's connection does not have the necessary permissions.
AnswerC

SSE-KMS encrypts objects with a KMS key, so reading them requires both S3 access and kms:Decrypt on that key. The Glue job's IAM role lacks this permission, producing AccessDenied despite valid S3 permissions. Granting kms:Decrypt on the key to the Glue role resolves the failure.

Why this answer

When S3 data is encrypted with SSE-KMS, any principal reading the object must have both s3:GetObject on the bucket and kms:Decrypt on the KMS key. The Glue job's IAM role is the principal making the read, so if it lacks kms:Decrypt, S3 returns AccessDenied even though the bucket policy may allow access. This is the most common cause of this specific error pattern.

Exam trap

DEA-C01 often tests the layered permission model of SSE-KMS, so candidates who focus only on S3 bucket policies or IAM S3 actions miss that kms:Decrypt is a separate, required permission on the KMS key.

How to eliminate wrong answers

Option A is wrong because a bucket policy denying the Glue role would also produce AccessDenied, but the question specifies SSE-KMS encryption, which points to the KMS key policy as the more likely missing permission. Option B is wrong because Data Catalog permissions affect metadata access, not the ability to read encrypted S3 objects. Option D is wrong because Glue connections are used for JDBC/network sources, not for S3 reads, so connection permissions are irrelevant here.

20
Multi-Selecteasy

A company wants to enforce encryption in transit for data moving between an EC2 instance and an S3 bucket. Which TWO methods can achieve this? (Choose 2)

Select 2 answers
A.Add a bucket policy that denies requests without the aws:SecureTransport condition.
B.Use a VPC endpoint for S3.
C.Enable default SSE-S3 encryption on the bucket.
D.Use the HTTPS endpoint for S3 API calls.
E.Enable CloudTrail to monitor for non-encrypted requests.
AnswersA, D

The aws:SecureTransport condition key evaluates whether the request arrived over TLS; denying when it is false blocks plain HTTP calls to S3. This enforces encryption in transit at the bucket policy layer, satisfying the requirement that EC2-to-S3 traffic never travel unencrypted.

Why this answer

Option A is correct because a bucket policy with a Deny effect on s3:* conditioned on "aws:SecureTransport": "false" explicitly rejects any request made over plain HTTP, thereby enforcing encryption in transit for all access to the bucket, including from EC2. Option D is correct because S3's HTTPS endpoint (https://bucket.s3.amazonaws.com or the regional equivalent) uses TLS to encrypt data in transit between the EC2 instance and S3, satisfying the encryption-in-transit requirement directly. Option B is not correct because a VPC endpoint (Gateway or Interface) only changes the network path and can be used with either HTTP or HTTPS; it does not by itself guarantee encryption in transit.

Option C is not correct because SSE-S3 provides encryption at rest for objects stored in the bucket, not encryption of data moving over the network. Option E is not correct because CloudTrail only logs and monitors API activity; it is a detective control that does not encrypt traffic or prevent unencrypted requests.

Exam trap

DEA-C01 often tests the confusion between encryption at rest (SSE-S3) and encryption in transit (HTTPS/TLS), causing candidates to select SSE-S3 or CloudTrail as methods for enforcing in-transit encryption.

21
MCQhard

An organization is using AWS Glue to process sensitive data. The data is stored in S3 with server-side encryption using AWS KMS (SSE-KMS). The Glue job fails with an error indicating that it cannot read the data. The IAM role used by Glue has the following policy. What is missing?

A.The s3:GetObject permission on the bucket
B.The kms:Decrypt permission on the KMS key
C.The kms:GenerateDataKey permission on the KMS key
D.The kms:ReEncrypt permission on the KMS key
AnswerB

Reading SSE-KMS encrypted S3 objects requires both S3 GetObject and kms:Decrypt on the customer managed key. The Glue execution role's policy grants S3 access but omits the KMS decrypt action, so the job cannot unwrap the data key and fails with an access-denied error.

Why this answer

The Glue job fails because the IAM role lacks the kms:Decrypt permission on the KMS key used for SSE-KMS encryption. When S3 objects are encrypted with SSE-KMS, any principal reading the object must have both s3:GetObject on the object and kms:Decrypt on the KMS key. Without kms:Decrypt, S3 returns an AccessDenied error even though the s3:GetObject permission is present.

Exam trap

DEA-C01 often tests the misconception that s3:GetObject alone is sufficient to read SSE-KMS encrypted objects, when in fact kms:Decrypt on the KMS key is also mandatory.

How to eliminate wrong answers

Option A is wrong because the question states the IAM role already has a policy (implied to include S3 read access); the missing piece is KMS decryption, not s3:GetObject. Option C is wrong because kms:GenerateDataKey is required for writing (encrypting) objects with SSE-KMS, not for reading them. Option D is wrong because kms:ReEncrypt is only needed when changing the encryption key or re-encrypting data, not for simple decryption during a read.

22
MCQmedium

A company uses Amazon Kinesis Data Streams to ingest real-time data. The compliance team requires that all data in the stream be encrypted at rest. Which configuration should be enabled?

A.Enable TLS encryption on the Kinesis stream
B.Enable server-side encryption using an AWS KMS key
C.Use client-side encryption in the producer application
D.Store the data in Amazon CloudWatch Logs instead
AnswerB

Server-side encryption with an AWS KMS key encrypts stream data at rest, meeting the compliance mandate. Kinesis encrypts using the specified customer managed key before writing to storage and decrypts on retrieval, so producers and consumers need no changes beyond KMS permissions.

Why this answer

Server-side encryption (SSE) for Amazon Kinesis Data Streams uses an AWS KMS key to automatically encrypt data at rest as it is written to the stream and decrypt it when read. This meets the compliance requirement for encryption at rest without requiring any changes to the producer or consumer applications.

Exam trap

The trap here is confusing encryption in transit (TLS) with encryption at rest (SSE), leading candidates to select TLS as the solution for at-rest compliance.

How to eliminate wrong answers

Option A is wrong because TLS encryption protects data in transit between clients and the Kinesis endpoint, not data at rest within the stream. Option C is wrong because client-side encryption encrypts data before it is sent to Kinesis, but this is a client-managed approach that does not leverage Kinesis's native at-rest encryption and adds complexity; the question asks which configuration should be enabled on the stream itself. Option D is wrong because storing data in CloudWatch Logs does not encrypt the Kinesis stream data at rest and is a different service entirely, not a configuration for Kinesis Data Streams.

23
MCQmedium

A data engineer needs to audit all access to an Amazon S3 bucket containing sensitive data. The audit must capture who accessed the bucket, from which IP address, and what actions were performed. Which AWS service should be enabled?

A.Enable S3 server access logging for the bucket.
B.Enable AWS CloudTrail with data events for the S3 bucket.
C.Use AWS Config to record S3 bucket-level changes.
D.Configure Amazon CloudWatch Logs to monitor S3 access.
AnswerB

CloudTrail data events capture object-level S3 operations, recording the caller identity, source IP address and action performed. Management events alone omit GetObject and PutObject, so enabling data events for the bucket is necessary to audit who accessed the sensitive data.

Why this answer

AWS CloudTrail data events capture object-level API activity on S3 buckets, including the identity of the caller, source IP address, timestamp, and the specific action (GetObject, PutObject, DeleteObject). Enabling data events on the bucket produces an auditable record of who accessed sensitive objects and from where, which is exactly what the requirement demands. Management events alone would only show bucket-level configuration changes, not object reads/writes.

Exam trap

DEA-C01 often tests the confusion between S3 server access logging and CloudTrail data events — candidates pick access logging because it sounds like an audit log, but only CloudTrail captures the full identity and IP context required for compliance audits.

How to eliminate wrong answers

Option A is wrong because S3 server access logs record requests to the bucket but do not natively capture the IAM identity or full request context (they show requester, but not the rich CloudTrail fields like userIdentity and full event JSON), and they are delivered best-effort with delays. Option C is wrong because AWS Config records resource configuration changes and compliance state — it does not log data-plane access to objects. Option D is wrong because CloudWatch Logs is a log aggregation service; S3 does not natively stream access events to CloudWatch Logs without CloudTrail or access logging already in place, so it is not the audit source itself.

24
Multi-Selectmedium

A data engineer needs to ensure that data stored in Amazon S3 is protected against accidental deletion and that the data cannot be altered for a period of 7 years to meet compliance requirements. The engineer must also ensure that the data remains encrypted at rest using SSE-KMS. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Enable S3 Object Lock in compliance mode on the bucket and set a retention period of 7 years for all objects.
B.Use AWS Backup to create a vault lock with a 7-year retention policy and schedule daily backups of the S3 bucket.
C.Configure default encryption on the bucket to use SSE-KMS with a customer managed key.
D.Enable versioning on the bucket and configure a lifecycle rule to transition objects to S3 Glacier Deep Archive after 30 days.
E.Create an S3 bucket policy that denies s3:DeleteObject and s3:PutObject for all principals except a specific IAM role.
AnswersA, C

S3 Object Lock in compliance mode prevents objects from being overwritten or deleted for the specified retention period, even by the root user. This meets the requirement that data cannot be altered for 7 years. It also provides immutability, which is essential for compliance. Enabling Object Lock requires versioning to be enabled on the bucket.

Why this answer

To protect data from deletion and alteration for 7 years, S3 Object Lock in compliance mode must be enabled on the bucket with a retention period of 7 years. This ensures objects are immutable. Additionally, default encryption with SSE-KMS ensures data is encrypted at rest.

Other options like versioning, lifecycle rules, bucket policies, or AWS Backup do not provide the required immutability for the primary data in S3.

Exam trap

The trap here is thinking that a bucket policy denying delete operations or versioning alone can provide the same immutability as S3 Object Lock in compliance mode, which is specifically designed for regulatory retention.

25
MCQeasy

A data engineer needs to share a dataset from an S3 bucket in Account A with another AWS account (Account B). The data must remain encrypted at rest with KMS. Which steps are required?

A.Update the KMS key policy to allow Account B's root user
B.Create an IAM role in Account A and grant cross-account access
C.Update the S3 bucket policy and the KMS key policy to allow Account B
D.Update the S3 bucket policy to allow Account B's root user
AnswerC

Correct: Both the S3 bucket policy and the KMS key policy must be updated to allow Account B.

Why this answer

The correct steps are to update both the S3 bucket policy to grant Account B access to the objects and the KMS key policy to grant Account B the necessary decrypt permissions. Option A is insufficient because it only updates the KMS key policy; the bucket policy must also be updated to allow Account B's access to the S3 objects. Option B is also insufficient because creating an IAM role alone does not grant KMS decrypt permissions; the KMS key policy must be updated.

Option C is correct as it includes both. Option D is insufficient because it only updates the bucket policy, not the KMS key policy.

26
MCQmedium

A company is using Amazon Redshift for analytics and needs to ensure that all data is encrypted at rest. The current cluster does not have encryption enabled. What is the most efficient way to enable encryption?

A.Change the cluster parameter group to enable encryption
B.Modify the cluster configuration to enable encryption
C.Use AWS DMS to migrate data to a new encrypted cluster
D.Create a snapshot of the cluster and restore it to a new cluster with encryption enabled
AnswerD

Redshift cannot enable encryption in place on an existing unencrypted cluster. Snapshotting and restoring into a new cluster with encryption enabled is the supported, least-effort migration path, preserving data while applying KMS encryption at rest.

Why this answer

Redshift does not support enabling encryption on an existing cluster; a new encrypted cluster must be created and data migrated. Modifying the cluster configuration or parameter groups does not enable encryption. Creating a snapshot and restoring it to a new cluster with encryption enabled is the standard approach.

27
MCQmedium

A data engineer must ensure that all objects written to an S3 bucket by an AWS Glue ETL job are encrypted with a customer-managed AWS KMS key, even if the job does not explicitly specify encryption parameters. The bucket policy already denies unencrypted PUT requests. Which configuration will enforce the required encryption with the LEAST operational overhead?

A.Enable S3 Bucket Keys for the bucket to reduce KMS costs.
B.Set the default encryption on the S3 bucket to SSE-KMS with the customer-managed key.
C.Attach an IAM policy to the Glue job role that allows only s3:PutObject with the s3:x-amz-server-side-encryption condition.
D.Modify the Glue job to set the --encryption-type parameter to SSE-KMS for all writes.
AnswerB

Configuring default bucket encryption with SSE-KMS and the customer-managed key ensures that any object PUT without explicit encryption headers is automatically encrypted with that key. This meets the requirement with no changes to the Glue job and works even if the job omits encryption parameters. The bucket policy can still deny non-compliant requests as an additional layer.

Why this answer

Default bucket encryption with SSE-KMS using the customer-managed key automatically encrypts all objects written without explicit encryption headers, satisfying the requirement without modifying the Glue job. It also works with the existing bucket policy denial for non-compliant requests. This approach minimizes operational effort and ensures consistent encryption across all writers.

Exam trap

The trap here is assuming that a bucket policy denying unencrypted PUTs is sufficient, but it only blocks requests and does not apply encryption automatically.

28
MCQeasy

A data engineer needs to securely store database credentials used by a Lambda function. The solution must automatically rotate the credentials every 90 days. Which AWS service should the engineer use?

A.AWS CloudHSM
B.AWS Systems Manager Parameter Store
C.IAM Roles for Lambda
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager natively stores and rotates credentials on a schedule, satisfying the 90-day rotation requirement without custom code. Lambda retrieves secrets via the SDK at runtime, so database passwords never persist in environment variables or code.

Why this answer

AWS Secrets Manager is purpose-built for storing and managing secrets such as database credentials, API keys, and tokens. It natively supports automatic rotation via Lambda rotation functions on a schedule (e.g., every 90 days), and integrates with RDS, Redshift, and DocumentDB for managed rotation. This directly satisfies both the secure storage and automatic 90-day rotation requirements.

Exam trap

The trap here is confusing Parameter Store SecureString with Secrets Manager — both store secrets, but only Secrets Manager provides native scheduled rotation, which is the deciding requirement.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM is a dedicated hardware security module for cryptographic key operations and does not provide secret storage with built-in rotation workflows for database credentials. Option B is wrong because Systems Manager Parameter Store can store SecureString parameters but does not natively rotate database credentials on a schedule — rotation must be custom-built. Option C is wrong because IAM Roles for Lambda provide temporary AWS credentials to the function itself, not storage or rotation of external database credentials.

29
MCQhard

A company uses AWS KMS to encrypt sensitive data stored in S3. To meet compliance requirements, they need to ensure that the encryption keys are automatically rotated every year. Which type of KMS key should they use?

A.Customer managed key with manual rotation
B.AWS managed key
C.Custom key store (CloudHSM) key
D.Customer managed key with automatic rotation enabled
AnswerD

Customer managed keys in AWS KMS support automatic annual rotation, which AWS-managed keys handle on a fixed three-year cycle you cannot change. Enabling rotation on a customer managed key satisfies the yearly compliance requirement, since the key material is replaced without altering the key ID or ARN.

Why this answer

Customer managed keys with automatic rotation enabled support automatic annual rotation, meeting the compliance requirement. AWS managed keys rotate automatically every year, but they cannot be controlled or customized by the customer, so they are not the best choice when the customer needs to manage the key policy or rotation schedule. Custom key stores (CloudHSM) do not support automatic rotation.

Option A (customer managed key with manual rotation) requires manual intervention to rotate, not automatic. Therefore, D is the correct answer.

30
MCQmedium

A data engineer needs to store sensitive data in Amazon S3 and automatically classify the data using a managed service. The data is uploaded via an S3 bucket. Which AWS service can automatically detect and classify sensitive data?

A.Amazon Macie
B.AWS WAF
C.Amazon Inspector
D.AWS Shield
AnswerA

Amazon Macie uses machine learning and pattern matching to automatically discover, classify, and alert on sensitive data such as personally identifiable information in S3. It is the managed service that fulfils the automatic classification requirement without custom code.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in Amazon S3. It continuously evaluates S3 buckets and identifies sensitive content such as PII, credentials, and financial data, generating findings that can be routed to EventBridge or Security Hub. This directly matches the requirement to automatically detect and classify sensitive data in S3.

Exam trap

The trap here is confusing security services that operate at different layers — candidates often pick AWS WAF or Shield because they associate 'security' with network protection, but the question specifically asks for data classification in S3, which only Macie provides.

How to eliminate wrong answers

Option B is wrong because AWS WAF is a web application firewall that filters HTTP/HTTPS traffic to protect web apps from exploits like SQL injection and XSS — it does not inspect or classify data at rest in S3. Option C is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure, not S3 data classification. Option D is wrong because AWS Shield is a managed DDoS protection service for applications running on AWS, with no data classification capability.

31
Multi-Selecteasy

Which THREE AWS services can be used to centrally manage and govern data across multiple AWS accounts? (Select THREE.)

Select 3 answers
A.Amazon S3
B.AWS Control Tower
C.AWS Organizations
D.Amazon Redshift
E.AWS Lake Formation
AnswersB, C, E

AWS Control Tower applies guardrails and account baselines across an organisation, enforcing governance at scale. It satisfies the multi-account central governance requirement by orchestrating AWS Organizations, IAM Identity Center and CloudTrail into a managed landing zone.

Why this answer

AWS Control Tower (B) is correct because it provides a centralized landing zone with guardrails and account provisioning that enforces governance and data management policies across multiple AWS accounts. AWS Organizations (C) is correct because it enables central management of multiple accounts through organizational units, service control policies (SCPs), and consolidated billing, which are foundational for cross-account governance. AWS Lake Formation (E) is correct because it centrally manages data lake permissions, cataloging, and fine-grained access control across accounts using AWS RAM resource shares and the Glue Data Catalog.

Amazon S3 (A) is incorrect because it is an object storage service, not a cross-account governance or central management service, even though it can host data governed by other services. Amazon Redshift (D) is incorrect because it is a data warehouse service for analytics, not a service for centrally managing and governing data across multiple accounts.

32
Multi-Selectmedium

A data engineer is designing a data pipeline that processes PII data using AWS Glue and stores results in S3. Which TWO actions should be taken to protect the data? (Choose 2)

Select 2 answers
A.Use S3 default encryption with SSE-S3 for the output bucket.
B.Store database credentials in AWS Secrets Manager and reference them in Glue connections.
C.Enable S3 object deletion protection by setting a retention policy.
D.Configure AWS Glue to use a KMS key for encrypting data written to S3.
E.Use HTTPS for all data transfer between Glue and S3.
AnswersB, D

AWS Secrets Manager stores the database credentials encrypted and rotates them, and Glue connections reference the secret rather than embedding plaintext passwords in job scripts or catalog properties. This removes hard-coded credentials from the PII pipeline, satisfying the protection requirement.

Why this answer

Option B is correct because storing database credentials in AWS Secrets Manager and referencing them from Glue connections avoids hardcoding secrets in scripts or job parameters, enabling secure, auditable, and rotatable credential management for PII pipelines. Option D is correct because configuring AWS Glue to use a customer-managed KMS key for encrypting data written to S3 provides encryption at rest with control over key policies, rotation, and access auditing, which is appropriate for sensitive PII. Option A is not the best choice because SSE-S3 uses AWS-managed keys with less control and auditability than a KMS key, and the question asks for protective actions beyond default encryption.

Option C is incorrect because S3 object deletion protection via retention policies (Object Lock) addresses immutability/deletion, not the confidentiality of PII data being processed. Option E is not selected because HTTPS protects data in transit, but Glue-to-S3 traffic within AWS is already encrypted in transit by default, so it is not one of the two required protective actions for this scenario.

Exam trap

DEA-C01 often tests the distinction between encryption at rest with AWS-managed keys (SSE-S3) versus customer-managed KMS keys (SSE-KMS), and candidates frequently pick SSE-S3 as 'good enough' for PII, missing that compliance and key control requirements demand KMS; similarly, they may choose HTTPS (already default) as a security measure, overlooking that it only covers transit, not at-rest protection or credential management.

33
MCQhard

A data engineer is designing a data pipeline that ingests data from an on-premises system into Amazon S3 using AWS Transfer Family. The data must be encrypted at rest using a customer-managed key in AWS KMS. The S3 bucket policy must allow only encrypted connections. Which policy condition should be used?

A.aws:SecureTransport
B.kms:EncryptionContext
C.s3:x-amz-server-side-encryption-aws-kms-key-id
D.s3:x-amz-server-side-encryption
AnswerA

aws:SecureTransport is a boolean condition key that evaluates whether the request arrived over HTTPS. Setting it to false in a Deny statement blocks unencrypted connections, satisfying the bucket policy requirement that only encrypted transport be permitted to the Transfer Family endpoint.

Why this answer

The correct condition is 'aws:SecureTransport' because it ensures that requests to the S3 bucket are made over HTTPS (TLS), thereby enforcing encrypted connections. This condition key is a boolean that indicates whether the request used SSL/TLS. Setting it to 'true' in a bucket policy denies any non-encrypted (HTTP) requests.

Exam trap

DEA-C01 often tests the confusion between encryption in transit and encryption at rest, and candidates may incorrectly choose a condition related to server-side encryption headers instead of 'aws:SecureTransport' for enforcing encrypted connections.

How to eliminate wrong answers

Option B is wrong because 'kms:EncryptionContext' is used to enforce specific encryption context values for KMS operations, not to enforce encrypted connections to S3. Option C is wrong because 's3:x-amz-server-side-encryption-aws-kms-key-id' is used to require a specific KMS key for server-side encryption, but it does not enforce that the connection itself is encrypted; it only checks the header for the key ID. Option D is wrong because 's3:x-amz-server-side-encryption' checks for the presence of the encryption header (e.g., 'aws:kms'), but again, it does not enforce that the connection is encrypted; a request could be made over HTTP with the header set.

34
MCQhard

A company uses AWS Lake Formation to manage access to a data lake in Amazon S3. A data engineer needs to grant a specific IAM role access to only the columns containing non-sensitive data in a table, while hiding columns with personally identifiable information (PII). The engineer has already registered the S3 bucket and the table in Lake Formation. What should the engineer do to meet this requirement?

A.Create a Lake Formation data filter that excludes the PII columns and grant SELECT permission on the filtered table to the IAM role.
B.Attach a bucket policy to the S3 bucket that allows the IAM role to read only specific objects.
C.Use an IAM policy that denies access to the S3 prefixes containing the PII columns.
D.Configure an AWS Glue job to create a new table that omits the PII columns and grant access to that table.
AnswerA

Lake Formation data filters allow column-level and row-level access control. By creating a data filter that excludes PII columns, the engineer can grant SELECT permission on that filtered view to the IAM role. This ensures the role can query only the non-sensitive columns. This is the correct approach because Lake Formation enforces these permissions at the table level without modifying the underlying data.

Why this answer

Lake Formation data filters enable column-level security by allowing you to exclude specific columns from a table. When you grant SELECT permission on a filtered table, the user can only access the included columns. This meets the requirement of hiding PII columns while providing access to non-sensitive data, without duplicating data or altering S3 objects.

Exam trap

The trap here is confusing S3 object-level permissions with column-level permissions, which are enforced by Lake Formation data filters.

35
MCQeasy

A data engineer is configuring an AWS Glue ETL job that processes data from an Amazon S3 bucket. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer needs to ensure that the Glue job uses HTTPS endpoints when reading from and writing to S3. Which action should the engineer take?

A.Ensure that the Glue job's IAM role has permissions to use HTTPS, and no further configuration is needed.
B.No action is needed; AWS Glue uses HTTPS for S3 by default.
C.Add the --enable-s3-ssl parameter to the Glue job's job parameters.
D.Configure the Glue connection to use an S3 endpoint with the https:// prefix.
AnswerB

AWS Glue uses the AWS SDK for S3 operations, and the SDK defaults to HTTPS endpoints. Therefore, data in transit between Glue and S3 is encrypted with TLS by default. No additional configuration is required to meet the requirement. This is the correct and simplest answer.

Why this answer

AWS Glue uses the AWS SDK to interact with Amazon S3, and the SDK uses HTTPS endpoints by default. This means data in transit is encrypted with TLS without any additional configuration. There is no need for special job parameters, connection settings, or IAM permissions to enable TLS.

The correct action is to recognize that no action is needed.

Exam trap

The trap here is assuming that you must enable SSL/TLS explicitly for Glue-S3 communication, when it is already enabled by default.

36
MCQmedium

A company needs to monitor and record all changes to IAM policies in their AWS account. Which AWS service should be used?

A.Amazon CloudWatch Logs
B.Amazon GuardDuty
C.AWS CloudTrail
D.AWS IAM Access Analyzer
AnswerC

AWS CloudTrail captures API activity, including IAM policy creation, modification and deletion, recording each event with the caller identity, timestamp and request parameters. This satisfies the requirement to monitor and record all IAM policy changes, since CloudTrail logs management events by default and delivers them to S3 or CloudWatch for auditing.

Why this answer

AWS CloudTrail records API activity in an AWS account, including all IAM policy changes (CreatePolicy, AttachRolePolicy, PutRolePolicy, etc.), capturing who made the change, when, from which IP, and with what parameters. It is the authoritative audit service for governance, compliance, and security analysis of control-plane actions. CloudWatch Logs, GuardDuty, and IAM Access Analyzer serve monitoring, threat detection, and permission analysis—not comprehensive API change recording.

Exam trap

DEA-C01 often tests the overlap between CloudTrail, CloudWatch, and GuardDuty—candidates pick GuardDuty because it 'detects' IAM issues, but the question asks for the service that records all changes, which is CloudTrail.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs stores and analyzes log data (including CloudTrail logs if forwarded), but it is not the service that natively records IAM API changes. Option B is wrong because Amazon GuardDuty is a threat-detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs for malicious activity; it does not itself record all IAM policy changes. Option D is wrong because IAM Access Analyzer identifies resources shared with external entities and validates policies against best practices; it does not provide a complete audit trail of IAM policy modifications.

37
Multi-Selecthard

A company uses Amazon Redshift for its data warehouse and needs to enforce column-level security on sensitive columns. Which TWO approaches can achieve this?

Select 2 answers
A.Apply an S3 bucket policy to the underlying data files.
B.Create views that expose only non-sensitive columns and grant access to the views.
C.Use Redshift Spectrum to query external tables and restrict columns via the external schema.
D.Use Redshift column-level security to grant or revoke permissions on specific columns.
E.Use Redshift row-level security policies to restrict column access.
AnswersB, D

Views restrict the projection to non-sensitive columns, so grantees query only exposed attributes; the underlying sensitive columns remain inaccessible through the view. This delivers column-level security by omission, satisfying the requirement without granting base-table access.

Why this answer

Option B is correct because creating views that expose only non-sensitive columns and granting users access to those views (rather than the base tables) is a standard Redshift pattern for column-level security: users query the view and cannot see the restricted columns. Option D is correct because Amazon Redshift natively supports column-level access control via GRANT and REVOKE on individual columns (for example, GRANT SELECT(col1, col2) ON table TO user), which directly enforces column-level security. Option A is wrong because an S3 bucket policy governs access to objects in S3, not to columns within Redshift tables, and does not control SQL-level column visibility.

Option C is wrong because Redshift Spectrum external schemas and tables do not provide a column-restriction mechanism for enforcing column-level security on Redshift data. Option E is wrong because Redshift row-level security (RLS) policies filter which rows a user can see, not which columns they can access.

Exam trap

DEA-C01 often tests the confusion between row-level security (filters rows) and column-level security (restricts columns), and the misconception that S3 bucket policies or Spectrum external schemas can enforce column-level access inside Redshift tables.

38
MCQmedium

A company wants to centrally manage encryption keys for multiple AWS services and automatically rotate them every year. Which AWS service should be used?

A.AWS CloudHSM
B.AWS Certificate Manager (ACM)
C.AWS Secrets Manager
D.AWS Key Management Service (KMS)
AnswerD

AWS Key Management Service provides customer managed keys with automatic annual rotation, satisfying the yearly rotation requirement. It integrates natively across multiple AWS services, enabling centralised key management. Unlike CloudHSM, which offers dedicated hardware but no built-in automatic rotation, KMS delivers the managed rotation and multi-service integration the scenario demands.

Why this answer

AWS Key Management Service (KMS) is designed to centrally manage encryption keys for multiple AWS services and supports automatic annual rotation of customer master keys. It integrates with services like S3, EBS, and RDS, making it the correct choice.

Exam trap

DEA-C01 often tests the distinction between KMS and CloudHSM; candidates may choose CloudHSM for key management but overlook the automatic rotation and integration features of KMS.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules but does not offer automatic key rotation and is not centrally managed across services in the same way as KMS. Option B is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates, not encryption keys for data at rest. Option C is wrong because AWS Secrets Manager is for managing secrets like database credentials, not for general encryption key management with rotation.

39
MCQmedium

A data engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest using a customer managed key in AWS KMS. The engineer also needs to enforce that any attempt to upload an object without specifying the correct KMS key is denied. Which combination of actions should the engineer take?

A.Configure the bucket to use SSE-KMS with the customer managed key and attach an IAM policy to all users that allows only s3:PutObject with the correct encryption header.
B.Enable default encryption with SSE-S3 and use AWS KMS grants to restrict access to the customer managed key.
C.Use an S3 Object Lambda access point to encrypt objects on upload with the customer managed key.
D.Enable default encryption on the bucket with SSE-KMS using the customer managed key, and add a bucket policy that denies s3:PutObject requests that do not include the correct x-amz-server-side-encryption header.
AnswerD

Default encryption ensures all objects are encrypted with the specified KMS key, but it does not prevent uploads with a different encryption method. A bucket policy that denies PutObject requests lacking the correct encryption header enforces the use of the specific KMS key. Together, they meet the requirement.

Why this answer

To enforce encryption with a specific customer managed KMS key, enable default SSE-KMS encryption on the bucket and add a bucket policy that denies PutObject requests unless they include the correct x-amz-server-side-encryption header. This ensures all objects are encrypted with the designated key and prevents uploads with other encryption methods.

Exam trap

The trap here is assuming that enabling default encryption alone enforces the use of a specific KMS key, when in fact uploads can override the default with a different encryption method unless a bucket policy explicitly denies it.

40
Multi-Selecthard

A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which TWO steps should the data engineer take? (Choose two.)

Select 2 answers
A.Use the default AWS managed KMS key for S3 (aws/s3)
B.Use SSE-S3 encryption instead of KMS
C.Create a customer-managed KMS key with a key policy that grants kms:Decrypt only to the allowed IAM roles
D.Add an IAM policy to the role that requires MFA for kms:Decrypt
E.Configure the S3 bucket to use SSE-KMS with the customer-managed key
AnswersC, E

A customer-managed KMS key lets you attach a key policy restricting kms:Decrypt to named IAM roles, satisfying the stem's requirement that only specific roles decrypt. AWS-managed keys use fixed policies you cannot edit, so they cannot enforce this restriction.

Why this answer

Option C is correct because a customer-managed KMS key allows you to define a key policy that explicitly grants kms:Decrypt only to the specific IAM roles, which is the core mechanism for restricting decryption permissions in KMS. Option E is correct because the S3 bucket must be configured to use SSE-KMS with that customer-managed key; otherwise, S3 would use a different key (such as the default aws/s3 key) and the key policy restriction would not apply to the objects. Option A is incorrect because the default AWS managed key aws/s3 has a key policy managed by AWS that grants broad permissions to the account, so it cannot be scoped to only specific IAM roles.

Option B is incorrect because SSE-S3 uses AES-256 with S3-managed keys and does not involve KMS or IAM role-based decrypt permissions at all. Option D is incorrect because requiring MFA for kms:Decrypt adds an authentication condition but does not by itself limit decryption to specific IAM roles, and MFA is not the mechanism that enforces role-level restriction.

41
MCQmedium

A company wants to monitor and alert on unauthorized API calls in their AWS account. Which AWS service should be used to detect and notify on such events?

A.Amazon GuardDuty and AWS Security Hub
B.Amazon VPC Flow Logs and Amazon CloudWatch Logs
C.AWS Config and AWS Systems Manager
D.AWS CloudTrail and Amazon CloudWatch Events
AnswerD

CloudTrail records every API call as a management event, capturing the caller identity and whether it was authorised. CloudWatch Events (EventBridge) then matches those unauthorised-call patterns via rules and triggers notifications, satisfying the requirement to both detect and alert on unauthorised API activity.

Why this answer

D is correct because AWS CloudTrail records all API calls in the AWS account, and Amazon CloudWatch Events (or EventBridge) can be configured with rules to detect specific API calls (e.g., unauthorized actions) and trigger notifications. Option A is incorrect because Amazon GuardDuty and AWS Security Hub are threat detection and security management services, not primarily for monitoring all API calls. Option B is incorrect because Amazon VPC Flow Logs capture network traffic metadata, not API calls.

Option C is incorrect because AWS Config monitors resource configuration changes, not API calls.

Exam trap

Candidates often assume GuardDuty is the go-to for API call monitoring, but GuardDuty focuses on threat detection, not comprehensive API logging. CloudTrail is the correct service for logging all API calls.

42
Multi-Selectmedium

A company is using Amazon Redshift for data warehousing. They need to ensure that data is encrypted at rest and in transit. Which TWO configurations are required to meet these requirements?

Select 2 answers
A.Enable encryption on the Redshift cluster using AWS KMS.
B.Configure the Redshift cluster to require SSL connections.
C.Use AWS CloudHSM to manage encryption keys for Redshift.
D.Enable VPC Flow Logs on the Redshift subnet.
E.Enable EBS encryption on the Redshift cluster nodes.
AnswersA, B

Enabling encryption on the Redshift cluster with AWS KMS satisfies the at-rest requirement, as it encrypts cluster data and snapshots using customer-managed or AWS-managed keys. This addresses the storage-layer constraint directly, though it does nothing for data in transit, which requires separate SSL/TLS configuration.

Why this answer

Option A is correct because enabling encryption on the Redshift cluster using AWS KMS provides encryption at rest — Redshift uses KMS customer master keys to encrypt the cluster's data blocks and system metadata on disk. Option B is correct because configuring the Redshift cluster to require SSL connections (via the require_ssl parameter set to true in the cluster's parameter group) enforces encryption in transit for all client and JDBC/ODBC connections to the cluster. Option C is not required because Redshift's at-rest encryption is natively managed through AWS KMS, not CloudHSM, and CloudHSM is not a prerequisite for meeting these requirements.

Option D is incorrect because VPC Flow Logs capture IP traffic metadata for network monitoring and do not encrypt data at rest or in transit. Option E is incorrect because Redshift manages its own storage encryption at the cluster level; enabling EBS encryption on cluster nodes is neither a supported nor a required configuration for Redshift data encryption.

43
MCQhard

A data engineer is troubleshooting an AWS Glue ETL job that fails with an access denied error when writing to an S3 bucket. The Glue job uses an IAM role that has an S3 bucket policy attached. The bucket policy denies access to any principal that does not use server-side encryption. What is the most likely cause of the failure?

A.The VPC endpoint policy for S3 is too restrictive.
B.The IAM role does not have s3:PutObject permission.
C.The Glue job is not using server-side encryption when writing to S3.
D.The S3 bucket uses S3 Block Public Access which denies all writes.
AnswerC

The bucket policy denies requests without encryption, causing access denied even if the role has PutObject permission.

Why this answer

If the Glue job does not set the encryption header (or the role does not have the kms:GenerateDataKey permission for SSE-KMS), the bucket policy will deny the request. Option A is wrong because Glue requires permissions on the S3 bucket and KMS key. Option B is wrong because VPC endpoints do not cause access denied errors for encryption.

Option D is wrong because S3 Block Public Access does not deny write access to authorized roles.

44
MCQhard

A company is using an Amazon RDS for PostgreSQL database to store personally identifiable information (PII). The security team wants to ensure that database administrators cannot view the plaintext PII data. Which solution should a data engineer implement?

A.Use IAM policies to restrict DBA access to the RDS instance
B.Enable Dynamic Data Masking in RDS to obfuscate PII for all users
C.Enable encryption at rest for the RDS instance using AWS KMS
D.Use client-side encryption with AWS KMS to encrypt PII before inserting into the database
AnswerD

Client-side encryption with AWS KMS encrypts PII before it reaches PostgreSQL, so ciphertext alone is stored. Database administrators lack the KMS key permissions needed to decrypt, satisfying the requirement that they cannot view plaintext PII. Server-side options such as RDS encryption leave administrators able to read data through SQL queries.

Why this answer

Using AWS KMS with client-side encryption ensures that data is encrypted before being sent to RDS, so database administrators cannot read the plaintext. Dynamic data masking in RDS is not natively supported; application-level masking would be needed. RDS encryption at rest protects data on disk but DBAs with access can still query plaintext.

Using IAM policies to restrict access does not prevent DBAs with database credentials from viewing data.

45
MCQmedium

A company uses AWS Lake Formation to manage data lake permissions. The data lake contains sensitive customer data in the 'customer' database. The security team wants to ensure that only users with a specific tag 'access_level=analyst' can query the 'customer' table. Which combination of steps should the data engineer take to enforce this?

A.In Lake Formation, create an LF-tag 'access_level' with values 'analyst' and 'admin'. Grant 'SELECT' permission on the 'customer' table to the tag value 'analyst'. Associate the LF-tag with the 'customer' table.
B.Create an IAM policy that conditionally allows 'glue:GetTable' based on the tag 'access_level=analyst'.
C.Apply a bucket policy on the S3 location of the 'customer' table that allows access only if the request carries the tag 'access_level=analyst'.
D.Use Lake Formation column-level filters to restrict access to columns based on the tag 'access_level=analyst'.
AnswerA

This uses Lake Formation TBAC to restrict access based on the user's tag.

Why this answer

Lake Formation LF-tags allow you to define metadata tags (key-value pairs) and grant permissions to those tags. By creating an LF-tag 'access_level' with values 'analyst' and 'admin', granting SELECT on the 'customer' table to the tag value 'analyst', and associating that LF-tag with the table, only principals who have the tag 'access_level=analyst' (or are granted via the tag) can query the table. This enforces tag-based access control at the Lake Formation permission layer, which is the intended mechanism for fine-grained, attribute-based access control in Lake Formation.

Exam trap

The trap here is that candidates often confuse IAM tag-based policies (Option B) or S3 bucket policies (Option C) with Lake Formation's native LF-tag mechanism, not realizing that LF-tags are a Lake Formation-specific construct that must be managed within Lake Formation itself, not at the IAM or S3 level.

How to eliminate wrong answers

Option B is wrong because an IAM policy conditionally allowing 'glue:GetTable' based on a tag controls access to the Glue Data Catalog API, but it does not enforce Lake Formation permissions on the underlying data; Lake Formation permissions override IAM policies for registered locations, and this approach would not prevent a user with the tag from querying the table if Lake Formation grants are not also configured. Option C is wrong because S3 bucket policies operate at the object storage layer and cannot evaluate Lake Formation LF-tags; they can use IAM tags via the 'aws:RequestTag' condition key, but this would require the request to carry the tag, which is not how Lake Formation principals are identified, and it would bypass Lake Formation's centralized permission model. Option D is wrong because column-level filters in Lake Formation restrict access to specific columns based on a filter expression, not based on LF-tags; LF-tags are used for row-level or table-level permission grants, not for column-level filtering.

46
MCQmedium

A data engineer manages an AWS Glue Data Catalog table that contains sensitive customer PII. The table's underlying data is in Amazon S3 and is queried by several AWS analytics services. The security team wants to implement column-level access control so that only authorized principals can view the PII columns, while other principals can still query non-sensitive columns. The solution must integrate with AWS Lake Formation and be enforced consistently across all query engines. Which approach should the data engineer take?

A.Implement an S3 bucket policy that allows only certain prefixes and use separate buckets for PII and non-PII data.
B.Create an IAM policy that denies access to the PII columns and attach it to the roles used by the analytics services.
C.Use AWS Glue Data Catalog resource policies to restrict access to specific columns in the table.
D.Register the S3 bucket as a Lake Formation data location, then grant column-level permissions on the table using Lake Formation.
AnswerD

Lake Formation column-level permissions allow granular control over specific columns in a table. By registering the S3 location and granting column-level permissions, the engineer ensures that only authorized principals can access PII columns, and this enforcement is applied across integrated services like Athena, Redshift Spectrum, and Glue ETL. This directly meets the requirement for consistent column-level access control.

Why this answer

Lake Formation column-level permissions are designed to provide fine-grained access control on tabular data in the Data Catalog. By registering the S3 location and granting column-level permissions, the data engineer can restrict access to sensitive columns while allowing queries on other columns. This enforcement is consistent across integrated analytics services.

Exam trap

The trap here is assuming that IAM policies or Glue Data Catalog resource policies can enforce column-level access control, but they operate at different levels and cannot restrict specific columns within a table.

47
Multi-Selectmedium

A company needs to protect sensitive data stored in Amazon S3 from unauthorized access. Which TWO actions should the data engineer take? (Choose two.)

Select 2 answers
A.Configure S3 bucket policies to require MFA for delete operations
B.Enable cross-region replication for all buckets
C.Set up an S3 Lifecycle policy to transition objects to Glacier
D.Enable S3 Block Public Access at the account level
E.Enable S3 Versioning on all buckets
AnswersA, D

Bucket policies requiring MFA for delete operations enforce multi-factor authentication before objects can be removed, guarding against compromised credentials and accidental deletion. This satisfies the protection requirement by adding a strong authentication control at the S3 API layer.

Why this answer

Option A is correct because an S3 bucket policy can include a condition such as aws:MultiFactorAuthPresent to deny s3:DeleteObject or s3:DeleteBucket unless the request is authenticated with MFA, adding a strong control against unauthorized or accidental deletion of sensitive data. Option D is correct because enabling S3 Block Public Access at the account level applies the four block-public-access settings to every bucket in the account, preventing bucket policies or ACLs from exposing objects publicly and thus blocking a major unauthorized-access vector. Option B is not correct because cross-region replication is a durability/availability and compliance feature that copies objects to another region; it does not by itself prevent unauthorized access.

Option C is not correct because a Lifecycle policy transitioning objects to Glacier is a cost/storage-class management action, not an access-control mechanism. Option E is not correct because S3 Versioning preserves prior object versions for recovery but does not restrict who can read or access the data.

48
MCQmedium

A company wants to grant cross-account access to an S3 bucket without using IAM roles. The data engineer needs to write a bucket policy that allows another AWS account to list objects. Which Principal should be specified in the bucket policy?

A.The AWS account ID that owns the bucket
B.The AWS account ID of the other account
C.The IAM user ARN in the other account
D.The root user of the other account
AnswerB

Specifying the other account's AWS account ID as the Principal delegates access at the account level, letting that account's administrators manage their own users without IAM role assumption. This satisfies the stem's constraint of cross-account access without roles, since S3 bucket policies accept account ARNs directly as valid principals.

Why this answer

Specifying the AWS account ID of the other account as the Principal in the bucket policy grants cross-account access to all users and roles in that account, allowing them to list objects. Option A is incorrect because the owning account's ID would grant access to itself, not the other account. Option C is incorrect because specifying an IAM user ARN would restrict access to only that user, not the entire account.

Option D is incorrect because the root user is a specific principal, not the account-wide access needed for cross-account delegation.

49
MCQhard

A data engineer is designing a data lake on Amazon S3 that must comply with a regulatory requirement to prevent any data from being overwritten or deleted for 7 years after creation. Which S3 feature should be used?

A.S3 bucket policy that denies s3:DeleteObject
B.S3 bucket versioning with MFA Delete
C.S3 Object Lock with retention mode set to COMPLIANCE
D.S3 bucket versioning only
AnswerC

S3 Object Lock in COMPLIANCE mode enforces a write-once-read-many (WORM) model, preventing any user, including the root account, from overwriting or deleting objects for the defined retention period. Setting a 7-year retention directly satisfies the regulatory immutability requirement, unlike GOVERNANCE mode, which privileged users can bypass.

Why this answer

S3 Object Lock with retention mode set to COMPLIANCE ensures that objects cannot be overwritten or deleted for the specified retention period (7 years). The retention period cannot be shortened or removed by any user, including the root user, making it suitable for regulatory compliance. Option A is incorrect because a bucket policy that denies s3:DeleteObject can be modified or removed, and it does not prevent overwrites.

Option B is incorrect because MFA Delete requires an additional authentication factor but can still be disabled by an authorized user, and it does not enforce a retention period. Option D is incorrect because bucket versioning alone does not prevent deletion; it only creates delete markers, and objects can still be permanently deleted.

50
MCQeasy

Refer to the exhibit. A data engineer checks the versioning status of an S3 bucket and sees the above output. The bucket contains critical logs that must not be permanently deleted. What should the engineer do to enhance protection against accidental or malicious deletion?

A.Enable MFA Delete on the bucket
B.Enable versioning on the bucket
C.Enable cross-region replication
D.Configure a lifecycle policy to expire noncurrent versions
AnswerA

MFA Delete requires multi-factor authentication for permanently deleting object versions or changing bucket versioning state, so a compromised credential alone cannot purge the critical logs. This directly satisfies the requirement that versioned data must not be permanently deleted.

Why this answer

Enabling MFA Delete on the bucket adds an extra layer of protection by requiring multi-factor authentication for permanently deleting object versions or changing the versioning state. Since the bucket already has versioning enabled (as shown in the exhibit), MFA Delete is the appropriate enhancement to prevent accidental or malicious permanent deletion.

Exam trap

DEA-C01 often tests the difference between versioning, MFA Delete, and Object Lock, so candidates may choose versioning again or lifecycle policies without realizing the exhibit already shows versioning enabled.

How to eliminate wrong answers

Option B is wrong because versioning is already enabled (the exhibit shows versioning status), so enabling it again is redundant. Option C is wrong because cross-region replication provides durability but does not prevent deletion; deleted objects can be replicated as deletions. Option D is wrong because a lifecycle policy to expire noncurrent versions would actually delete older versions, which contradicts the requirement to prevent permanent deletion.

51
MCQhard

A company stores sensitive customer data in an Amazon S3 bucket with versioning enabled. A data engineer accidentally deleted the current version of an object. What is the quickest way to restore the object to its previous state without additional data transfer costs?

A.Use S3 Batch Operations to restore the object from the Recycle Bin.
B.Delete the delete marker that was created by the deletion.
C.Copy the previous version from the bucket to itself.
D.Use the S3 sync command to restore the previous version.
AnswerB

Deleting an object in a versioned bucket inserts a delete marker rather than erasing prior versions. Removing that delete marker restores the object to its previous state instantly, with no data transfer and no re-upload, since the original version's bytes were never removed from the bucket.

Why this answer

With S3 versioning enabled, deleting an object does not permanently remove it; instead, a delete marker is placed. To restore the object to its previous state, you simply remove the delete marker, which makes the previous version the current version again. Option A is incorrect because S3 does not have a Recycle Bin; S3 Batch Operations are for bulk actions but not for restoring from a recycle bin.

Option C would not restore the object properly; copying the previous version to itself would create a new version, not restore the original. Option D is incorrect because the s3 sync command synchronizes objects between locations and does not restore previous versions.

52
MCQeasy

A company uses AWS Glue to process sensitive data stored in Amazon S3. The security team requires that all data in transit between AWS Glue and S3 be encrypted. Which configuration should be used to meet this requirement?

A.Use an S3 bucket policy that denies requests not using HTTPS.
B.Use an AWS KMS key to encrypt the data before uploading to S3.
C.Configure AWS Glue to use SSL by setting the 'ssl' parameter to 'true'.
D.Enable default encryption on the S3 bucket using SSE-S3.
AnswerA

An S3 bucket policy denying requests where aws:SecureTransport is false enforces TLS on every request, so Glue-to-S3 traffic cannot fall back to plain HTTP. This satisfies the in-transit encryption requirement at the bucket level, covering all clients including AWS Glue.

Why this answer

Requiring HTTPS for all requests to the S3 bucket ensures that data in transit between AWS Glue and S3 is encrypted using TLS. By using an S3 bucket policy with a condition that denies requests where `aws:SecureTransport` is false, the company enforces encryption for all connections, including those from AWS Glue. This meets the security requirement without needing to modify Glue or S3 configurations beyond the bucket policy.

Exam trap

The trap here is that candidates often confuse encryption at rest (SSE-S3, SSE-KMS, client-side encryption) with encryption in transit (TLS/HTTPS), and may incorrectly assume that enabling default encryption or using KMS keys secures the data during transfer.

How to eliminate wrong answers

Option B is wrong because encrypting data with an AWS KMS key before uploading to S3 (client-side encryption) protects data at rest, not data in transit; the security team specifically requires encryption in transit. Option C is wrong because AWS Glue does not have an 'ssl' parameter; Glue uses HTTPS by default when connecting to S3, and this setting is not configurable via a simple parameter. Option D is wrong because enabling default encryption on the S3 bucket (SSE-S3) only encrypts data at rest, not data in transit between Glue and S3.

53
MCQmedium

An organization needs to audit all access to their S3 buckets for compliance purposes. They want to log both successful and failed API calls. Which AWS service should be used?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.VPC Flow Logs
AnswerC

CloudTrail records S3 data-plane and management API activity, capturing both successful and failed calls with identity, timestamp and source IP. This satisfies the compliance requirement to audit all bucket access, which S3 server access logging cannot match for failed calls.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made to S3, including both successful and failed requests, and delivers log files to an S3 bucket for auditing and compliance. CloudTrail captures management events (e.g., CreateBucket) and, when enabled, data events (e.g., GetObject, PutObject) for S3, providing a complete audit trail of access.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (API auditing) with AWS Config (configuration auditing) or VPC Flow Logs (network traffic logging), failing to recognize that only CloudTrail captures the specific API call details needed for access auditing.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is used for monitoring, storing, and accessing log files from various AWS services (e.g., EC2, Lambda), but it does not natively capture S3 API calls; it can only receive logs forwarded from CloudTrail or other sources. Option B is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes, not for logging API calls or access events. Option D is wrong because VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol) at the network interface level, not S3 API-level operations or authentication details.

54
MCQmedium

A data engineer needs to ensure that an S3 bucket can only be accessed from a specific VPC. Which policy element should be used?

A.Use the condition key aws:VpcSourceIp in the bucket policy.
B.Use the condition key aws:SourceIp in the bucket policy.
C.Use the condition key aws:SourceVpce in the bucket policy.
D.Use the condition key aws:SourceVpc in the bucket policy.
AnswerD

The aws:SourceVpc condition key evaluates the VPC endpoint through which the request arrives, so the bucket policy denies any traffic not originating from the specified VPC. This directly satisfies the requirement that the bucket be accessible only from that VPC.

Why this answer

The condition key aws:SourceVpc restricts requests to originate from a specific VPC. Option C (aws:SourceVpce) limits access to a VPC endpoint, not the VPC itself. Option B (aws:SourceIp) restricts by IP address, not VPC.

Option A (aws:VpcSourceIp) is not a valid condition key.

55
MCQeasy

A data engineer needs to grant an IAM role read-only access to Amazon DynamoDB tables in a specific AWS account. Which IAM policy element should be used to restrict access to only the 'GetItem' and 'Query' actions?

A.Resource
B.Action
C.Effect
D.Condition
AnswerB

The Action element lists the specific API operations a policy allows or denies, so specifying dynamodb:GetItem and dynamodb:Query grants exactly those read-only calls and nothing else. This directly satisfies the stem's constraint of restricting access to only those two DynamoDB actions within the account.

Why this answer

The Action element in an IAM policy specifies the AWS API operations that the policy allows or denies. To restrict access to only 'GetItem' and 'Query' on DynamoDB tables, you list these actions in the Action element, e.g., 'dynamodb:GetItem' and 'dynamodb:Query'. This directly controls which operations the role can perform, making it the correct choice for limiting permissions to specific actions.

Exam trap

DEA-C01 often tests confusion between IAM policy elements, particularly Action versus Resource, where candidates might mistakenly think Resource specifies the allowed operations instead of the target AWS resources.

How to eliminate wrong answers

Option A is wrong because the Resource element defines the AWS resources (e.g., specific DynamoDB table ARNs) to which the policy applies, not the allowed actions. Option C is wrong because the Effect element specifies whether the policy allows or denies access (Allow/Deny), not which actions are permitted. Option D is wrong because the Condition element adds constraints (e.g., IP range, time) under which the policy is in effect, but does not list the actions themselves.

56
MCQhard

A data engineer manages an Amazon Redshift cluster that contains a table with credit card numbers. The security team requires that the credit card column be stored in encrypted form and that only users with a specific IAM role can see the full values. Other users should see a partially masked value when they query the table. Which Redshift feature should the data engineer use?

A.Redshift row-level security with a policy that filters rows containing credit card numbers.
B.Redshift column-level encryption with a customer managed key in AWS KMS.
C.Redshift Spectrum with an external table that uses a SerDe to mask the credit card column.
D.Redshift dynamic data masking with a masking policy attached to the credit card column.
AnswerD

Redshift dynamic data masking applies a masking policy to a column so that unauthorized users see a masked value at query time, while authorized roles see the full value. It is role-based and does not require changing the stored data. This directly satisfies the requirement to show partial values to most users and full values only to a specific role.

Why this answer

Redshift dynamic data masking attaches a masking policy to a column and evaluates the querying user's role at query time. Authorized roles see the original value, while others see a masked form such as the last four digits. Column-level encryption, Spectrum, and row-level security address different concerns and cannot produce role-based partial masking of a column value.

Exam trap

The trap here is assuming that column-level encryption also masks values for unauthorized users, when it only protects data at rest.

57
Multi-Selectmedium

A data engineer is configuring a data lake on Amazon S3 that contains sensitive customer information. The company requires that all access to this data be logged and monitored, and that any data shared with external partners must be anonymized before leaving the S3 bucket. Which combination of AWS services should the engineer use to meet these requirements? (Choose THREE.)

Select 3 answers
A.AWS WAF
B.AWS Lake Formation
C.AWS CloudTrail
D.AWS Direct Connect
E.Amazon Macie
AnswersB, C, E

Lake Formation provides fine-grained access control and can be used to enforce anonymization policies.

Why this answer

AWS Lake Formation (B) is correct because it provides fine-grained access control and data anonymization capabilities for data lakes on Amazon S3. It allows you to define column-level and row-level security policies, and can automatically anonymize sensitive data (e.g., via masking or tokenization) before it is shared with external partners, ensuring compliance with data governance requirements.

Exam trap

The trap here is that candidates often confuse AWS WAF (a web-layer security tool) with data-level security, or assume Direct Connect provides logging and monitoring, when in fact neither service addresses S3 data access logging or anonymization.

58
MCQeasy

A data engineer needs to grant an AWS Glue ETL job access to read data from an Amazon S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs with an IAM role. Which action must the engineer take to allow the Glue job to decrypt the data?

A.Enable default encryption on the S3 bucket using SSE-S3 instead of SSE-KMS, which eliminates the need for KMS permissions.
B.Attach a policy to the Glue job's IAM role that allows kms:Decrypt and kms:GenerateDataKey on the specific KMS key.
C.Use an S3 Access Point with a policy that allows the Glue job's IAM role to access objects, and configure the access point to use a different KMS key.
D.Modify the S3 bucket policy to allow the Glue job's IAM role to perform s3:GetObject, and rely on S3 to decrypt the data automatically.
AnswerB

For a Glue job to read SSE-KMS encrypted data, its IAM role must have permissions to use the KMS key for decryption. The required permissions are kms:Decrypt and kms:GenerateDataKey (for some operations). Attaching a policy with these actions on the specific key resource grants the necessary access. Without these permissions, the Glue job will fail with access denied errors.

Why this answer

To allow an AWS Glue job to read SSE-KMS encrypted data from S3, the IAM role associated with the Glue job must have permissions to use the KMS key for decryption. Specifically, the role needs kms:Decrypt and kms:GenerateDataKey permissions on the key. S3 bucket policies alone do not grant KMS access, and changing encryption to SSE-S3 or using access points does not satisfy the requirement to use SSE-KMS.

Exam trap

The trap here is assuming that granting s3:GetObject in a bucket policy is sufficient for reading SSE-KMS encrypted objects, when in fact the requester also needs explicit KMS permissions.

59
MCQeasy

A company wants to grant read-only access to an S3 bucket for a data analyst. The analyst should be able to list objects and read object content. Which IAM policy effect and action combination is correct?

A.Effect: Allow, Actions: s3:GetObject, s3:DeleteObject
B.Effect: Allow, Actions: s3:ListAllMyBuckets, s3:GetObject
C.Effect: Allow, Actions: s3:PutObject, s3:GetObject
D.Effect: Allow, Actions: s3:ListBucket, s3:GetObject
AnswerD

ListBucket operates on the bucket resource and GetObject on the object resource, so both actions are required for listing and reading. An Allow effect grants the analyst read-only access without write permissions, matching the least-privilege requirement for listing objects and retrieving their content.

Why this answer

To grant read-only access to an S3 bucket, the policy must allow s3:ListBucket to list objects in the bucket and s3:GetObject to read object content. These actions are the minimum required for read-only access to a specific bucket.

Exam trap

DEA-C01 often tests the distinction between s3:ListBucket and s3:ListAllMyBuckets; candidates might confuse the two, leading to incorrect policies.

How to eliminate wrong answers

Option A is wrong because s3:DeleteObject grants delete permissions, which is not read-only. Option B is wrong because s3:ListAllMyBuckets lists all buckets in the account, not just the specific bucket, and does not grant permission to list objects within the bucket. Option C is wrong because s3:PutObject grants write permissions, which is not read-only.

60
MCQeasy

A company is using AWS Lake Formation to manage permissions on a data lake. They want to grant a data scientist the ability to query tables in the 'analytics' database using Amazon Athena, but prevent them from accessing the underlying S3 data directly. What is the best way to achieve this?

A.Grant the data scientist an IAM policy with s3:GetObject on the S3 bucket.
B.Grant SELECT permission on the 'analytics' database tables in Lake Formation.
C.Create an IAM policy that allows Athena queries only.
D.Add the data scientist to a Lake Formation data lake location with read access.
AnswerB

Lake Formation grants SELECT on the analytics tables, letting the data scientist query them through Athena while Lake Formation mediates access to the underlying S3 objects. Direct S3 access stays blocked because permissions are enforced at the catalog and table level, not through S3 bucket policies.

Why this answer

Lake Formation grants SELECT permission on named database tables, which allows querying via Athena without granting direct S3 access. Option A is incorrect because granting s3:GetObject on the entire bucket would allow the data scientist to bypass Lake Formation and access the data directly. Option C is incorrect because a policy that allows Athena queries only does not grant the necessary permissions to access the database tables.

Option D is incorrect because adding the user to a data lake location with read access is too broad and would also grant direct S3 access, which does not meet the requirement of preventing direct S3 access.

61
MCQhard

A healthcare company uses AWS Lake Formation to manage access to a data lake in Amazon S3. The data lake contains a table with patient records, and the company needs to ensure that only users in the 'Cardiology' department can query columns containing sensitive information such as patient name and diagnosis. Other departments should be able to query non-sensitive columns like patient ID and visit date. The company wants to implement this with the least operational overhead. What should the data engineer do?

A.Create an AWS Glue ETL job that reads the table, filters out sensitive columns based on the user's department, and writes the results to separate S3 buckets for each department. Grant each department access to its respective bucket.
B.Use AWS Identity and Access Management (IAM) policies to deny access to the sensitive columns for all departments except Cardiology. Attach these policies to the IAM roles used by each department.
C.Use Lake Formation column-level security to grant SELECT on the sensitive columns only to the Cardiology department role, and grant SELECT on non-sensitive columns to all other department roles.
D.Configure an Amazon Athena workgroup for each department and use Athena's column-level access control to restrict sensitive columns. Grant each department's users access to their workgroup.
AnswerC

Lake Formation supports column-level permissions, allowing fine-grained access control. By granting SELECT on sensitive columns only to the Cardiology role and on non-sensitive columns to other roles, the engineer enforces the requirement with minimal overhead. Lake Formation manages the permissions centrally, and no additional ETL or view creation is needed. This is the most efficient and secure approach.

Why this answer

Lake Formation column-level security allows granular access control at the column level, enabling the company to grant SELECT on sensitive columns only to the Cardiology department while allowing other departments to query non-sensitive columns. This approach centralizes permission management and requires no data duplication or custom ETL, minimizing operational overhead. It is the intended solution for fine-grained access control in a data lake.

Exam trap

The trap here is assuming that IAM policies can enforce column-level access, but IAM operates at the resource level and cannot restrict individual columns within a table.

62
MCQmedium

A company uses Amazon Redshift for data warehousing. The security team requires that all data stored in Redshift be encrypted at rest using a customer-managed KMS key. How should the data engineer configure this?

A.Enable encryption using a KMS key when creating the Redshift cluster
B.Configure S3 SSE-KMS on the underlying S3 storage
C.Use the AWS KMS console to encrypt the Redshift cluster after creation
D.Set a cluster parameter group with encryption enabled
AnswerA

Specifying a customer-managed KMS key at cluster creation makes Redshift encrypt all data at rest with that key, satisfying the requirement for customer-managed encryption. Redshift cannot retroactively swap the key type, so this must be set during provisioning.

Why this answer

Redshift encryption at rest with a customer-managed KMS key must be specified at cluster creation time via the 'Encrypted' and 'KmsKeyId' parameters (console: 'KMS' encryption option). Once a cluster is created unencrypted, it cannot be converted in place — you must create a new encrypted cluster and migrate data. This satisfies the security team's requirement of a CMK rather than the default AWS-managed key.

Exam trap

DEA-C01 often tests the misconception that Redshift encryption can be enabled after cluster creation or via parameter groups, when in reality it is an immutable creation-time setting requiring cluster recreation or snapshot restore.

How to eliminate wrong answers

Option B is wrong because SSE-KMS on S3 is irrelevant — Redshift stores data on its own managed compute/storage nodes, not in a customer-visible S3 bucket, so S3 encryption settings have no effect on Redshift cluster data. Option C is wrong because the KMS console cannot encrypt an existing Redshift cluster; KMS only manages keys, and Redshift clusters cannot be retroactively encrypted in place. Option D is wrong because cluster parameter groups control engine/runtime settings (e.g., enable_user_activity_logging, max_cursor_result_set_size), not encryption, which is a cluster-level immutable property set at creation.

63
MCQmedium

A data engineering team needs to encrypt data at rest in an Amazon S3 bucket that stores sensitive customer information. The team must use an AWS Key Management Service (AWS KMS) customer managed key with automatic rotation enabled. Which configuration meets these requirements?

A.Use default encryption with SSE-KMS and specify the customer managed key ID.
B.Use default encryption with SSE-S3.
C.Use default encryption with SSE-C and provide a customer-provided key.
D.Use default encryption with SSE-KMS and leave the key ID empty to use the AWS managed key.
AnswerA

SSE-KMS with a customer managed key encrypts objects at rest under a key the team controls, and enabling automatic rotation on that key satisfies the rotation requirement. SSE-S3 and AWS managed keys cannot provide customer-controlled rotation.

Why this answer

It enables SSE-KMS with a customer managed key that supports automatic key rotation, meeting the requirement for a customer managed key with automatic rotation. Option B is incorrect because SSE-S3 uses AWS managed keys that are not customer-controlled and do not support automatic rotation. Option C is incorrect because SSE-C requires the customer to provide and manage their own keys, and does not support automatic rotation.

Option D is incorrect because leaving the key ID empty defaults to the AWS managed KMS key, which is not a customer managed key and does not support automatic rotation.

64
MCQhard

A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The engineer needs to grant a specific IAM role read access to only the columns 'customer_id' and 'purchase_amount' in a table stored in the AWS Glue Data Catalog. The table contains sensitive columns like 'credit_card_number'. Which Lake Formation permission model should the engineer use to achieve this?

A.Grant the IAM role DESCRIBE permission on the table, and then use AWS Glue to create a transformed dataset with only the required columns.
B.Grant the IAM role SELECT permission on the table, and then use an IAM policy to deny access to the sensitive columns.
C.Grant the IAM role SELECT permission on the table, and then create a data filter that includes only the required columns.
D.Create a view in Amazon Athena that selects only the required columns, and grant the IAM role access to the view.
AnswerC

Lake Formation supports column-level security through data filters. A data filter allows you to specify which columns are included or excluded. By granting SELECT on the table and then creating a data filter that includes only customer_id and purchase_amount, the role can access only those columns. This is the correct way to implement column-level access control in Lake Formation.

Why this answer

AWS Lake Formation provides fine-grained access control, including column-level security. To grant read access to specific columns, you grant SELECT permission on the table and then attach a data filter that includes only the allowed columns. Data filters are evaluated at query time, ensuring that the role can only access the specified columns.

This is the most direct and secure method.

Exam trap

The trap here is thinking that IAM policies can enforce column-level access within Lake Formation, when Lake Formation uses its own permission model with data filters.

65
MCQmedium

A company uses Amazon RDS for MySQL to store transactional data. The database contains sensitive financial information. The company's security policy requires that all data at rest be encrypted using a customer-managed KMS key. The database was originally launched without encryption at rest. The security team now needs to enable encryption without significant downtime. What should they do?

A.Create a snapshot of the database, copy the snapshot with encryption enabled, and restore a new DB instance from the encrypted snapshot.
B.Enable encryption by modifying the DB instance's storage type to 'encrypted'.
C.Use the AWS DMS (Database Migration Service) to migrate data to a new encrypted RDS instance.
D.Modify the DB instance and enable encryption under the 'Storage' settings.
AnswerA

RDS does not support encrypting an existing unencrypted instance in place. Snapshot-copy with encryption re-encrypts the data under a customer-managed KMS key, and restoring creates a new encrypted instance, meeting the policy with only the brief downtime of a snapshot restore.

Why this answer

RDS for MySQL does not support enabling encryption at rest on an existing unencrypted DB instance. The only supported method is to take a snapshot, copy the snapshot with encryption enabled using a customer-managed KMS key, and then restore a new DB instance from that encrypted snapshot. This approach requires a brief downtime during the switchover but avoids a full data migration.

Exam trap

DEA-C01 often tests the misconception that you can enable encryption on an existing RDS instance by modifying it, when in fact encryption must be applied at creation or via snapshot restore, leading candidates to choose the modify option.

How to eliminate wrong answers

Option B is wrong because modifying the storage type of an RDS instance does not enable encryption; encryption must be enabled at creation time or via snapshot restore. Option C is wrong because AWS DMS is used for migrating data between different database engines or platforms, and while it could be used, it is not the recommended or simplest method for enabling encryption on an existing RDS instance. Option D is wrong because the RDS modify operation does not provide an option to enable encryption on an existing unencrypted instance; encryption settings are immutable after creation unless you restore from an encrypted snapshot.

66
MCQmedium

A data engineer is configuring an S3 bucket to host sensitive data. The security policy requires that all objects be encrypted with a key that is generated and managed by the customer, and that the key be stored in AWS KMS. Which encryption option should be used?

A.Server-Side Encryption with S3-Managed Keys (SSE-S3)
B.Client-Side Encryption
C.Server-Side Encryption with Customer-Provided Keys (SSE-C)
D.Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
AnswerD

SSE-KMS encrypts objects using keys held in AWS KMS, and selecting a customer managed key means the customer generates and controls that key, including its policy and rotation. SSE-S3 uses AWS-owned keys the customer cannot manage.

Why this answer

SSE-KMS allows you to use customer-managed keys stored in AWS KMS, meeting the requirement for customer-generated and managed keys. Option A is incorrect because SSE-S3 uses AWS-managed keys, not customer-managed. Option B is incorrect because client-side encryption encrypts data outside S3, not using S3 server-side encryption.

Option C is incorrect because SSE-C uses customer-provided keys that you manage yourself, but they are not stored in AWS KMS—you must provide them with each request.

67
MCQmedium

A data engineer is setting up a data pipeline that ingests streaming data from Amazon Kinesis Data Streams into an S3 data lake using Amazon Kinesis Data Firehose. The data contains personally identifiable information (PII). The security team requires that all data be encrypted at rest in S3 using an AWS KMS customer managed key (CMK) that is specific to the application. Additionally, the data must be encrypted in transit between all services. The engineer creates the KMS key and configures Firehose to use server-side encryption with the key for the S3 destination. However, Firehose delivery fails with an error indicating that the KMS key is not accessible. What is the most likely cause?

A.The KMS key policy does not grant the firehose.amazonaws.com service principal the required permissions.
B.The Kinesis data stream is not encrypted at rest.
C.The Firehose delivery stream is not in the same region as the KMS key.
D.The S3 bucket policy does not grant the Firehose delivery stream access to write objects.
AnswerA

Firehose assumes the `firehose.amazonaws.com` service principal to call KMS GenerateDataKey and Decrypt on your behalf, so the CMK's key policy must explicitly grant that principal those actions. Without this grant, the key is inaccessible and delivery fails, even though the IAM role used for S3 access is correctly configured.

Why this answer

When Firehose writes to S3 using SSE-KMS with a customer managed key, the Firehose service principal (firehose.amazonaws.com) must be granted kms:GenerateDataKey and kms:Decrypt in the KMS key policy. Without that grant, Firehose cannot obtain the data key to encrypt objects, and delivery fails with an access-denied error referencing the KMS key. The key policy is the resource-based control that authorizes the service principal.

Exam trap

DEA-C01 often tests the two-layer KMS authorization model — candidates focus on IAM roles or S3 bucket policies and forget that the KMS key policy must explicitly grant the AWS service principal access.

How to eliminate wrong answers

Option B is wrong because Kinesis Data Streams encryption at rest is independent of Firehose's ability to write encrypted objects to S3; an unencrypted stream does not block KMS-based S3 encryption. Option C is wrong because KMS keys are regional and Firehose and the key must be in the same region, but the question states the engineer created the key and configured Firehose, and the error is specifically about key accessibility, not region mismatch. Option D is wrong because an S3 bucket policy denying write access would produce an S3 access-denied error, not a KMS key accessibility error; the failure occurs at the encryption step before the PutObject call.

68
MCQmedium

A media company stores video metadata in an Amazon DynamoDB table. The security team requires that all data at rest in the table be encrypted with a customer managed key in AWS KMS, and that the key usage be auditable. The data engineer needs to configure encryption for the table. Which action should the data engineer take?

A.Use DynamoDB Accelerator (DAX) with encryption in transit enabled, and configure the DAX cluster to use a customer managed KMS key.
B.Enable DynamoDB encryption at rest using the default AWS owned key, and enable CloudTrail logging for DynamoDB.
C.Enable DynamoDB encryption at rest using an AWS managed key, and use AWS CloudTrail to monitor key usage.
D.Create a customer managed KMS key and specify it when creating the DynamoDB table, ensuring the key policy allows DynamoDB to use it for encryption and decryption.
AnswerD

DynamoDB supports customer managed KMS keys for encryption at rest. By specifying the key during table creation and granting DynamoDB permissions in the key policy, the table data is encrypted with that key. KMS key usage is logged in CloudTrail, providing the required auditability. This meets the security team's requirements.

Why this answer

DynamoDB encryption at rest can use customer managed KMS keys. Specifying such a key during table creation ensures the table is encrypted with that key. The key policy must grant DynamoDB permission to use the key.

KMS key usage is logged in CloudTrail, providing auditability. Other options use keys that are not customer managed or do not encrypt the table at rest.

Exam trap

The trap here is assuming that AWS managed keys or DAX provide the same control and auditability as customer managed keys for DynamoDB encryption at rest.

69
MCQhard

A data engineer is configuring an AWS Lake Formation permissions model for a data lake in Amazon S3. Analysts must query a table through Amazon Athena and see only rows where the 'region' column equals 'EU'. The engineer has already registered the S3 location with Lake Formation and created the table in the AWS Glue Data Catalog. Which action should the engineer take to enforce the row-level restriction?

A.Create an IAM policy that allows Athena StartQueryExecution only when the query string contains region='EU'.
B.Create an S3 bucket policy that denies GetObject for objects whose keys do not start with 'EU/'.
C.Create a Lake Formation data filter that includes the expression region='EU' and grant SELECT on the table with that data filter to the analysts' IAM role.
D.Create a separate Athena workgroup for the analysts and configure the workgroup to append a WHERE clause to every query.
AnswerC

Lake Formation data filters allow row-level and cell-level security by attaching a filter expression to a table resource. When you grant SELECT with a data filter, Athena queries automatically include the filter condition, so analysts only see rows where region equals 'EU'. This is the native Lake Formation mechanism for row-level access control without modifying the underlying data.

Why this answer

Lake Formation data filters are the correct mechanism for row-level security. By creating a data filter with the expression region='EU' and granting SELECT with that filter, the analyst's queries through Athena automatically receive the filter condition. This enforcement happens at the Lake Formation permission layer, so it applies consistently regardless of how the query is written, and the underlying data remains unchanged.

Exam trap

The trap here is assuming that IAM policies or S3 bucket policies can enforce row-level filtering, when only Lake Formation data filters operate at that granularity.

70
MCQhard

A company has a requirement to store audit logs for 7 years for compliance. The logs are stored in S3 and must be immutable. Which S3 feature should be used?

A.Use a bucket policy that denies s3:DeleteObject
B.Enable MFA Delete on the bucket
C.Enable S3 Versioning and set a lifecycle policy
D.Enable S3 Object Lock in compliance mode
AnswerD

S3 Object Lock in compliance mode enforces a write-once-read-many (WORM) retention period that no user, including the root account, can shorten or bypass. This directly satisfies the seven-year immutability requirement, unlike governance mode, which privileged users can override.

Why this answer

S3 Object Lock in compliance mode prevents objects from being deleted or overwritten for a specified retention period, ensuring immutability for compliance. Option A is wrong because a bucket policy denying s3:DeleteObject does not prevent overwrites or other actions that could modify the object. Option B is wrong because MFA Delete adds a protection layer but can be bypassed by the root user and does not prevent overwrites.

Option C is wrong because versioning and lifecycle policies do not inherently prevent deletion or overwrite of all versions; they only manage object versions and transitions. Option D is correct.

71
MCQeasy

A company stores sensitive data in Amazon S3 and requires that all data in transit between on-premises applications and S3 be encrypted. The applications use the AWS SDK to upload and download objects. Which configuration should the data engineer implement to enforce encryption in transit?

A.Configure the S3 bucket policy to deny requests that do not use the aws:SecureTransport condition key.
B.Enable default encryption on the S3 bucket using SSE-S3.
C.Enable S3 Transfer Acceleration on the bucket to ensure data is encrypted during transfer.
D.Use AWS Certificate Manager (ACM) to provision a TLS certificate for the S3 bucket.
AnswerA

The aws:SecureTransport condition key checks whether the request was sent over HTTPS. By adding a bucket policy that denies requests where aws:SecureTransport is false, you enforce that all data in transit uses TLS encryption. This is a standard and effective method to enforce encryption in transit for S3.

Why this answer

To enforce encryption in transit for S3, the bucket policy should deny any request that does not use HTTPS, which is indicated by the aws:SecureTransport condition key being false. This ensures that all data transfers between on-premises applications and S3 are encrypted using TLS. Other options address encryption at rest or performance, not in-transit encryption.

Exam trap

The trap here is confusing encryption at rest (SSE-S3) with encryption in transit, which requires enforcing HTTPS via bucket policies.

72
MCQmedium

A data engineer needs to allow an AWS Lambda function to access a specific AWS KMS customer managed key to decrypt data. The Lambda function assumes an IAM role. Which policy statement should be added to the KMS key policy to grant the necessary permissions with least privilege?

A.Allow the IAM role to perform kms:Decrypt on the KMS key, with a condition that the request comes from the Lambda function's VPC endpoint.
B.Allow the IAM role to perform kms:Decrypt on the KMS key, specifying the role's ARN as the principal.
C.Allow the IAM role to perform kms:* on the KMS key, specifying the role's ARN as the principal.
D.Allow the IAM role to perform kms:Decrypt on the KMS key, with a condition that the aws:PrincipalArn matches the role's ARN.
AnswerB

This statement grants the exact permission needed (kms:Decrypt) to the specific IAM role. It follows least privilege by not granting additional actions and by scoping the principal to the role. This is the correct and simplest way to allow the Lambda function to decrypt data using the KMS key.

Why this answer

The KMS key policy must grant the Lambda function's IAM role the kms:Decrypt permission. Specifying the role's ARN as the principal ensures only that role can use the key for decryption. This follows least privilege by not granting unnecessary actions.

Other options either grant excessive permissions or add unnecessary conditions that could hinder legitimate access.

Exam trap

The trap here is granting kms:* or adding unnecessary conditions instead of focusing on the specific kms:Decrypt action needed.

73
MCQhard

A company runs a data lake on AWS using S3 for storage and AWS Glue for ETL. The security team discovers that a contractor who left the company two months ago still has access to an S3 bucket containing sensitive data. The access was granted via an IAM user that was not deleted. The data engineer is asked to implement a solution to prevent future occurrences. The company uses AWS Organizations and has multiple accounts. The requirement is to automatically detect and remediate IAM users that have not been used for 90 days by disabling their access keys and notifying the security team. The solution must be least privilege and use AWS-native services. Which approach should the data engineer take?

A.Use AWS IAM Access Analyzer to generate findings for unused access and create an AWS Config managed rule to automatically disable the IAM user's access keys.
B.Use AWS CloudTrail to monitor IAM user activity and set up a CloudWatch alarm that triggers an SNS notification to the security team to manually disable the keys.
C.Use AWS Lake Formation to revoke the permissions of the IAM user and set up a scheduled Lambda function to check for unused IAM users.
D.Use AWS IAM Access Analyzer to generate findings for unused access and create an AWS Config custom rule with a Lambda function that automatically disables the access keys and sends a notification via SNS.
AnswerD

IAM Access Analyzer surfaces unused-access findings, and an AWS Config custom rule with Lambda disables stale access keys automatically, notifying via SNS. This satisfies the stem's least-privilege, AWS-native requirement for detecting and remediating 90-day-unused IAM users.

Why this answer

AWS IAM Access Analyzer can generate findings for unused access, and AWS Config with a custom rule can auto-remediate by invoking a Lambda function to disable keys and notify via SNS. Option A is incorrect because AWS Config managed rules cannot automatically disable access keys; they only evaluate compliance and require manual action or a custom rule with remediation. Option B is incorrect because CloudTrail and CloudWatch alarms do not automatically disable keys; they only notify for manual intervention.

Option C is incorrect because Lake Formation is used for fine-grained access control on data lakes, not for managing IAM users or disabling access keys.

74
Multi-Selectmedium

A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket encrypted with SSE-KMS and writes to another S3 bucket also encrypted with SSE-KMS. The job uses an IAM role. The security team requires that the job have only the minimum necessary permissions to decrypt and encrypt data. Which TWO actions should be included in the IAM policy attached to the Glue job role? (Choose two.)

Select 2 answers
A.kms:ReEncryptFrom on the KMS key used by the destination S3 bucket.
B.kms:Encrypt on the KMS key used by the source S3 bucket.
C.kms:CreateGrant on both KMS keys to allow S3 to use the keys.
D.kms:GenerateDataKey on the KMS key used by the destination S3 bucket.
E.kms:Decrypt on the KMS key used by the source S3 bucket.
AnswersD, E

When writing objects to the destination S3 bucket with SSE-KMS, S3 uses the KMS key to generate a data key for encryption. The Glue job role must have kms:GenerateDataKey permission on the destination key to allow S3 to encrypt the data on its behalf. This is required for the write operation to succeed.

Why this answer

To read SSE-KMS encrypted objects from the source bucket, the Glue job role needs kms:Decrypt on the source key. To write SSE-KMS encrypted objects to the destination bucket, S3 requires the job role to have kms:GenerateDataKey on the destination key. These two permissions are the minimum required for the job to function while adhering to least privilege.

Exam trap

The trap here is confusing the permissions needed for S3 to use KMS keys with permissions for direct KMS operations like CreateGrant or ReEncrypt.

75
MCQeasy

A company needs to ensure that data stored in Amazon RDS is encrypted at rest. Which action should the data engineer take?

A.Enable encryption at rest by modifying the existing RDS instance.
B.Encrypt the underlying EBS volumes using AWS KMS.
C.Create a new RDS instance with encryption enabled using AWS KMS.
D.Enable SSL/TLS for connections to the RDS instance.
AnswerC

RDS encryption at rest can only be enabled when the instance is created; existing unencrypted instances cannot be encrypted in place. Creating a new instance with encryption enabled using AWS KMS therefore satisfies the requirement directly, unlike modifying an existing instance, which cannot add storage encryption.

Why this answer

Amazon RDS encryption at rest must be enabled when the DB instance is created, using AWS KMS. It cannot be added later. Option A is incorrect because encryption cannot be enabled on an existing RDS instance; you must create a new one with encryption enabled.

Option B is incorrect because encrypting the underlying EBS volumes does not encrypt the RDS database; RDS encryption at rest is separate and must be configured at the instance level. Option D is incorrect because SSL/TLS secures data in transit, not at rest.

Page 1 of 4 · 246 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Data Security Governance questions.