Courseiva

CCNA Data Security Governance Questions

75 of 246 questions · Page 3/4 · Data Security Governance topic · Answers revealed

151
MCQmedium

A data engineering team is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another. The security team mandates that both read and write operations use a customer-managed AWS KMS key so they can audit key usage. Which configuration should the data engineer apply to the Glue job to meet this requirement?

A.Enable default encryption on the S3 bucket with the customer-managed KMS key and rely on Glue to use that default for all operations.
B.Modify the S3 bucket policy to deny any requests that do not include the aws:SecureTransport condition and require the KMS key in the request headers.
C.Add a job parameter --encryption-type sse-kms and specify the KMS key ARN in the job script, then set the Security configuration to use the same key.
D.Create an AWS Glue Security configuration that enables S3 encryption with the customer-managed KMS key for both reads and writes, and attach it to the job.
AnswerD

A Glue Security configuration allows you to specify a KMS key for S3 encryption, which Glue uses when reading from and writing to S3. By attaching this configuration to the job, all data access uses the specified customer-managed key, satisfying the audit requirement. This is the intended mechanism for controlling encryption in Glue jobs.

Why this answer

The correct approach is to use an AWS Glue Security configuration that specifies the customer-managed KMS key for S3 encryption. This configuration is applied at the job level and ensures that Glue uses the key for both reading and writing data. It provides a centralized way to enforce encryption and enables auditing of key usage.

Other methods like bucket policies or default encryption do not guarantee that the Glue job will use the specified key for all operations.

Exam trap

The trap here is assuming that S3 bucket default encryption or bucket policies alone will force AWS Glue to use a specific customer-managed KMS key for both reads and writes.

152
MCQeasy

A data engineer needs to audit all AWS KMS key usage in the account. Which AWS service should be used to record KMS API calls?

A.AWS CloudTrail
B.AWS Config
C.Amazon CloudWatch Logs
D.Amazon GuardDuty
AnswerA

AWS CloudTrail records every KMS API call as a management event, capturing the caller identity, key ARN, timestamp and source IP. This directly satisfies the audit requirement, since KMS operations such as Encrypt, Decrypt and CreateKey are logged automatically to the account's event history and any configured trail.

Why this answer

AWS CloudTrail records API calls for KMS. Option B (AWS Config) is wrong because it records resource changes, not API calls. Option C (Amazon CloudWatch Logs) is wrong because it stores logs but does not record API calls.

Option D (Amazon GuardDuty) is wrong because it is for threat detection.

153
MCQhard

A company wants to audit all changes to IAM policies in their AWS account. Which combination of services should be used to achieve this?

A.AWS Config and Amazon SNS
B.AWS CloudTrail and Amazon CloudWatch Logs
C.Amazon CloudWatch Logs and Amazon SNS
D.AWS CloudTrail and Amazon DynamoDB
AnswerB

AWS CloudTrail records every IAM policy change as a management event, capturing the API caller, timestamp and request parameters. Streaming those trails into Amazon CloudWatch Logs satisfies the audit requirement, enabling metric filters and alarms on specific `PutPolicy` or `CreatePolicy` calls for continuous monitoring.

Why this answer

AWS CloudTrail records all API calls, including IAM policy changes, and can deliver logs to Amazon CloudWatch Logs for monitoring and alerting. This combination provides a comprehensive audit trail and real-time analysis capability.

Exam trap

The trap is confusing AWS Config with CloudTrail. Config is for configuration history, not API auditing. Candidates might also think CloudWatch Logs alone can capture API calls without CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configurations but not API calls; it can track IAM policy changes but lacks the detailed event history of CloudTrail. Option C is wrong because CloudWatch Logs alone does not capture API activity; it needs a source like CloudTrail. Option D is wrong because DynamoDB is a database, not an audit or logging service.

154
MCQmedium

A company needs to enforce encryption in transit for all data moving between its Amazon S3 bucket and a fleet of Amazon EC2 instances. The data is accessed via S3 API calls over the internet. Which configuration ensures encryption in transit?

A.Enable SSE-S3 on the bucket.
B.Enable S3 Transfer Acceleration.
C.Use a VPC endpoint for S3.
D.Configure the bucket policy to deny requests that do not use HTTPS.
AnswerD

A bucket policy with a `aws:SecureTransport` condition set to false denies any request made over plain HTTP, forcing all S3 API calls from the EC2 fleet to use HTTPS/TLS. This directly enforces encryption in transit for internet-based access, satisfying the stem's requirement.

Why this answer

Configuring the bucket policy to deny requests that do not use HTTPS ensures encryption in transit for S3 API calls. Option A is wrong because SSE-S3 encrypts data at rest, not in transit. Option B is wrong because S3 Transfer Acceleration uses a global network but does not enforce encryption; HTTPS must still be used.

Option C is wrong because a VPC endpoint for S3 uses AWS network but does not enforce encryption; the bucket policy must explicitly require HTTPS.

155
Multi-Selectmedium

A company is building a data pipeline that ingests sensitive customer data from an on-premises database into Amazon S3 using AWS DMS. The data must be encrypted at rest in S3 and in transit. The security team requires that the encryption keys be managed by the company (not AWS). Which TWO actions should the data engineer take to meet these requirements? (Choose TWO.)

Select 2 answers
A.Enable encryption at rest using the default DMS encryption settings.
B.Configure the S3 bucket to use server-side encryption with AWS KMS (SSE-KMS) using a customer managed key.
C.Configure the S3 bucket to use server-side encryption with S3 managed keys (SSE-S3).
D.Enable SSL/TLS encryption on the DMS source and target endpoints.
E.Create an AWS KMS key and use it in the DMS endpoint to encrypt data in transit.
AnswersB, D

SSE-KMS with a customer managed key encrypts objects at rest while the company retains control over key rotation and access policy, satisfying the requirement that keys not be AWS-managed. It also complements TLS for the in-transit requirement.

Why this answer

Option B is correct because SSE-KMS with a customer managed key lets the company own and control the KMS key that protects the data at rest in Amazon S3, satisfying the requirement that keys be managed by the company rather than AWS. Option D is correct because enabling SSL/TLS on the DMS source and target endpoints encrypts data in transit between the on-premises database and Amazon S3, which is the required in-transit protection. Option A is incorrect because the default DMS encryption settings do not provide company-managed keys for S3 data at rest.

Option C is incorrect because SSE-S3 uses S3-managed keys, which AWS controls, not the company. Option E is incorrect because KMS keys are used for encryption at rest, not for encrypting DMS data in transit; in-transit encryption is handled by SSL/TLS on the endpoints.

Exam trap

The trap here is that candidates often confuse encryption at rest with encryption in transit, and mistakenly think that KMS keys can be used for both, or that default DMS encryption or SSE-S3 satisfies the customer-managed key requirement.

156
MCQhard

A financial services company uses a multi-account AWS Organization with hundreds of accounts. The data engineering team needs to enable cross-account access to an encrypted S3 bucket in the data lake account (account ID 111111111111) for a Glue ETL job running in the analytics account (account ID 222222222222). The S3 bucket uses AWS KMS customer managed key (CMK) for server-side encryption (SSE-KMS). The Glue job fails with an AccessDenied error when trying to read data from the bucket. The IAM roles in both accounts have the necessary S3 permissions and the bucket policy allows access from the analytics account. What is the most likely cause of the failure?

A.The KMS key policy does not grant the analytics account's IAM role permission to use the key for decryption.
B.The S3 bucket is in a different region than the Glue job.
C.The Glue job does not have an IAM role assigned.
D.The S3 bucket policy does not allow the s3:GetObject action for the analytics account's IAM role.
AnswerA

With SSE-KMS, the caller needs kms:Decrypt on the CMK in addition to S3 permissions. The bucket policy grants S3 access, but the key policy must separately authorise the analytics account's role, so its absence causes the AccessDenied failure.

Why this answer

When an S3 bucket is encrypted with SSE-KMS using a customer managed key (CMK), cross-account access requires that the KMS key policy explicitly grants the external account's IAM role permission to use the key for decryption. Even if the S3 bucket policy allows access, KMS enforces its own key policy, and without a grant for kms:Decrypt, the Glue job in the analytics account cannot decrypt the objects. This is the most likely cause because the scenario states that S3 permissions and bucket policy are already correctly configured.

Exam trap

DEA-C01 often tests the misconception that S3 bucket policies alone are sufficient for cross-account access to encrypted data, ignoring the separate KMS key policy requirement for decryption.

How to eliminate wrong answers

Option B is wrong because a region mismatch would typically produce a different error (e.g., bucket not found or endpoint mismatch) and the scenario does not indicate any regional configuration issue. Option C is wrong because the Glue job must have an IAM role to run at all; if no role were assigned, the job would fail immediately upon creation or with a different error, not an AccessDenied on S3 read. Option D is wrong because the scenario explicitly states that the bucket policy allows access from the analytics account, so the S3 bucket policy is not the missing piece.

157
MCQeasy

Refer to the exhibit. An IAM policy includes the above statement to allow decryption of a KMS key under specific conditions. What does this policy allow?

A.Decrypt any data encrypted with any KMS key
B.Decrypt data that was encrypted with the encryption context {"aws:pi":"db-123"}
C.Encrypt data with the KMS key using the specified encryption context
D.Decrypt data encrypted with the KMS key without any encryption context
AnswerB

The policy's condition matches the encryption context key-value pair aws:pi equal to db-123, so kms:Decrypt succeeds only for ciphertext whose encryption context includes that exact pair, binding decryption to data encrypted under the same context.

Why this answer

Option B is correct because the policy allows the kms:Decrypt action only when the encryption context matches the specified key-value pair. The condition likely uses the StringEquals condition operator on the kms:EncryptionContext:aws:pi key with value db-123. This means decryption is permitted only for ciphertext that was encrypted with that exact encryption context.

Exam trap

DEA-C01 often tests the misunderstanding of encryption context conditions in IAM policies. Candidates may think the policy allows decryption of any data with the key, but the condition restricts it to a specific context.

How to eliminate wrong answers

Option A is wrong because the policy is scoped to a specific KMS key and condition, not any key. Option C is wrong because the action is kms:Decrypt, not kms:Encrypt. Option D is wrong because the condition requires the encryption context to be present and match; decryption without any encryption context would fail the condition.

158
MCQeasy

A data engineer needs to ensure that all data in an S3 bucket is encrypted at rest. The bucket currently contains unencrypted objects from past uploads. Which action will encrypt these existing objects without re-uploading them?

A.Attach a bucket policy requiring SSE-S3
B.Enable default encryption on the bucket
C.Use the S3 console to select all objects and apply encryption
D.Use S3 Batch Operations with an encryption job
AnswerD

S3 Batch Operations applies a batch job that re-encrypts existing objects in place using SSE-KMS or SSE-S3, satisfying the stem's constraint of encrypting past uploads without re-uploading. It reads each object and writes it back encrypted, preserving keys and metadata.

Why this answer

S3 Batch Operations can run an encryption job across existing objects, applying SSE-S3, SSE-KMS, or SSE-C encryption without re-uploading the data. This is the only option that retroactively encrypts already-stored objects in place. Default encryption and bucket policies only affect new uploads, not existing objects.

Exam trap

The trap is assuming that enabling default encryption or a bucket policy retroactively encrypts existing objects — the exam tests whether you know that only a copy/rewrite operation (via Batch Operations or CLI copy) changes encryption on already-stored objects.

How to eliminate wrong answers

Option A is wrong because a bucket policy requiring SSE-S3 only rejects unencrypted PUT requests; it does not encrypt objects already in the bucket. Option B is wrong because enabling default encryption applies only to new objects uploaded after the setting is enabled, leaving existing objects unencrypted. Option C is wrong because the S3 console does not provide a bulk 'apply encryption' action on existing objects; you would have to copy each object, which is effectively re-uploading.

159
MCQhard

A company has an AWS Glue ETL job that reads data from an S3 bucket, transforms it, and writes to another S3 bucket. The security team requires that data in transit between the Glue job and S3 be encrypted using TLS. The Glue job runs in a VPC with a VPC endpoint for S3. Which configuration ensures TLS encryption for all data transfer?

A.Use an S3 Gateway Endpoint and ensure the Glue job uses HTTP instead of HTTPS.
B.Use an S3 Interface Endpoint and disable TLS.
C.Use an S3 Gateway Endpoint and ensure the Glue job uses HTTPS.
D.Enable SSE-KMS encryption on both source and destination S3 buckets.
AnswerC

An S3 Gateway Endpoint keeps traffic to S3 on the AWS private network, so TLS is not applied automatically. Forcing the Glue connection to use HTTPS (s3a:// with SSL enabled) encrypts data in transit, satisfying the security team's TLS requirement.

Why this answer

An S3 Gateway Endpoint keeps traffic between the VPC and S3 on the AWS private network, and when the Glue job is configured to use HTTPS (the default for the AWS SDK and Glue S3 connections), the data in transit is encrypted with TLS. The gateway endpoint itself does not encrypt traffic, but it does not prevent TLS; the key is that the client must use the HTTPS scheme. Combining the gateway endpoint with HTTPS satisfies the requirement for TLS encryption in transit.

Exam trap

The trap is confusing encryption at rest (SSE-KMS) with encryption in transit (TLS); candidates see 'encryption' in the option and pick it without checking whether it applies to data in motion.

How to eliminate wrong answers

Option A is wrong because using HTTP explicitly disables TLS, which directly violates the requirement for encryption in transit. Option B is wrong because disabling TLS on an interface endpoint removes encryption, and interface endpoints are for services like KMS or Secrets Manager, not the standard S3 data path. Option D is wrong because SSE-KMS is encryption at rest, not in transit; it protects objects on disk but does nothing for the TLS requirement between Glue and S3.

160
MCQeasy

A company wants to centrally manage access to multiple AWS accounts for its data engineers. The company already uses AWS Organizations. Which AWS service should be used to define fine-grained permissions across accounts?

A.AWS IAM
B.AWS IAM Identity Center (AWS Single Sign-On)
C.AWS Resource Access Manager (AWS RAM)
D.AWS Key Management Service (AWS KMS)
AnswerB

IAM Identity Center centralises workforce access across all accounts in AWS Organizations, assigning permission sets to users and groups from one place. It provides the cross-account fine-grained permissions the company needs without per-account IAM users.

Why this answer

AWS IAM Identity Center (formerly AWS Single Sign-On) is designed to centrally manage access to multiple AWS accounts within AWS Organizations. It allows you to define fine-grained permissions using permission sets and assign them to users or groups across accounts.

Exam trap

The trap is confusing AWS RAM (resource sharing) with identity management; candidates may also think IAM alone can centrally manage multi-account access, but IAM is per-account and lacks the centralized SSO and permission set features of IAM Identity Center.

How to eliminate wrong answers

Option A is wrong because AWS IAM is account-specific; while it can be used with roles for cross-account access, it does not provide a central place to manage access across multiple accounts in an organization. Option C is wrong because AWS RAM shares resources (e.g., subnets, transit gateways) across accounts, not user permissions. Option D is wrong because AWS KMS manages encryption keys, not user access permissions.

161
MCQeasy

A company uses Amazon Redshift for data warehousing. The security team requires that all data in transit between the Redshift cluster and clients be encrypted. Which feature should be enabled?

A.Client-side VPN
B.SSL/TLS encryption
C.AWS KMS key
D.VPC peering
AnswerB

SSL/TLS encryption secures data in transit between clients and the Redshift cluster, directly satisfying the requirement that all traffic be encrypted. Redshift supports SSL connections, and enabling the `require_ssl` parameter forces every client connection to use TLS, preventing unencrypted access.

Why this answer

Amazon Redshift supports SSL/TLS encryption for client connections to ensure data in transit is encrypted. Option A (Client-side VPN) is not a Redshift feature for encrypting client connections. Option C (AWS KMS key) is used for encrypting data at rest, not in transit.

Option D (VPC peering) does not provide encryption of data in transit between the cluster and clients.

162
MCQhard

A company uses AWS Lake Formation to manage data lakes on Amazon S3. The data engineer needs to grant a data analyst access to query specific columns in a table using Amazon Athena, but deny access to columns containing personally identifiable information (PII). Which Lake Formation feature should be used?

A.Row-level security filters.
B.Column-level permissions in Lake Formation.
C.Tag-based access control with Lake Formation tags.
D.Cell-level security with AWS Glue.
AnswerB

Column-level permissions in Lake Formation restrict access at the individual column granularity, so the analyst can query non-PII columns while PII columns remain denied. This satisfies the stem's requirement to grant selective column access through Athena without exposing sensitive data, since Lake Formation enforces these controls centrally across integrated analytics services.

Why this answer

Lake Formation column-level permissions allow a data engineer to grant SELECT on specific columns of a table while excluding others, which is exactly what is needed to hide PII columns from the analyst. When the analyst queries via Athena, Lake Formation enforces the column filter at query time, returning only the permitted columns. This is the native, fine-grained access control mechanism for column-level restrictions in Lake Formation.

Exam trap

DEA-C01 often tests the confusion between row-level filters (horizontal) and column-level permissions (vertical), and candidates may incorrectly choose tag-based access control when the question asks for the specific column-restriction feature.

How to eliminate wrong answers

Option A is wrong because row-level security filters restrict which rows are visible based on a filter expression, not which columns — they address horizontal, not vertical, data restriction. Option C is wrong because tag-based access control (LF-TBAC) uses tags to scale permission management across many resources, but the question asks for the specific feature that grants column-level access; tags are a management mechanism, not the column-permission primitive itself. Option D is wrong because 'cell-level security with AWS Glue' is not a real Lake Formation feature — Glue does not provide cell-level access control, and Lake Formation is the correct service for fine-grained column/row control.

163
MCQeasy

A data engineer needs to ensure that an Amazon Redshift cluster only accepts encrypted connections. Which parameter should be modified?

A.enable_user_activity_logging
B.max_concurrency_scaling_clusters
C.require_SSL
D.wlm_json_configuration
AnswerC

The require_SSL parameter in the Redshift cluster's parameter group enforces TLS, rejecting unencrypted client connections. Modifying it satisfies the constraint that the cluster accept only encrypted connections, whereas other parameters govern query behaviour or logging rather than transport encryption.

Why this answer

Setting the `require_SSL` parameter to `true` forces all connections to the Amazon Redshift cluster to use SSL/TLS encryption, ensuring that data in transit is encrypted. This parameter is modified in the cluster's parameter group and applies to both JDBC and ODBC connections, as well as the Redshift Query Editor.

Exam trap

The trap here is that candidates may confuse `require_SSL` with other security-related parameters like `enable_user_activity_logging` (auditing) or assume that encryption is handled by a different mechanism (e.g., WLM or concurrency scaling), leading them to pick a wrong option that sounds security-adjacent but is technically unrelated.

How to eliminate wrong answers

Option A is wrong because `enable_user_activity_logging` controls the logging of user activity (e.g., queries run by users) for auditing purposes, not connection encryption. Option B is wrong because `max_concurrency_scaling_clusters` defines the maximum number of concurrency scaling clusters that can be used to handle spikes in concurrent queries, unrelated to encryption. Option D is wrong because `wlm_json_configuration` defines workload management (WLM) queue configurations (e.g., concurrency, memory allocation) and has no effect on SSL/TLS enforcement.

164
MCQeasy

A data engineer is setting up an Amazon RDS for MySQL database. The compliance team requires that all data at rest be encrypted. What must the engineer do to enable encryption for this database?

A.Specify an AWS KMS key when launching the DB instance
B.Enable encryption after the DB instance is created by modifying the DB instance
C.Use AWS Secrets Manager to store the encryption key and attach it to the DB instance
D.Encrypt the underlying EBS volumes after the instance is created
AnswerA

Specifying a customer-managed AWS KMS key at DB instance creation enables encryption at rest for the underlying storage, volumes, snapshots and read replicas, satisfying the compliance requirement. Encryption cannot be enabled retroactively on an existing unencrypted instance; it must be set at launch.

Why this answer

For Amazon RDS, encryption at rest must be enabled at the time of DB instance creation by specifying an AWS KMS key. Once the DB instance is created, you cannot enable encryption by simply modifying the instance; you would need to create an encrypted snapshot and restore it to a new encrypted instance. Therefore, the engineer must specify a KMS key when launching the DB instance to meet the compliance requirement.

Exam trap

DEA-C01 often tests the misconception that encryption can be enabled on an existing RDS instance by modifying it, when in fact it must be set at creation time or via snapshot restore.

How to eliminate wrong answers

Option B is wrong because RDS does not allow enabling encryption on an existing unencrypted DB instance via modification; the only way is to create a snapshot, encrypt it, and restore to a new instance. Option C is wrong because AWS Secrets Manager is used for storing and rotating credentials, not for managing encryption keys for RDS storage encryption. Option D is wrong because you cannot directly encrypt the underlying EBS volumes of an RDS instance; RDS manages the storage and encryption is handled at the service level, not by manual EBS encryption.

165
MCQhard

A data engineer is configuring AWS Glue to crawl a dataset stored in Amazon S3 and populate the AWS Glue Data Catalog. The security team requires that all data in transit between AWS Glue and Amazon S3 be encrypted using TLS. The engineer has already configured the Glue crawler to use a connection with the appropriate VPC settings. What additional step must the engineer take to enforce encryption in transit?

A.Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
B.Configure the Glue crawler to use an S3 endpoint with SSL enabled in the connection options.
C.Set the Glue crawler's security configuration to require SSL for S3 connections.
D.Enable server-side encryption with AWS KMS (SSE-KMS) on the S3 bucket, which automatically enforces TLS for all requests.
AnswerA

To enforce encryption in transit, the S3 bucket policy must include a condition that denies requests when aws:SecureTransport is false. This ensures that any request to the bucket, including from AWS Glue, must use TLS. AWS Glue uses HTTPS by default when accessing S3, so the policy will not block legitimate traffic but will reject unencrypted requests, satisfying the security requirement.

Why this answer

To enforce encryption in transit between AWS Glue and Amazon S3, the engineer must attach a bucket policy that denies requests when aws:SecureTransport is false. This ensures all requests, including those from Glue, use TLS. AWS Glue already uses HTTPS by default, but the bucket policy provides a hard enforcement.

Glue security configurations and connection options do not control TLS for S3, and SSE-KMS is for encryption at rest.

Exam trap

The trap here is confusing encryption at rest (SSE-KMS) with encryption in transit (TLS), and assuming that enabling SSE-KMS or a Glue security configuration will enforce TLS for S3 requests.

166
MCQhard

A data engineer is managing an AWS Glue Data Catalog that contains metadata for tables in Amazon S3. The security team requires that access to the Data Catalog be restricted based on the user's department, and that users can only see tables that belong to their department. The Data Catalog tables are tagged with a 'Department' key. Which AWS feature should the engineer use to enforce this requirement?

A.Amazon S3 bucket policies that restrict access to objects based on the 'Department' tag on the S3 objects.
B.AWS Lake Formation tag-based access control (LF-TBAC) with tags on Data Catalog resources and matching IAM principals.
C.AWS Glue resource policies that allow or deny access based on the 'Department' tag.
D.IAM policies with condition keys that match the 'Department' tag on the Data Catalog tables.
AnswerB

AWS Lake Formation supports tag-based access control, which allows you to define permissions based on tags attached to Data Catalog resources and IAM principals. By tagging tables with a Department key and assigning matching tags to users, you can grant or deny access dynamically. This meets the requirement for department-based access without managing individual table permissions.

Why this answer

AWS Lake Formation tag-based access control (LF-TBAC) allows you to define permissions using tags on Data Catalog resources and IAM principals. This enables attribute-based access control, so users can only access tables with matching tags. This is the recommended way to implement fine-grained, scalable access control for the Glue Data Catalog.

Other options either do not support tag-based filtering for the catalog or address the wrong resource.

Exam trap

The trap here is assuming that IAM policies alone can enforce tag-based access to Glue Data Catalog tables, when Lake Formation is required.

167
Multi-Selecthard

A data engineer is configuring a VPC for an Amazon Redshift cluster. The cluster must be accessible only from a specific on-premises network via a Direct Connect connection. Which TWO actions should the engineer take to meet this requirement? (Choose TWO.)

Select 2 answers
A.Enable Redshift Enhanced VPC Routing.
B.Configure a security group to allow inbound traffic from the on-premises CIDR block.
C.Configure a network ACL to allow inbound traffic from the on-premises CIDR block.
D.Create a VPC endpoint for Redshift.
E.Make the Redshift cluster publicly accessible.
AnswersB, C

A security group is stateful and instance-level, so allowing inbound traffic from the on-premises CIDR block restricts Redshift access to that network only, satisfying the requirement that the cluster be reachable solely via Direct Connect.

Why this answer

Option B is correct because a security group acts as the stateful firewall for the Redshift cluster, and adding an inbound rule that permits the on-premises CIDR block on the Redshift port (5439) is required to allow that specific network to reach the cluster. Option C is correct because the network ACL is the stateless subnet-level control, so it must also include an inbound rule allowing the on-premises CIDR block (and corresponding outbound return traffic) for the connection to succeed. Option A is not needed because Enhanced VPC Routing only affects how COPY/UNLOAD traffic is routed to S3 or other services, not client access from on-premises.

Option D is wrong because a VPC endpoint is for private access to AWS services like S3, not for enabling on-premises clients to reach a Redshift cluster. Option E is wrong because making the cluster publicly accessible would expose it to the internet, violating the requirement to restrict access to the on-premises network only.

168
MCQhard

A data engineer manages an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another bucket. The security team mandates that all data at rest in both buckets be encrypted with customer-managed AWS KMS keys, and that each service use a distinct key. The Glue job's IAM role currently has s3:GetObject and s3:PutObject permissions but jobs fail with an access denied error when writing output. What is the MOST likely cause?

A.The output bucket uses SSE-S3 by default, which overrides the SSE-KMS setting and prevents the customer-managed key from being used.
B.The KMS key policy does not allow the AWS Glue service principal to use the key for cryptographic operations.
C.The S3 bucket policy on the output bucket does not include a statement allowing the Glue job role to perform s3:PutObject.
D.The IAM role lacks kms:GenerateDataKey and kms:Decrypt permissions on the customer-managed KMS key used by the output bucket.
AnswerD

When S3 uses SSE-KMS with a customer-managed key, writing an object requires the caller to have kms:GenerateDataKey on that key, and reading requires kms:Decrypt. The Glue role has S3 permissions but no KMS permissions, so the PutObject call fails with access denied. Adding the required KMS actions on the output key resolves the failure.

Why this answer

Writing to an S3 bucket encrypted with SSE-KMS using a customer-managed key requires both the S3 PutObject permission and KMS permissions on that key, specifically kms:GenerateDataKey for uploads and kms:Decrypt for downloads. The Glue execution role only has S3 permissions, so the KMS authorization check fails and S3 returns access denied. Granting the role the needed KMS actions on the output key fixes the job.

Exam trap

The trap here is focusing only on S3 bucket policies and IAM S3 actions while overlooking that SSE-KMS adds a second authorization layer requiring kms:GenerateDataKey and kms:Decrypt on the key itself.

169
MCQeasy

A data engineer is configuring an AWS Glue crawler to catalog data stored in an Amazon S3 bucket. The security team requires that all data in transit between the crawler and S3 be encrypted using TLS. Which configuration should the engineer implement to meet this requirement?

A.Enable default encryption on the S3 bucket with SSE-S3, which automatically encrypts data in transit.
B.Enable SSL/TLS for the Glue crawler by setting the --enable-ssl parameter in the crawler configuration.
C.Attach a bucket policy to the S3 bucket that denies requests that do not use the aws:SecureTransport condition.
D.Configure the Glue crawler to use a VPC endpoint for S3 and enable encryption in transit on the endpoint.
AnswerC

Enforcing TLS for data in transit to S3 is done by adding a bucket policy that denies requests where aws:SecureTransport is false. This ensures that any request, including from Glue crawlers, must use HTTPS. Glue crawlers use the AWS SDK, which uses HTTPS by default, so they will comply. This is the standard method to enforce encryption in transit for S3.

Why this answer

To enforce encryption in transit for S3, the most direct method is to use a bucket policy that denies requests where aws:SecureTransport is false. This forces all clients, including AWS Glue crawlers, to use HTTPS. Glue crawlers use the AWS SDK, which defaults to HTTPS, so they will continue to work.

This approach is recommended by AWS for compliance with encryption-in-transit requirements.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, and assuming that S3 default encryption covers data in transit.

170
MCQhard

A data engineer is building a data pipeline that ingests sensitive data into Amazon S3 and then processes it with AWS Glue. The security team requires that the data be encrypted at rest using a customer managed key in AWS KMS, and that the engineer be able to audit all key usage. The engineer creates a KMS customer managed key and configures the S3 bucket to use SSE-KMS with that key. The Glue job's IAM role has been granted kms:Decrypt and kms:GenerateDataKey permissions on the key. However, when the Glue job runs, it fails with an access denied error related to KMS. Which additional action should the engineer take to resolve the error?

A.Enable automatic key rotation on the KMS key to ensure the Glue job can retrieve the latest key material.
B.Update the KMS key policy to allow the Glue job's IAM role to use the key for cryptographic operations.
C.Change the S3 bucket encryption to SSE-S3 so that KMS permissions are no longer required.
D.Grant the Glue job's IAM role kms:CreateGrant permission on the KMS key.
AnswerB

KMS key policies are the primary access control for KMS keys. Even if an IAM policy grants kms:Decrypt and kms:GenerateDataKey, the key policy must also allow the principal to use the key. If the key policy does not explicitly grant access to the Glue job's role, access is denied. Updating the key policy to allow the role resolves the error while maintaining least privilege.

Why this answer

KMS key policies must explicitly allow the principal to use the key for cryptographic operations. Even with IAM permissions granting kms:Decrypt and kms:GenerateDataKey, the key policy is the ultimate gatekeeper. The Glue job's role must be listed in the key policy with the necessary permissions.

Updating the key policy resolves the access denied error while adhering to the requirement for customer managed keys and auditable key usage.

Exam trap

The trap here is assuming that IAM permissions alone are sufficient for KMS access, when the key policy must also grant access.

171
MCQmedium

A company uses Amazon S3 to store log files. The security team notices that some objects are being accessed from an unexpected AWS account. The data engineer needs to identify which specific IAM user or role is accessing the objects. Which AWS service should be used to get this information?

A.AWS Trusted Advisor
B.Amazon S3 server access logs
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records the identity of the principal making each S3 data-plane API call, including the IAM user or role ARN and the source account. This satisfies the stem's need to attribute unexpected cross-account object access to a specific identity.

Why this answer

AWS CloudTrail records API activity in your AWS account, including S3 data events such as GetObject, PutObject, and DeleteObject. To identify the specific IAM user or role accessing S3 objects, you need to enable S3 data events in CloudTrail, which will log the identity of the caller. CloudTrail is the correct service for auditing and tracking user activity.

Exam trap

DEA-C01 often tests the difference between S3 server access logs (which lack IAM identity) and CloudTrail data events (which include the IAM principal), leading candidates to choose the wrong service.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides recommendations and best practices checks, but it does not provide detailed access logs or identify specific IAM principals. Option B is wrong because Amazon S3 server access logs record requests to a bucket but do not include the IAM user or role identity; they only show the bucket owner, requester, and other details, but not the IAM principal. Option D is wrong because AWS Config is used for assessing, auditing, and evaluating the configurations of AWS resources, not for tracking API access.

172
MCQeasy

A data engineer needs to restrict access to an Amazon S3 bucket so that only objects encrypted with a specific AWS KMS key can be uploaded. Which S3 bucket policy condition should be used?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.kms:ViaService
C.s3:x-amz-server-side-encryption
D.kms:EncryptionContext
AnswerA

The s3:x-amz-server-side-encryption-aws-kms-key-id condition key inspects the KMS key ID supplied in the upload request, so the bucket policy denies any PutObject not encrypted with the specified key. This directly enforces the stem's single-key upload restriction.

Why this answer

The correct condition is s3:x-amz-server-side-encryption-aws-kms-key-id (option A). This condition key allows you to require that objects uploaded to the S3 bucket are encrypted with a specific AWS KMS key by checking the key ID used in the encryption header. Option B (kms:ViaService) restricts KMS key usage to specific AWS services but does not enforce a key ID on S3 objects.

Option C (s3:x-amz-server-side-encryption) only checks whether server-side encryption is enabled, not the specific key. Option D (kms:EncryptionContext) is used to enforce encryption context, not the key ID.

173
MCQhard

Refer to the exhibit. A data engineer runs the AWS CLI command shown to encrypt a file using AWS KMS. The command succeeds. Later, the engineer tries to decrypt the file using the same key but without providing an encryption context. The decryption fails. What is the most likely reason?

A.The KMS key policy does not allow decryption.
B.The KMS key has been disabled.
C.The plaintext file was corrupted.
D.The encryption context must be provided during decryption.
AnswerD

The encryption context supplied during encryption is cryptographically bound to the ciphertext, so KMS requires the identical key-value pairs to authorise decryption. Omitting them causes the request to fail, satisfying the stem's constraint that the same key alone is insufficient.

Why this answer

When encrypting data with AWS KMS, an encryption context can be provided as additional authenticated data (AAD). This context must be supplied during decryption; otherwise, decryption fails. The command succeeded during encryption, so the key is not disabled (B is wrong) and the key policy is not the issue (A is wrong).

File corruption would cause a different error (C is wrong).

174
MCQeasy

A data engineer is setting up an AWS Glue ETL job that reads data from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that all data in transit be encrypted using TLS. The engineer has configured the job to use the appropriate S3 endpoints. Which additional configuration is necessary to enforce TLS for data in transit between AWS Glue and Amazon S3?

A.Set the AWS Glue job's security configuration to enable S3 encryption in transit.
B.Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
C.Enable default encryption on the S3 bucket using SSE-KMS.
D.Configure the AWS Glue job to use a VPC endpoint for S3 and enable private DNS.
AnswerB

An S3 bucket policy with a condition that denies requests when aws:SecureTransport is false enforces that all requests to the bucket must use TLS. This applies to AWS Glue and any other client, ensuring data in transit is encrypted. This is a standard method to enforce TLS for S3 access.

Why this answer

To enforce TLS for data in transit to S3, you must use a bucket policy that denies requests when aws:SecureTransport is false. This ensures that all access, including from AWS Glue, uses HTTPS. Other options address encryption at rest or network routing, not TLS enforcement.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, or assuming that VPC endpoints automatically enforce TLS. The condition aws:SecureTransport is the key to enforcing TLS.

175
MCQmedium

Refer to the exhibit. A data engineer applies this S3 bucket policy to an S3 bucket. What is the effect of this policy?

A.Allows access only from specific IP addresses.
B.Allows only HTTPS requests to get and put objects, and denies HTTP requests.
C.Allows only GetObject actions over HTTPS.
D.Allows anonymous access to get and put objects over HTTP.
AnswerB

The policy's `aws:SecureTransport` condition evaluates the request protocol, so `"aws:SecureTransport": "false"` in a Deny statement blocks any non-TLS call. This satisfies the stem's requirement to enforce encryption in transit: plain HTTP `GetObject` and `PutObject` attempts are rejected, while HTTPS equivalents remain permitted.

Why this answer

The bucket policy allows GetObject and PutObject actions only when the request uses HTTPS, and explicitly denies all S3 actions when the request uses HTTP due to the condition `aws:SecureTransport=false`. Therefore, only HTTPS requests for Get and Put are permitted. Option A is incorrect because the policy does not restrict by IP addresses.

Option C is incorrect because both Get and Put are allowed over HTTPS, not just Get. Option D is incorrect because the policy does not grant anonymous access; it requires secure transport and does not allow HTTP.

176
MCQeasy

A retail company uses Amazon Redshift for its data warehouse. The security team requires that all data in the cluster be encrypted at rest using a hardware security module (HSM) to manage the encryption keys. The data engineer needs to configure the Redshift cluster accordingly. Which action should the data engineer take?

A.Use Redshift Spectrum to query data in Amazon S3 that is encrypted with an HSM, and enable encryption for the Redshift cluster with AWS KMS.
B.Enable Redshift encryption at rest with an AWS owned key and use AWS CloudHSM to store the key.
C.Enable Redshift encryption at rest using AWS KMS with a customer managed key, and configure the cluster to use an HSM for key storage.
D.Configure the Redshift cluster to use an HSM for encryption at rest by specifying the HSM connection details and enabling encryption when creating the cluster.
AnswerD

Amazon Redshift supports encryption at rest using a hardware security module (HSM) for key management. When creating or modifying a cluster, you can enable encryption and specify an HSM connection. This meets the requirement for HSM-based encryption. The HSM must be configured with the appropriate keys and network access.

Why this answer

Amazon Redshift supports encryption at rest using an HSM. When creating a cluster, you can choose HSM encryption and provide the HSM connection details. This allows the cluster to use keys stored in a hardware security module, satisfying the security team's requirement.

Other options either use KMS or do not encrypt the cluster itself.

Exam trap

The trap here is assuming that AWS KMS or CloudHSM can be used directly for Redshift HSM encryption, when Redshift requires a specific HSM connection configuration.

177
MCQeasy

A company needs to centralize audit logs from multiple AWS accounts into a single S3 bucket. Which service should be used to aggregate these logs?

A.AWS Config
B.Amazon Kinesis Data Firehose
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail delivers account activity events across all accounts to one centralised S3 bucket, satisfying the multi-account aggregation requirement. Its organisation trail captures management and data events from every member account, writing them to a single destination bucket, which is precisely the centralised audit-log consolidation the stem demands.

Why this answer

AWS CloudTrail can be configured to deliver logs from multiple accounts to a single S3 bucket using a trail in the management account. Option C is correct.

178
MCQeasy

A data engineer needs to ensure that data in transit between an Amazon RDS for PostgreSQL database and an application is encrypted. Which configuration should be used?

A.Use VPC peering to connect the application to the database
B.Enable SSL/TLS for the database connection
C.Enable encryption at rest for the RDS instance
D.Use IAM database authentication
AnswerB

SSL/TLS encrypts the wire protocol between the application and PostgreSQL, protecting credentials and query results from interception. Enabling it on the RDS connection satisfies the requirement for encryption of data in transit rather than at rest.

Why this answer

Enabling SSL/TLS for the database connection encrypts the data in transit between the application and the RDS PostgreSQL instance, ensuring confidentiality. Option A (VPC peering) provides network connectivity but does not encrypt traffic. Option C (encryption at rest) protects data stored on disk, not in transit.

Option D (IAM database authentication) controls access but does not encrypt the connection.

179
MCQmedium

A company wants to enable automatic encryption for all new objects written to an S3 bucket. The bucket has existing objects that are unencrypted. Which solution meets these requirements with the least operational overhead?

A.Configure a lifecycle policy to transition objects to a new bucket with encryption
B.Enable default encryption on the bucket using SSE-S3
C.Use S3 server-side encryption with S3 managed keys (SSE-S3) and apply a bucket policy that denies writes without encryption
D.Use S3 Batch Operations to copy existing objects with SSE-S3
AnswerB

Enabling SSE-S3 default encryption applies AES-256 encryption automatically to every new object with no key management, and existing unencrypted objects remain readable. This satisfies both requirements with minimal operational overhead compared with SSE-KMS or re-uploading objects.

Why this answer

Enabling default encryption on the bucket with SSE-S3 causes all new objects written to the bucket to be encrypted automatically without any client-side changes or bucket policy enforcement. It is a single bucket-level setting, so it has the least operational overhead. Existing unencrypted objects remain unencrypted until rewritten, but the requirement only specifies automatic encryption for new objects.

Exam trap

The trap is reading 'existing objects are unencrypted' as a requirement to encrypt them — the question only requires automatic encryption for new objects, so candidates who over-engineer with Batch Operations or bucket policies pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because a lifecycle policy transitions objects between storage classes or expires them — it cannot encrypt objects, and moving to a new bucket does not retroactively encrypt existing data. Option C is wrong because while a bucket policy denying unencrypted PUTs enforces encryption, it requires clients to send encryption headers and can break existing writers; it is more operational overhead than simply enabling default encryption. Option D is wrong because S3 Batch Operations to copy existing objects with SSE-S3 addresses existing objects, not new writes, and adds operational overhead for a requirement that only concerns new objects.

180
MCQhard

A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer grants a data analyst SELECT permission on a table in the AWS Glue Data Catalog. However, when the analyst queries the table using Amazon Athena, they receive an error that they are not authorized to access the underlying S3 data. What is the MOST likely reason?

A.The AWS Glue Data Catalog table is encrypted with SSE-KMS and the analyst lacks kms:Decrypt.
B.The analyst's IAM role lacks the lakeformation:GetDataAccess permission.
C.The analyst's IAM role does not have s3:GetObject permission on the S3 bucket.
D.The S3 bucket is not registered as a data location in Lake Formation.
AnswerD

Lake Formation requires that the S3 location be registered as a data location to manage fine-grained access. Without registration, Lake Formation cannot grant access to the underlying data, even if table permissions are granted. The analyst would need direct S3 permissions or the location must be registered.

Why this answer

For Lake Formation to manage access to data lake data, the S3 bucket must be registered as a data location. Without registration, Lake Formation cannot enforce or grant access to the underlying objects, resulting in authorization errors even when table permissions are granted. Registering the location enables Lake Formation to provide temporary credentials for data access.

Exam trap

The trap here is assuming that granting table permissions in Lake Formation automatically grants access to the underlying S3 data, overlooking the need to register the data location.

181
MCQhard

A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer needs to grant a data analyst read access to specific columns in a table registered in the AWS Glue Data Catalog, while hiding other columns that contain personally identifiable information. The analyst uses Amazon Athena to query the table. Which Lake Formation feature should the engineer use?

A.Use AWS Glue Studio to create an ETL job that copies only the allowed columns to a new table and grant access to that table.
B.Use Lake Formation column-level permissions to grant SELECT on only the allowed columns.
C.Create a resource link to the table and grant SELECT on the link.
D.Apply an IAM policy to the analyst that allows s3:GetObject on the S3 path of the table.
AnswerB

Lake Formation supports fine-grained access control, including column-level permissions. You can grant SELECT on a subset of columns in a table. When the analyst queries via Athena, Lake Formation filters the columns, and the analyst can only see the permitted columns. This directly meets the requirement to hide PII columns while allowing access to others.

Why this answer

Lake Formation column-level permissions allow granular control over which columns a principal can access. By granting SELECT only on specific columns, the analyst can query the table via Athena but will receive errors or filtered results for unauthorized columns. This is the intended feature for hiding PII while enabling access to other data.

Exam trap

The trap here is confusing resource links with column-level permissions; resource links alone do not provide column filtering.

182
MCQmedium

Refer to the exhibit. The S3 bucket policy above is applied to the bucket "example-bucket". An IAM user attempts to upload an object to the bucket without specifying any encryption header. What is the outcome?

A.The upload succeeds but the object is not encrypted
B.The upload fails because GetObject requires encryption
C.The object is uploaded successfully with SSE-S3 encryption by default
D.The upload fails with an Access Denied error
AnswerD

The bucket policy denies `s3:PutObject` unless the request includes the `s3:x-amz-server-side-encryption` header, so an upload without any encryption header fails the condition and is explicitly denied. Because an explicit Deny in a bucket policy overrides any IAM allow, S3 returns Access Denied.

Why this answer

The bucket policy shown requires that any PutObject request include server-side encryption headers (e.g., x-amz-server-side-encryption). Since the IAM user uploads without specifying an encryption header, the condition in the policy is not met, and the request is denied with an Access Denied error. This is the standard behavior of a deny-by-default encryption-enforcement policy.

Exam trap

The trap is assuming S3 default encryption will silently encrypt the object; DEA-C01 tests that an explicit encryption-required bucket policy causes Access Denied when the header is missing.

How to eliminate wrong answers

Option A is wrong because the policy explicitly blocks unencrypted uploads — the object would not be stored unencrypted. Option B is wrong because GetObject is not the operation being attempted; the failure is on PutObject, and GetObject encryption requirements are a separate policy concern. Option C is wrong because S3 does not automatically apply SSE-S3 when a policy requires an explicit encryption header — the request fails before default encryption is considered.

183
MCQeasy

A data engineer needs to ensure that data stored in Amazon S3 is automatically deleted after 30 days. Which S3 feature should be used?

A.S3 Lifecycle policy
B.S3 MFA Delete
C.S3 Versioning
D.S3 Object Lock
AnswerA

An S3 Lifecycle policy defines expiration rules that automatically delete objects after a specified number of days, directly meeting the 30-day deletion requirement. It applies at bucket or prefix level without custom code, unlike versioning or replication, which retain data rather than remove it.

Why this answer

S3 Lifecycle policies can automatically delete objects after a specified time period, such as 30 days. Option B (MFA Delete) requires multi-factor authentication for deletion but does not automate deletion. Option C (Versioning) keeps multiple versions but does not delete.

Option D (Object Lock) prevents deletion or modification but does not schedule automatic deletion.

184
MCQhard

A healthcare company stores patient records in an S3 bucket encrypted with SSE-S3. The data engineering team uses AWS Glue ETL jobs to process this data and load it into an Amazon Redshift cluster for analytics. Recently, the security team mandated that all sensitive data must be encrypted at rest using customer-managed keys (CMK) in AWS KMS, and that the keys must be rotated automatically every year. The team updated the S3 bucket to use SSE-KMS with a CMK and enabled automatic key rotation. However, after the change, the Glue ETL jobs that read from the S3 bucket started failing with 'Access Denied' errors. The Glue job uses an IAM role named 'GlueETLRole' that has the following permissions: s3:GetObject on the bucket, kms:Decrypt and kms:GenerateDataKey on the CMK, and all necessary Glue permissions. The Redshift cluster is also encrypted with a different CMK, and the Glue role has kms:Decrypt on that key as well. What is the most likely cause of the failure?

A.The KMS key policy for the CMK used for S3 encryption does not grant 'GlueETLRole' permission to use the key.
B.The IAM role 'GlueETLRole' does not have kms:Decrypt permission on the CMK used for S3 encryption.
C.The Glue job requires kms:Encrypt permission to read encrypted data from S3.
D.The S3 VPC endpoint policy does not allow the Glue job to access the KMS key.
AnswerA

The CMK's key policy must explicitly allow the GlueETLRole to call kms:Decrypt and kms:GenerateDataKey; IAM permissions alone are insufficient because KMS authorises against both the key policy and the identity policy. Since SSE-KMS now wraps every S3 object read, the missing key policy grant produces the Access Denied failures.

Why this answer

The most likely cause is that the KMS key policy for the CMK used for S3 encryption does not grant 'GlueETLRole' permission to use the key. Even if the IAM role has kms:Decrypt and kms:GenerateDataKey permissions, the KMS key policy must also allow the role to use the key. KMS requires both IAM policy and key policy to grant access.

Exam trap

DEA-C01 often tests the dual-authorization requirement of KMS, and candidates may incorrectly assume that IAM permissions alone are sufficient, overlooking the need for key policy grants.

How to eliminate wrong answers

Option B is wrong because the scenario states the IAM role already has kms:Decrypt and kms:GenerateDataKey on the CMK, so the IAM policy is not the issue. Option C is wrong because reading encrypted data from S3 requires kms:Decrypt, not kms:Encrypt; kms:Encrypt is for writing encrypted data. Option D is wrong because S3 VPC endpoint policies control network access to S3, not access to KMS keys; KMS access is governed by IAM and key policies.

185
MCQmedium

A company needs to automate the detection of sensitive data in Amazon S3 and generate reports. Which AWS service should be used?

A.Amazon Macie
B.Amazon Inspector
C.Amazon GuardDuty
D.AWS Config
AnswerA

Amazon Macie uses machine learning and pattern matching to discover sensitive data such as personally identifiable information across S3 buckets, satisfying the automated detection requirement. It continuously evaluates bucket inventory, assigns severity-based findings, and produces reports, directly meeting the reporting constraint without custom code or manual review.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover and protect sensitive data in Amazon S3. It automatically detects personally identifiable information (PII), financial data, and credentials, and generates detailed findings and reports. This directly matches the requirement to automate sensitive data detection and reporting in S3.

Exam trap

DEA-C01 often tests the confusion between Macie (data discovery in S3), Inspector (vulnerability scanning), and GuardDuty (threat detection), tempting candidates to pick Inspector for 'sensitive data' because it sounds security-related.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and network exposure — it does not detect sensitive data in S3. Option C is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, CloudTrail, and DNS logs — not data classification. Option D is wrong because AWS Config is a configuration compliance service that records resource changes and evaluates them against rules, but it does not perform data-level sensitive content discovery.

186
MCQhard

A data engineer maintains an AWS Glue Data Catalog with databases for several lines of business. Auditors require that every change to table definitions, partition additions, and schema edits in the catalog be recorded with the identity of the caller and that the records be retained for 365 days in a dedicated S3 bucket. Which solution should the data engineer implement?

A.Enable AWS Glue job metrics and continuous logging, then export the logs to Amazon CloudWatch Logs with a retention period of 365 days.
B.Configure an AWS CloudTrail trail that logs management events, including AWS Glue Data Catalog API calls, and deliver the trail to the dedicated S3 bucket with a 365-day lifecycle rule.
C.Turn on AWS Config recording for the AWS::Glue::Table resource type and store configuration snapshots in the dedicated S3 bucket for 365 days.
D.Enable AWS CloudTrail data events for the AWS Glue Data Catalog and deliver the logs to the dedicated S3 bucket with a 365-day lifecycle retention policy.
AnswerB

Data Catalog operations such as CreateTable, UpdateTable, and BatchCreatePartition are management events recorded by CloudTrail. A trail that logs management events captures the caller identity and request details, and delivering to a dedicated S3 bucket with a 365-day lifecycle rule meets the retention requirement for auditors.

Why this answer

AWS Glue Data Catalog mutations such as CreateTable, UpdateTable, and BatchCreatePartition are management events, and a CloudTrail trail that logs management events records the caller identity and request details for each. Delivering that trail to a dedicated S3 bucket with a 365-day lifecycle rule satisfies both the identity-capture and retention requirements, whereas data events, job logs, and AWS Config do not cover these catalog operations.

Exam trap

The trap here is confusing CloudTrail data events with management events, when Data Catalog changes are management events and are not captured by enabling data events.

187
MCQmedium

Refer to the exhibit. A data engineer runs this AWS CLI command to execute an Athena query. What is the purpose of the EncryptionConfiguration parameter?

A.It encrypts the query string in transit
B.It encrypts the data in the source table
C.It enables client-side encryption for the query output
D.It encrypts the query results stored in Amazon S3 at rest
AnswerD

EncryptionConfiguration specifies SSE-S3 or SSE-KMS settings applied to the query result files Athena writes into the S3 query-result location. This satisfies the parameter's purpose: protecting results at rest in Amazon S3, not encrypting data in transit or the source data being queried.

Why this answer

The EncryptionConfiguration parameter in Athena specifies how the query results stored in S3 are encrypted at rest. SSE_S3 means server-side encryption with S3-managed keys. It does not encrypt the query itself, data in transit, or the source data.

188
MCQeasy

A data engineer needs to encrypt data in transit between an Amazon RDS for MySQL instance and an application. Which solution should be used?

A.Enable encryption at rest using AWS KMS
B.Use SSL/TLS to connect to the RDS instance
C.Store the data in Amazon S3 with server-side encryption
D.Use AWS CloudHSM to generate and store encryption keys
AnswerB

SSL/TLS encrypts the wire protocol between the application and the RDS for MySQL endpoint, satisfying the in-transit encryption requirement. RDS MySQL supports TLS connections natively; clients negotiate certificates during the handshake, protecting credentials and query data from interception. Encryption at rest options such as KMS keys do not address data moving across the network.

Why this answer

Encryption in transit for an RDS for MySQL instance is achieved by connecting with SSL/TLS, which encrypts the wire protocol between the application and the database. RDS MySQL supports TLS and provides an rds-ca certificate that the client uses to verify the server. Enabling SSL/TLS on the connection is the direct, correct answer for data in transit.

Exam trap

DEA-C01 often tests whether candidates confuse encryption at rest (KMS, SSE) with encryption in transit (TLS/SSL) — the phrase 'in transit' is the key discriminator, and options mentioning KMS or S3 encryption are the classic distractors.

How to eliminate wrong answers

Option A is wrong because AWS KMS encryption at rest protects data on the underlying storage volume, not the network path between the application and the database. Option C is wrong because storing data in S3 with SSE is a different storage service and does not encrypt the RDS connection; it also changes the architecture rather than securing the existing path. Option D is wrong because CloudHSM generates and stores keys for encryption at rest or custom key operations, not for encrypting the MySQL client-server transport.

189
Multi-Selecthard

A financial services company needs to share sensitive customer data with a third-party analytics firm. The data resides in an S3 bucket encrypted with an AWS KMS customer managed key. The third party has their own AWS account. Which combination of steps is required to securely share the data? (Choose TWO.)

Select 2 answers
A.Share the KMS key material with the third party
B.Update the KMS key policy to include the third-party account as a principal with kms:Decrypt permission
C.Create an IAM role in the third-party account that can be assumed by the data owner
D.Grant the third-party account access to the KMS key management
E.Configure an S3 bucket policy that grants the third-party account access to the objects
AnswersB, E

The KMS key policy must name the third-party account as a principal granted kms:Decrypt, because key policies govern who may use a customer managed key. Without this grant, cross-account decryption of the S3 objects fails regardless of bucket permissions.

Why this answer

Option B is correct because when an S3 object is encrypted with a customer managed KMS key, any principal in another AWS account must be explicitly granted kms:Decrypt on that key via the key policy (or a grant); the key policy is the primary cross-account authorization mechanism for KMS keys. Option E is correct because the third-party account also needs S3-level permission to read the objects, which is provided by a bucket policy granting actions such as s3:GetObject to the third-party principal. Together, the bucket policy authorizes the S3 data access and the KMS key policy authorizes decryption of the objects.

Option A is wrong because KMS key material is never exported or shared; the third party uses the key through KMS APIs without ever seeing the material. Option C is wrong because creating a role in the third-party account assumable by the data owner reverses the trust direction and does not grant the third party access to the data. Option D is wrong because key management (e.g., kms:CreateGrant, kms:PutKeyPolicy) is not needed and would over-privilege the third party; only kms:Decrypt is required.

190
MCQhard

A company has an AWS Glue ETL job that reads from an RDS MySQL instance and writes to S3. The security team requires that the connection to RDS be encrypted and that credentials be rotated automatically. Which configuration should be used?

A.Store the database password in an encrypted parameter in Systems Manager Parameter Store and enable SSL for the connection.
B.Use IAM database authentication for RDS and store credentials in Glue connection properties.
C.Store the password in a text file in an encrypted S3 bucket and use SSL.
D.Store the password in AWS Secrets Manager with automatic rotation enabled and configure Glue to use SSL for the connection.
AnswerD

Secrets Manager with automatic rotation directly satisfies the credential-rotation constraint, unlike static Glue connection passwords. Enabling SSL encrypts data in transit between Glue and RDS MySQL, meeting the encryption requirement. Together these address both security mandates without custom rotation logic or manual credential updates.

Why this answer

AWS Secrets Manager provides automatic rotation of RDS credentials, and AWS Glue can be configured to use SSL for an encrypted connection to RDS MySQL. Option A (Systems Manager Parameter Store) stores encrypted parameters but does not natively support automatic rotation of RDS credentials. Option B (IAM database authentication) provides authentication but does not encrypt the connection itself; SSL is still required for encryption.

Option C (encrypted S3 bucket) is not a service designed for dynamic credential management and lacks automatic rotation.

191
MCQmedium

A data engineer is building an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to an Amazon Redshift cluster. The security team requires that the data be encrypted in transit between Glue and Redshift. Which configuration should the engineer implement to meet this requirement?

A.Enable SSL in the Redshift connection by setting the sslmode parameter to 'require' in the JDBC URL used by the Glue job.
B.Use AWS Glue's built-in encryption feature by setting the --encryption-type parameter to 'ssl' in the job configuration.
C.Enable encryption on the Redshift cluster by turning on cluster encryption, which automatically encrypts data in transit.
D.Configure the Glue job to write to Redshift using the Redshift Spectrum feature, which automatically encrypts data in transit.
AnswerA

Amazon Redshift supports SSL encryption for connections. To enforce encryption in transit between Glue and Redshift, the JDBC connection must use SSL. Setting sslmode=require in the JDBC URL ensures that the connection uses SSL and fails if SSL is not available. This is the standard method to encrypt data in transit for Redshift connections from Glue.

Why this answer

To encrypt data in transit between AWS Glue and Amazon Redshift, the Glue job must establish an SSL connection to Redshift. This is done by adding sslmode=require to the JDBC URL in the Glue connection. This ensures that the connection uses SSL and rejects non-SSL connections.

Other options either address encryption at rest or are not applicable to the scenario.

Exam trap

The trap here is confusing encryption at rest (cluster encryption) with encryption in transit (SSL/TLS), and assuming that enabling cluster encryption covers in-transit encryption.

192
MCQhard

A data engineer is troubleshooting an ETL job that reads from an S3 bucket encrypted with SSE-KMS. The job is failing with an error indicating that the IAM role does not have permission to decrypt the data. What is the most likely missing permission?

A.kms:GenerateDataKey
B.s3:ListBucket
C.kms:Decrypt
D.s3:GetObject
AnswerC

SSE-KMS requires the caller to hold kms:Decrypt on the customer-managed key before S3 can return the object. The role's S3 permissions are irrelevant here; the missing KMS grant is what blocks the ETL job's reads.

Why this answer

When an S3 object is encrypted with SSE-KMS, reading the object requires two sets of permissions: s3:GetObject on the object and kms:Decrypt on the KMS key used to encrypt it. The error explicitly states the IAM role lacks permission to decrypt, so the missing permission is kms:Decrypt. Without it, S3 cannot call KMS to decrypt the data key, and the GetObject call fails with AccessDenied.

Exam trap

The trap is assuming that s3:GetObject alone is sufficient to read SSE-KMS encrypted objects, ignoring the separate KMS permission required for decryption.

How to eliminate wrong answers

Option A is wrong because kms:GenerateDataKey is needed for writing (PutObject) with SSE-KMS, not for reading existing encrypted objects. Option B is wrong because s3:ListBucket controls the ability to list objects in a bucket, which is unrelated to decryption and would produce a different error. Option D is wrong because s3:GetObject is the permission to read the object itself; if it were missing, the error would be about S3 access, not KMS decryption.

193
MCQeasy

A company wants to audit all changes to IAM policies in their AWS account. Which AWS service should be used to record these changes for compliance purposes?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon S3
AnswerC

AWS CloudTrail records API activity, capturing every IAM policy change as a management event with the caller's identity, timestamp and source IP. This satisfies the audit requirement by providing an immutable, queryable log of who modified which policy and when, which CloudWatch metrics or Config rules alone cannot deliver.

Why this answer

AWS CloudTrail records API calls, including IAM policy changes. AWS Config records resource configurations but not all API calls. CloudWatch Logs can store logs but does not record API calls itself.

S3 is the destination for logs, not the recording service.

194
MCQmedium

A data engineer is using AWS Lake Formation to manage fine-grained access to a data lake in Amazon S3. The engineer grants a data analyst SELECT permission on a table but wants to ensure that the analyst cannot access columns containing sensitive data such as social security numbers. The table is registered in the AWS Glue Data Catalog. Which Lake Formation feature should the engineer use to restrict access to specific columns?

A.Row-level security using filter expressions in Lake Formation.
B.S3 bucket policies with prefix-based restrictions.
C.AWS Glue Data Catalog resource policies.
D.Column-level security in Lake Formation permissions.
AnswerD

Lake Formation supports column-level security by allowing you to grant or deny access to specific columns within a table. When granting SELECT on a table, you can exclude sensitive columns, ensuring the analyst can query only approved columns. This directly meets the requirement without duplicating data.

Why this answer

Lake Formation column-level security allows granting SELECT on a subset of columns, effectively hiding sensitive columns from unauthorized users. Row-level security filters rows, not columns. Glue Data Catalog policies and S3 bucket policies do not provide column-level granularity for query engines.

Exam trap

The trap here is mixing up row-level and column-level security features in Lake Formation, or assuming that S3 or Glue policies can enforce column-level access.

195
MCQeasy

A data engineer needs to audit all changes to IAM policies in an AWS account. Which AWS service should be used?

A.AWS CloudTrail
B.AWS Config
C.AWS Organizations
D.Amazon CloudWatch Logs
AnswerA

CloudTrail records all API activity for auditing.

Why this answer

WS CloudTrail because it records API calls made in the account, including changes to IAM policies. AWS Config tracks resource configuration changes, not API calls. AWS Organizations is for multi-account management.

Amazon CloudWatch Logs is for log storage and monitoring, not auditing API calls.

196
MCQmedium

A healthcare company stores patient records in an Amazon S3 bucket and uses AWS Lake Formation to manage access for multiple analytics teams. The compliance team requires that any column containing patient identifiers be masked by default for all users except a privileged data steward role. Which Lake Formation feature should the data engineer implement to meet this requirement?

A.Enable S3 Object Lock in governance mode on the bucket to prevent unauthorized access to sensitive objects.
B.Use AWS Glue DataBrew to create a masking recipe that anonymizes the sensitive columns before granting access.
C.Configure a data filter that excludes sensitive columns from the table definition.
D.Create a Lake Formation tag-based access control policy that attaches LF-Tags to the sensitive columns and grants access only to the steward role.
AnswerD

Lake Formation tag-based access control (LF-TBAC) allows you to attach LF-Tags to databases, tables, and columns, and then grant permissions based on those tags. By tagging sensitive columns and granting access only to the steward role, all other users are denied access to those columns by default. This satisfies the requirement to mask by default while allowing the steward full access.

Why this answer

Lake Formation tag-based access control enables attribute-based permissions where LF-Tags on columns determine access. Tagging sensitive columns and granting only the steward role access ensures all other users are denied those columns by default, effectively masking them. This is a native Lake Formation governance feature that integrates with analytics services and provides fine-grained control without duplicating data.

Exam trap

The trap here is assuming that data filters in Lake Formation can mask column values, when they actually restrict rows or hide columns entirely.

197
Multi-Selectmedium

A company is building a data lake on AWS and must encrypt data at rest. Which services can provide server-side encryption for data stored in Amazon S3? (Choose TWO.)

Select 2 answers
A.SSE-S3
B.SSL/TLS
C.AWS SDK client-side encryption
D.AWS CloudHSM
E.SSE-KMS
AnswersA, E

SSE-S3 applies AES-256 encryption with keys fully managed and rotated by AWS, requiring no key configuration from the engineer. It satisfies the data-at-rest encryption requirement for S3 objects while removing customer key management overhead entirely.

Why this answer

SSE-S3 (Option A) is correct because Amazon S3 server-side encryption with S3-managed keys (AES-256) encrypts objects at rest automatically, with AWS managing the key material and rotation. SSE-KMS (Option E) is also correct because it performs server-side encryption at rest using AWS KMS customer master keys (CMKs), giving you control over key policies, auditing, and rotation. Both are S3 server-side encryption modes applied after data reaches S3, satisfying the data-at-rest requirement.

SSL/TLS (Option B) is wrong because it only encrypts data in transit between the client and S3, not at rest. AWS SDK client-side encryption (Option C) is wrong because it encrypts data before it is sent to S3, so it is client-side, not server-side. AWS CloudHSM (Option D) is wrong because it is a dedicated hardware security module service for key storage and cryptographic operations, not an S3 server-side encryption option by itself.

Exam trap

DEA-C01 often tests whether candidates confuse encryption at rest (SSE-S3, SSE-KMS) with encryption in transit (SSL/TLS) or client-side encryption, and may mistakenly select CloudHSM as a direct S3 encryption option.

198
MCQmedium

A data engineer must give an Amazon Redshift cluster the ability to load data from an Amazon S3 bucket using the COPY command. The security team prohibits embedding long-term AWS credentials in SQL and requires that access be revoked automatically when the cluster is deleted. The S3 bucket is encrypted with SSE-KMS using a customer managed key. Which approach should the data engineer use?

A.Configure the cluster with a database user that has a password stored in AWS Systems Manager Parameter Store and grant that user access to the S3 bucket through a bucket ACL.
B.Use the COPY command with the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters populated from an IAM role's temporary credentials obtained by calling AssumeRole from an external application.
C.Create an IAM user with an access key, store the key in AWS Secrets Manager, and pass the secret ARN to the COPY command using the CREDENTIALS clause.
D.Attach an IAM role to the Redshift cluster, grant the role s3:GetObject on the bucket and kms:Decrypt on the customer managed key, and reference the role ARN in the COPY command.
AnswerD

Attaching an IAM role to the cluster provides temporary credentials that Redshift assumes automatically, so no long-term keys appear in SQL. Granting s3:GetObject and kms:Decrypt allows the COPY to read SSE-KMS encrypted objects. Because the role is attached to the cluster, deleting the cluster removes the role association, satisfying automatic revocation.

Why this answer

Attaching an IAM role to the Amazon Redshift cluster lets the COPY command assume temporary credentials without any long-term keys in SQL. The role needs s3:GetObject on the bucket and kms:Decrypt on the customer managed key to read SSE-KMS encrypted objects. Because the role is associated with the cluster, deleting the cluster removes that association, so access is revoked automatically as the security team requires.

Exam trap

The trap here is assuming the COPY command can accept arbitrary credential parameters, when the supported credential-free path is an IAM role attached to the cluster referenced by ARN.

199
MCQmedium

A data engineer must mask the last four digits of a credit card column in an Amazon Redshift table so that analysts in a specific role see masked values while a fraud team sees the full values. The engineer wants a solution that applies to all queries without modifying each analyst's SQL. Which approach should the engineer use?

A.Create a view that applies a masking expression to the credit card column and grant the analyst role access only to the view.
B.Encrypt the credit card column with AWS KMS and grant the analyst role decrypt permissions on a different key than the fraud team.
C.Use row-level security to restrict the analyst role to rows where the credit card column is not null.
D.Create a dynamic data masking policy with the credit card column, then attach it to the analyst role so masking applies automatically at query time.
AnswerD

Redshift dynamic data masking policies are attached to roles and applied automatically whenever a user in that role queries the column, so no SQL changes are required. The fraud team, not attached to the masking policy, continues to see full values. This satisfies both the blanket masking requirement and role-based visibility in a single column-level control.

Why this answer

Redshift dynamic data masking attaches a masking policy to a role, so any query by that role against the tagged column returns masked values automatically, with no SQL rewriting. Users in roles without the policy see the original data. This provides column-level, role-based protection that satisfies both teams' visibility needs.

Exam trap

The trap here is choosing row-level security or a masking view, when only dynamic data masking changes column values transparently per role without altering queries.

200
MCQmedium

A financial services company uses AWS Glue ETL jobs to process sensitive customer data stored in Amazon S3. The data is encrypted at rest with SSE-KMS using a customer-managed key. Recently, the security team discovered that the Glue job's IAM role has an overly permissive policy that allows the 'kms:Decrypt' action for all KMS keys in the account. The company wants to follow the principle of least privilege. The Glue job runs on a schedule and reads from a specific S3 bucket. The security team needs to update the IAM policy to restrict KMS decryption to only the specific key used for that bucket. What should they do?

A.Update the policy to allow 'kms:Decrypt' with a resource of 'arn:aws:kms:us-east-1:123456789012:key/*' to cover all keys in the account.
B.Update the policy to allow 'kms:Decrypt' with a resource of '*' to ensure the job can always decrypt data.
C.Update the policy to allow 'kms:Decrypt' only for the specific KMS key ARN used by the S3 bucket containing the customer data.
D.Remove the 'kms:Decrypt' action from the policy and rely on S3 bucket policies to grant decryption permissions.
AnswerC

Restricting the Resource element to the specific KMS key ARN satisfies the least-privilege constraint, since AWS evaluates the Resource field against the key's ARN during the kms:Decrypt authorisation call. The Glue job's IAM role then decrypts only data encrypted under that customer-managed key, eliminating access to every other key in the account.

Why this answer

To follow least privilege, the IAM role for the Glue job should only have access to decrypt using the specific KMS key that encrypts the S3 bucket containing the customer data. This is done by allowing 'kms:Decrypt' with a resource set to the exact ARN of that key, not a wildcard or all keys. Option A is incorrect because using a wildcard in the key ARN (key/*) still grants access to all keys under that key hierarchy, which is overly permissive.

Option B is incorrect because allowing 'kms:Decrypt' with resource '*' would grant access to all keys in the account, violating least privilege. Option D is incorrect because removing 'kms:Decrypt' from the IAM policy would prevent the Glue job from decrypting the data; the job's IAM role needs the permission, and relying solely on S3 bucket policies cannot grant decryption permissions cross-account or for IAM roles.

201
MCQmedium

A data engineer needs to allow an IAM user to rotate the secret in AWS Secrets Manager for an RDS database. Which IAM action should be included in the policy?

A.secretsmanager:RotateSecret
B.secretsmanager:PutSecretValue
C.secretsmanager:UpdateSecret
D.secretsmanager:GetSecretValue
AnswerA

The `secretsmanager:RotateSecret` action authorises triggering immediate rotation of a stored secret, satisfying the requirement to rotate the RDS credential. It differs from `PutSecretValue`, which merely writes a new value without invoking the rotation Lambda, and from `UpdateSecret`, which modifies metadata or encryption rather than performing rotation.

Why this answer

The secretsmanager:RotateSecret action allows the user to initiate rotation of a secret. Option A is correct. secretsmanager:GetSecretValue only retrieves the secret value, not rotate it.

202
MCQeasy

A data engineer needs to ensure that an Amazon S3 bucket containing sensitive customer data is encrypted at rest. Which AWS service can be used to manage the encryption keys?

A.AWS Certificate Manager
B.AWS Secrets Manager
C.AWS CloudHSM
D.AWS Key Management Service (KMS)
AnswerD

AWS KMS centrally creates, rotates and controls the customer-managed keys used for S3 server-side encryption (SSE-KMS), satisfying the encryption-at-rest requirement. KMS also provides audit trails of key usage through CloudTrail, giving the key management capability the scenario demands.

Why this answer

AWS Key Management Service (KMS) is the managed service for creating, rotating, and controlling the keys used to encrypt data at rest in S3 (SSE-KMS). It integrates natively with S3 so that objects are encrypted with a KMS customer master key, and access to the key is governed by IAM and key policies. This is the standard answer for managing S3 encryption keys.

Exam trap

DEA-C01 often tests whether candidates confuse services that manage different secret types — ACM handles TLS certificates, Secrets Manager handles credentials, and KMS handles encryption keys, so candidates who pick ACM or Secrets Manager for S3 key management fall into the trap.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager manages TLS/SSL certificates for encryption in transit, not data-at-rest encryption keys. Option B is wrong because Secrets Manager stores and rotates secrets such as database credentials and API keys, not encryption keys for S3 objects. Option C is wrong because CloudHSM is a dedicated hardware security module for custom key management and is not the managed service used for standard S3 SSE-KMS encryption; it is used when you need single-tenant HSM control.

203
Multi-Selectmedium

A company is using AWS Lake Formation to manage permissions on a data lake. Which of the following are valid ways to grant access to a user or role? (Choose THREE.)

Select 3 answers
A.Grant permissions to a SAML or SCIM group
B.Grant permissions using tag-based access control (LF-Tags)
C.Grant permissions to an IAM user or role
D.Grant permissions to an AWS Organizations unit
E.Grant permissions via an S3 bucket policy
AnswersA, B, C

Lake Formation integrates with SAML and SCIM identity providers, so permissions granted to an external group propagate to its members without per-user grants. This satisfies the stem's requirement for valid access-granting methods, alongside IAM principals and tag-based LF-TBAC grants, reducing administrative overhead.

Why this answer

Lake Formation supports granting permissions directly to IAM users and roles (option C), which is the fundamental way principals are identified in AWS. It also supports granting permissions to SAML or SCIM groups (option A), allowing federated identities to inherit Lake Formation permissions through their group membership. Additionally, Lake Formation supports tag-based access control using LF-Tags (option B), where permissions are granted on tags and then associated with resources and principals.

Option D is incorrect because Lake Formation does not grant permissions to AWS Organizations units; it works with IAM principals and federated groups, not OUs directly. Option E is incorrect because S3 bucket policies are an S3-level access mechanism and do not grant Lake Formation permissions, which are managed within Lake Formation's own permission model.

Exam trap

Tag-based access control (LF-Tags) is a valid method in Lake Formation, similar to IAM resource tags, but it is specific to Lake Formation.

204
MCQmedium

A data engineer is troubleshooting an Amazon Redshift cluster that is not responding to queries. The engineer suspects that the cluster may have been accidentally deleted. Which AWS service should be used to investigate the deletion?

A.AWS Config
B.AWS CloudTrail
C.Amazon CloudWatch Logs
D.AWS Trusted Advisor
AnswerB

AWS CloudTrail records DeleteCluster API calls, capturing the identity, source IP and timestamp of the deletion. This event history lets the engineer confirm whether the cluster was deleted, by whom, and when, which CloudWatch metrics or cluster logs alone cannot establish.

Why this answer

AWS CloudTrail records API activity in an AWS account, including the DeleteCluster API call that would be logged when a Redshift cluster is deleted. By querying CloudTrail event history or a trail's logs, the engineer can identify who deleted the cluster, when, and from which source IP. This makes CloudTrail the correct service for investigating the deletion event itself.

Exam trap

DEA-C01 often tests the confusion between CloudTrail (API audit/activity) and AWS Config (resource configuration history), since both can show that a resource no longer exists but only CloudTrail reveals who made the API call.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and compliance state over time, but it does not capture the API caller identity or the specific delete request details needed to investigate who performed the deletion. Option C is wrong because CloudWatch Logs stores application and service log output, not AWS API audit events — Redshift cluster deletion is an API action, not a log stream event. Option D is wrong because Trusted Advisor provides best-practice checks and recommendations, not an audit trail of API calls or deletion events.

205
MCQmedium

A data engineer is configuring an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to another S3 bucket. The security team requires that data be encrypted at rest using a customer-managed AWS KMS key, and that the Glue job be able to decrypt the source data and encrypt the target data. The engineer has already created a KMS key and attached a key policy that allows the Glue service role to use the key for encrypt and decrypt operations. However, when the job runs, it fails with an access denied error related to KMS. What is the most likely cause of the failure?

A.The KMS key is in a different AWS Region than the S3 buckets, causing cross-Region latency and timeouts.
B.The Glue job is using an outdated version of the AWS SDK that does not support KMS encryption.
C.The Glue job's IAM role lacks permissions for kms:Decrypt and kms:GenerateDataKey.
D.The S3 bucket policy does not allow the Glue job's IAM role to perform s3:GetObject and s3:PutObject.
AnswerC

The Glue job assumes an IAM role to access AWS services. Even if the KMS key policy grants access, the IAM role must also have explicit permissions for kms:Decrypt and kms:GenerateDataKey to use the key for reading and writing encrypted data. Without these IAM permissions, the job cannot decrypt source objects or generate data keys for encryption, resulting in access denied.

Why this answer

For a Glue job to use a customer-managed KMS key, both the key policy and the IAM role's identity-based policy must grant the necessary permissions. The key policy alone is insufficient; the IAM role must explicitly allow kms:Decrypt and kms:GenerateDataKey. This dual authorization ensures least privilege.

The error indicates the IAM role lacks these permissions, so adding them resolves the issue.

Exam trap

The trap here is assuming that a permissive KMS key policy is enough, overlooking that the IAM role also needs explicit permissions for KMS actions.

206
MCQmedium

A data engineer manages an AWS Glue job that reads from an Amazon S3 bucket containing PII. The security team requires that the data be encrypted at rest using a customer-managed AWS KMS key, and that the engineer be able to audit key usage. The engineer has already created a KMS key. Which combination of steps should the engineer take to meet these requirements?

A.Use SSE-S3 for the S3 bucket and enable S3 server access logging to track key usage.
B.Enable default encryption on the S3 bucket with SSE-KMS using the AWS managed key aws/s3, and enable AWS CloudTrail data events for S3.
C.Configure the Glue job to use client-side encryption with a customer-managed KMS key, and enable AWS CloudTrail management events.
D.Configure the S3 bucket to use SSE-KMS with the customer-managed key, and enable AWS CloudTrail logging for KMS API calls.
AnswerD

Using SSE-KMS with a customer-managed key ensures data at rest is encrypted with that key, and CloudTrail logs all KMS API calls, providing an audit trail of key usage. This directly meets the encryption and auditing requirements. The Glue job will automatically use the key when reading and writing if permissions are granted.

Why this answer

SSE-KMS with a customer-managed key provides control over the encryption key and enables auditing via CloudTrail, which logs all KMS API calls. This meets both the encryption at rest and auditability requirements. Other options either use AWS-managed keys or do not provide the necessary audit detail.

Exam trap

The trap here is assuming that S3 server access logging or CloudTrail S3 data events capture KMS key usage, when only CloudTrail management events for KMS or KMS key policies provide that visibility.

207
MCQmedium

A data engineer needs to share an S3 bucket with another AWS account. They want to ensure that the objects in the bucket remain encrypted with SSE-KMS using a customer managed key. What additional step is required for cross-account access?

A.Modify the KMS key policy to grant the target account kms:Decrypt permission
B.Add an IAM policy in the target account to allow kms:Decrypt
C.Disable SSE-KMS encryption on the bucket
D.Add a bucket policy that grants the target account s3:GetObject
AnswerA

Cross-account SSE-KMS access requires both the S3 bucket policy and the KMS key policy to permit the target account. Because the key is customer managed, its key policy must explicitly grant the other account kms:Decrypt, otherwise S3 cannot unwrap the data key for that account's requests.

Why this answer

When using SSE-KMS with a customer managed key, cross-account access requires the KMS key policy to grant the target account's IAM role or user the necessary KMS permissions (kms:Decrypt, and optionally kms:GenerateDataKey). The S3 bucket policy must also grant s3:GetObject, and the target account's IAM policy must allow kms:Decrypt. However, the key policy is the additional step specific to KMS that is not covered by S3 policies alone.

Without it, the target account cannot use the key. Option A is correct because modifying the key policy is essential. Option B is insufficient because the target account's IAM policy cannot override the key policy.

Option C is unnecessary and breaks encryption. Option D provides S3 access but not KMS access.

208
MCQmedium

A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The company wants to grant a data analyst read-only access to specific columns in a table stored in the AWS Glue Data Catalog. The analyst should not be able to see other columns or any rows that contain sensitive data. The engineer sets up Lake Formation permissions on the table, granting SELECT on specific columns. However, when the analyst queries the table using Amazon Athena, they can see all columns. What is the most likely reason?

A.The Glue Data Catalog table definition does not include the column-level metadata required for Lake Formation.
B.The analyst has IAM permissions that allow direct access to the S3 bucket, bypassing Lake Formation.
C.Lake Formation column-level permissions are not supported for Athena queries.
D.The analyst's IAM role lacks the lakeformation:GetDataAccess permission.
AnswerB

Lake Formation uses a permission model that requires the principal to have no direct IAM access to the underlying S3 data. If the analyst has IAM permissions to read the S3 bucket, they can bypass Lake Formation's column-level restrictions and access all data directly. To enforce Lake Formation permissions, the analyst's IAM policy must not allow direct S3 access, and all access should go through Lake Formation-enabled services.

Why this answer

Lake Formation enforces fine-grained access control only when users do not have direct IAM permissions to the underlying data. If the analyst has IAM permissions to read the S3 bucket, they can bypass Lake Formation and access all columns and rows. To enforce column-level security, the analyst's IAM policy must not allow direct S3 access; all data access must be mediated through Lake Formation.

The other options are either incorrect or would produce different errors.

Exam trap

The trap here is assuming that Lake Formation permissions alone are sufficient, while ignoring that direct IAM access to S3 can bypass those permissions entirely.

209
MCQeasy

A data engineer runs the command shown to check the encryption configuration of an S3 bucket. The output shows SSEAlgorithm: AES256. What does this mean?

A.The bucket uses SSE-S3 with Amazon S3-managed keys
B.The bucket uses SSE-KMS with a customer-managed key
C.The bucket uses SSE-C with customer-provided keys
D.The bucket does not have encryption enabled
AnswerA

SSEAlgorithm AES256 indicates server-side encryption with Amazon S3-managed keys (SSE-S3), where S3 owns and rotates the AES-256 keys. This satisfies the stem's observed output directly: SSE-KMS would report aws:kms, and SSE-C would not appear as a bucket default algorithm.

Why this answer

AES256 refers to SSE-S3, where Amazon S3 manages the encryption keys using AES-256. Option B (SSE-KMS) would show 'aws:kms'. Option C (SSE-C) would require the customer to provide keys.

Option D (no encryption) is incorrect because encryption is enabled.

210
MCQmedium

Refer to the exhibit. A data engineer queries AWS CloudTrail to investigate a PutObject event. What does the exhibit reveal about the object sensitive.csv?

A.The upload failed due to encryption mismatch.
B.The object was uploaded with server-side encryption using AWS KMS.
C.The object was not encrypted at rest.
D.The object was encrypted with SSE-S3.
AnswerB

The CloudTrail record shows the PutObject request carried the x-amz-server-side-encryption header set to aws:kms, confirming the object was written using SSE-KMS rather than SSE-S3 or SSE-C. This satisfies the investigation's need to identify the encryption mechanism applied to sensitive.csv at upload time.

Why this answer

The CloudTrail event contains `x-amz-server-side-encryption: aws:kms`, which confirms the object was uploaded with server-side encryption using AWS KMS (SSE-KMS). Option A is incorrect because the event shows a successful upload, not a failure. Option C is incorrect because the event indicates encryption was applied.

Option D is incorrect because SSE-S3 would show `AES256`, not `aws:kms`.

211
MCQmedium

A data engineer is configuring an S3 bucket for storing sensitive customer data. The bucket must be encrypted at rest using an AWS Key Management Service (KMS) key that is managed by the data engineering team. The team wants to ensure that only users with explicit permission can decrypt the data. Which S3 encryption option should be used?

A.SSE-KMS
B.Client-side encryption
C.SSE-S3
D.SSE-C
AnswerA

SSE-KMS encrypts objects with a KMS key, and decryption requires kms:Decrypt permission on that key. This satisfies the requirement for team-managed keys and explicit decrypt authorisation, unlike SSE-S3 where AWS owns the key and access is governed solely by S3 permissions.

Why this answer

SSE-KMS is the correct option because it uses a customer-managed AWS KMS key, allowing the data engineering team to control access and permissions for decryption. Client-side encryption is not an S3 server-side encryption option and does not use KMS. SSE-S3 uses Amazon S3-managed keys, which do not provide customer-controlled access.

SSE-C requires the customer to manage their own encryption keys and does not use KMS, nor does it allow the same level of access control as a CMK.

212
MCQmedium

A data engineer is designing a data lake on S3 with sensitive data. The security policy mandates that data must be encrypted at rest and in transit, and that an inventory of all objects must be maintained for compliance. Which actions should be taken?

A.Enforce HTTPS via bucket policy, enable default SSE-S3 encryption, and enable S3 Inventory.
B.Use SSE-KMS encryption and enable CloudTrail for S3 events.
C.Enable S3 default encryption using SSE-S3 and enable S3 Inventory.
D.Enforce HTTPS using bucket policy and enable S3 Server Access Logging.
AnswerA

Enforcing HTTPS via bucket policy satisfies the in-transit encryption mandate, while default SSE-S3 provides AES-256 server-side encryption at rest without key management overhead. S3 Inventory delivers scheduled CSV or Parquet reports of all objects and their metadata, meeting the compliance inventory requirement. Together these three controls cover every stated constraint.

Why this answer

It covers all requirements: encryption in transit (HTTPS enforcement via bucket policy), encryption at rest (default SSE-S3), and compliance inventory (S3 Inventory). Option B uses SSE-KMS which is not required and lacks inventory. Option C includes at-rest encryption and inventory but misses in-transit encryption.

Option D includes in-transit encryption but lacks at-rest encryption and compliance inventory.

213
MCQeasy

A company has an S3 bucket that stores logs for compliance. The compliance team requires that objects are retained for 7 years and cannot be deleted or overwritten. Which S3 feature should be used?

A.Enable S3 Object Lock with retention mode COMPLIANCE and a retention period of 7 years
B.Enable MFA Delete on the bucket
C.Configure an S3 bucket policy that denies delete and overwrite actions
D.Enable S3 Versioning and configure a lifecycle policy to expire objects after 7 years
AnswerA

S3 Object Lock in COMPLIANCE mode enforces a WORM retention period that no user, including the root account, can shorten or bypass, directly satisfying the requirement that objects cannot be deleted or overwritten for 7 years. GOVERNANCE mode would permit privileged users to alter retention, so it fails this constraint.

Why this answer

S3 Object Lock in COMPLIANCE mode enforces a WORM (Write Once Read Many) model where no user, including the root account, can delete or overwrite the object version until the retention period expires. Setting a 7-year retention period directly satisfies the compliance requirement that objects cannot be deleted or overwritten for 7 years. COMPLIANCE mode is the strictest retention mode and is specifically designed for regulatory retention scenarios.

Exam trap

DEA-C01 often tests the misconception that MFA Delete or bucket policies provide immutability — candidates confuse access control with WORM retention, but only Object Lock in COMPLIANCE mode guarantees non-deletable, non-overwritable objects.

How to eliminate wrong answers

Option B is wrong because MFA Delete only requires additional authentication for delete operations; it does not prevent deletion or overwriting, and a user with MFA can still delete objects. Option C is wrong because a bucket policy denying delete and overwrite actions can be modified or removed by an administrator, so it is not tamper-proof and does not provide immutable retention. Option D is wrong because versioning plus a lifecycle expiration policy allows objects to be deleted after 7 years but does not prevent deletion or overwriting before 7 years; lifecycle rules can also be changed at any time.

214
MCQeasy

A data engineer is building an AWS Glue job that reads from a JDBC source and must retrieve the database password at runtime without hardcoding it in the script or job parameters in plaintext. The company already stores the password in AWS Secrets Manager. Which action should the engineer take?

A.Grant the Glue job role secretsmanager:GetSecretValue on the secret ARN and retrieve the secret in the job using the Glue Secrets Manager connection property.
B.Embed the password directly in the Glue ETL script and restrict access to the script in Amazon S3.
C.Use an IAM database authentication token for the JDBC connection instead of a password.
D.Store the password in an AWS Glue job parameter and mark it as encrypted using a KMS key.
AnswerA

AWS Glue integrates with Secrets Manager through the connection's secretId property, letting the job fetch credentials at runtime. Granting secretsmanager:GetSecretValue scoped to the specific secret ARN provides least-privilege access. This avoids embedding plaintext credentials in scripts or job parameters while giving the job the password it needs.

Why this answer

AWS Glue connections support a secretId property that fetches credentials from Secrets Manager at runtime. Granting the job role GetSecretValue on the specific secret keeps access narrow and avoids plaintext credentials in scripts or parameters, while also enabling rotation and audit through Secrets Manager.

Exam trap

The trap here is assuming encrypted job parameters are safe, when the real goal is to keep credentials out of the job definition entirely via a secrets store.

215
MCQmedium

A company is designing a data lake on AWS and must comply with GDPR requirements. The company needs to implement data masking for personally identifiable information (PII) columns in Amazon Redshift. Which feature should be used?

A.Use Amazon RDS Proxy to intercept queries
B.Amazon S3 Object Lambda to mask data on the fly
C.Create views in Redshift that apply masking functions
D.AWS Lake Formation row-level security
AnswerC

Dynamic data masking in Amazon Redshift applies masking policies at query time, so PII columns return redacted values without altering stored data. Attaching these policies to roles satisfies GDPR's data-minimisation requirement, and unlike views, masking persists across all queries against the table, including ad-hoc analyst access.

Why this answer

Amazon Redshift supports dynamic data masking through views that apply masking functions, such as using CASE statements or custom masking functions to obfuscate PII columns. Option A is incorrect because Amazon RDS Proxy is a connection proxy for RDS databases and does not provide data masking capabilities for Redshift. Option B is incorrect because Amazon S3 Object Lambda is used to transform data in S3, not to mask data in Redshift queries.

Option D is incorrect because AWS Lake Formation row-level security filters rows based on permissions but does not mask or obfuscate column values; it is for access control, not data masking.

216
MCQhard

A data engineer is troubleshooting an issue where an IAM role used by AWS Glue cannot read data from an S3 bucket encrypted with SSE-KMS. The bucket policy allows the role to perform s3:GetObject. What additional permission is needed?

A.s3:GetObjectVersion
B.kms:Decrypt on the KMS key
C.s3:GetObjectAcl
D.kms:GenerateDataKey on the KMS key
AnswerB

SSE-KMS encrypts objects with a KMS key, so s3:GetObject alone is insufficient: S3 must call KMS to unwrap the data key on the caller's behalf. The role therefore needs kms:Decrypt on that key, satisfying the stem's requirement to read the SSE-KMS-encrypted objects.

Why this answer

For SSE-KMS, the IAM role needs kms:Decrypt permission on the KMS key to read encrypted objects. Option A (s3:GetObjectVersion) is not required because the bucket policy already allows s3:GetObject; versioning is not relevant here. Option C (s3:GetObjectAcl) is for access control lists, not encryption.

Option D (kms:GenerateDataKey) is used for encrypting new objects, not reading existing ones. Therefore, the correct answer is B.

217
MCQhard

A company uses AWS Lake Formation to manage fine-grained access to a data lake in Amazon S3. A data analyst needs to query a table in the AWS Glue Data Catalog that contains columns with sensitive data. The analyst must be able to see only non-sensitive columns and only rows where the region column equals 'US'. The analyst uses Amazon Athena for queries. Which Lake Formation permission model should the data engineer implement?

A.Grant the analyst SELECT permission on the table and use AWS Glue job bookmarks to filter sensitive data.
B.Grant the analyst SELECT permission on the table and create a data filter that includes only non-sensitive columns and a row filter for region = 'US'.
C.Create a view in Athena that selects only non-sensitive columns and filters rows for region = 'US', and grant the analyst access to the view.
D.Grant the analyst SELECT permission on the table and use an IAM policy to deny access to sensitive columns.
AnswerB

Lake Formation data filters allow column-level and row-level security. Granting SELECT on the table with a data filter that specifies the allowed columns and a row filter expression restricts the analyst to only the permitted columns and rows. This meets the requirement precisely without granting broader access.

Why this answer

Lake Formation data filters provide column-level and row-level security by allowing you to specify which columns and rows a principal can access. By granting SELECT with a data filter that includes only non-sensitive columns and a row filter for region = 'US', the analyst is restricted appropriately. IAM policies, Athena views, and Glue job bookmarks do not enforce the required fine-grained access control.

Exam trap

The trap here is assuming that IAM policies or Athena views can enforce column-level and row-level security, when Lake Formation data filters are the correct mechanism for fine-grained access control in a data lake.

218
MCQmedium

A data engineer is configuring an S3 bucket policy to allow cross-account access for a partner account to read objects. The bucket is encrypted with SSE-KMS using a customer-managed key. What additional configuration is needed to allow the partner account to decrypt the objects?

A.Add a bucket policy that grants the partner account s3:GetObject
B.Create a VPC endpoint for S3 and add it to the bucket policy
C.Update the KMS key policy to grant the partner account kms:Decrypt permission
D.Add a bucket policy that grants s3:GetObject and s3:GetEncryptionConfiguration
AnswerC

Granting the partner account kms:Decrypt in the KMS key policy satisfies the stem's requirement that cross-account readers decrypt SSE-KMS objects. S3 bucket policies alone cannot authorise key usage; the customer-managed key's policy must separately permit the partner principal, since KMS enforces its own authorisation independently of S3.

Why this answer

For cross-account access with SSE-KMS, the KMS key policy must grant the partner account access to use the key. The bucket policy alone is insufficient. The partner account does not need VPC endpoints, and the bucket policy for decryption is not needed.

The partner account does not need access to the S3 bucket's encryption configuration.

219
MCQmedium

A data engineer needs to ensure that all objects written to an S3 bucket are encrypted with SSE-KMS using a specific customer managed key, and that any upload without that encryption is rejected. The engineer has created the bucket and the KMS key. Which approach will enforce this requirement at the bucket level?

A.Enable S3 Block Public Access on the bucket.
B.Use an S3 Lifecycle rule to transition objects to S3 Glacier with encryption.
C.Add a bucket policy that denies s3:PutObject requests where the s3:x-amz-server-side-encryption header is not aws:kms or the s3:x-amz-server-side-encryption-aws-kms-key-id does not match the specified key.
D.Configure the bucket's default encryption to use SSE-KMS with the customer managed key.
AnswerC

A bucket policy with a Deny effect on s3:PutObject can evaluate conditions on request headers such as s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id. This explicitly blocks uploads that do not use the required encryption method and key. This is the only option that enforces rejection of non-compliant uploads at the bucket level, satisfying the requirement.

Why this answer

To enforce that every object is uploaded with a specific SSE-KMS key, a bucket policy must explicitly deny s3:PutObject requests that do not carry the required encryption headers. Default encryption only applies when no encryption is specified, and it cannot reject requests that specify a different method. The policy approach is the only one that guarantees non-compliant uploads are denied.

Exam trap

The trap here is assuming that setting default encryption on the bucket is sufficient to enforce a specific encryption method for all uploads.

220
Multi-Selecteasy

A company must comply with a regulation that requires logging all access to sensitive data stored in Amazon S3. Which AWS services can be used to capture and store access logs? (Choose TWO.)

Select 2 answers
A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.Amazon S3 server access logs
E.VPC Flow Logs
AnswersC, D

AWS CloudTrail records S3 API activity, including object-level data events when enabled, capturing who accessed sensitive objects and when. It satisfies the regulation by providing an auditable log of all access requests to the bucket.

Why this answer

AWS CloudTrail (C) is correct because it records S3 data events (GetObject, PutObject, DeleteObject) for object-level access to sensitive data, delivering an audit trail of every API call to the S3 bucket. Amazon S3 server access logs (D) are also correct because they capture detailed, object-level records of every request made to a bucket, including requester, operation, and response status, and can be stored in a target bucket for compliance. AWS Config (A) evaluates resource configuration and compliance over time but does not log individual data access requests.

Amazon CloudWatch Logs (B) stores and monitors log data but does not itself capture S3 access events. VPC Flow Logs (E) capture IP traffic metadata at the ENI/subnet level and cannot record S3 object-level access.

Exam trap

DEA-C01 often tests the confusion between configuration auditing (AWS Config), network traffic logging (VPC Flow Logs), and actual data access logging (CloudTrail data events and S3 server access logs), causing candidates to select services that do not capture S3 object access.

221
MCQeasy

A company uses Amazon QuickSight for data visualization. The data engineer needs to ensure that users can only see data relevant to their department. The data is stored in Amazon S3 and is accessed via SPICE. The engineer has created datasets in QuickSight and wants to implement row-level security (RLS). The dataset contains a column 'Department' that indicates which department a row belongs to. The engineer has configured RLS rules using a separate permissions dataset. However, users report that they can see all rows, not just their department's rows. What is the most likely reason?

A.The RLS permissions dataset is not correctly configured to map users to department values.
B.The 'Department' column is not included in the dataset.
C.The users have been granted admin access to the QuickSight dashboard.
D.The SPICE dataset does not support row-level security.
AnswerA

The permissions dataset must map each user or group to specific Department values; if its columns or entries are malformed, QuickSight applies no matching rule and defaults to showing all rows. Correctly mapping users to department values satisfies the stem's requirement that each user sees only their own department's data.

Why this answer

RLS in QuickSight works by matching the user's identity (via username or group) against rules in a permissions dataset that maps users/groups to allowed values of a column (e.g., Department). If users see all rows, the most likely cause is that the permissions dataset is not correctly mapping users to department values — for example, wrong usernames, missing group mappings, or a dataset that does not join properly to the main dataset.

Exam trap

DEA-C01 often tests the assumption that SPICE does not support RLS or that a missing column is the cause — the real trap is recognizing that RLS failures usually stem from identity-mapping mismatches in the permissions dataset, not from SPICE limitations.

How to eliminate wrong answers

Option B is wrong because if the 'Department' column were missing from the dataset, RLS rules referencing it would fail to apply or error out, but the symptom described (users see all rows) points to a mapping/configuration issue rather than a missing column, which would typically break the rule setup entirely. Option C is wrong because admin access to the dashboard would grant broad permissions, but the question states RLS rules were configured and users still see all rows — the issue is the RLS configuration itself, not dashboard-level access. Option D is wrong because SPICE datasets fully support row-level security; RLS is applied at query time regardless of whether data is in SPICE or direct query.

222
MCQeasy

A data engineer must give an AWS Glue ETL job temporary access to data in an Amazon S3 bucket without creating long-term IAM user access keys. The job runs on a schedule and must retrieve credentials automatically. Which mechanism should the engineer use?

A.Attach an IAM role to the AWS Glue job and let the service assume it to obtain temporary credentials automatically.
B.Store an IAM user's access key and secret key in AWS Secrets Manager and have the Glue job retrieve them at runtime.
C.Generate a pre-signed URL for each S3 object and pass the URLs as job parameters to the Glue script.
D.Create an IAM user with programmatic access and embed the access key in the Glue job script as a hard-coded variable.
AnswerA

AWS Glue jobs run with an IAM role that the service assumes on your behalf, and the AWS SDK and Glue runtime retrieve temporary credentials automatically. No access keys are created or stored, and permissions are governed by the role's policies. This is the standard, secure way to grant a Glue job access to S3.

Why this answer

AWS Glue jobs are associated with an IAM role that the service assumes to call other AWS services. The Glue runtime and AWS SDK automatically obtain temporary credentials from that role, so the job can read S3 data without any stored access keys. This satisfies the no-long-term-credentials requirement and follows AWS best practice for service-to-service authorization.

Exam trap

The trap here is treating Secrets Manager or pre-signed URLs as the default way to give compute services credentials, when AWS compute services such as Glue should use an attached IAM role for automatic temporary credentials.

223
MCQeasy

A company wants to ensure that all S3 buckets are encrypted using server-side encryption. Which AWS service can be used to automatically remediate non-compliant buckets?

A.AWS CloudTrail
B.Amazon Inspector
C.AWS Trusted Advisor
D.AWS Config
AnswerD

AWS Config rules continuously evaluate S3 bucket encryption against your desired configuration and can trigger automatic remediation, such as invoking a Systems Manager automation to enable default encryption. This satisfies the requirement to remediate non-compliant buckets automatically, rather than merely detecting or reporting drift.

Why this answer

AWS Config can use managed rules like s3-bucket-server-side-encryption-enabled to check compliance and trigger auto-remediation via SSM Automation or Lambda. Option D is correct.

224
MCQeasy

A data engineer is configuring AWS Glue jobs to access data stored in Amazon S3. The data is encrypted using server-side encryption with AWS KMS (SSE-KMS). The Glue job needs to read and write data to the S3 bucket. Which IAM policy statement should be added to the Glue job's IAM role to allow it to use the KMS key?

A.{"Effect":"Allow","Action":["kms:Decrypt"],"Resource":"*"}
B.{"Effect":"Allow","Action":["kms:Decrypt","kms:GenerateDataKey"],"Resource":"*"}
C.{"Effect":"Allow","Action":["kms:Decrypt","kms:ReEncrypt"],"Resource":"*"}
D.{"Effect":"Allow","Action":["kms:Decrypt","kms:Encrypt"],"Resource":"*"}
AnswerB

SSE-KMS requires both kms:Decrypt to read encrypted objects and kms:GenerateDataKey to obtain a data key for writing. Granting these two actions on the key resource satisfies the stem's read-and-write requirement, since Glue cannot access KMS-encrypted S3 data with either permission missing.

Why this answer

To read and write data encrypted with SSE-KMS, AWS Glue needs both `kms:Decrypt` (to read existing encrypted data) and `kms:GenerateDataKey` (to create a new data key for writing encrypted data). `kms:GenerateDataKey` is required because S3 uses a data key to encrypt objects, and the caller must generate that key via KMS. Option B correctly includes both actions, allowing the Glue job to perform read and write operations on the SSE-KMS encrypted bucket.

Exam trap

The trap here is that candidates often assume `kms:Encrypt` is needed for writing encrypted data, but S3 SSE-KMS actually requires `kms:GenerateDataKey` because the encryption is done with a derived data key, not by calling `kms:Encrypt` directly.

How to eliminate wrong answers

Option A is wrong because it only grants `kms:Decrypt`, which allows reading encrypted data but not writing new encrypted objects; writing requires `kms:GenerateDataKey` to create the encryption key. Option C is wrong because `kms:ReEncrypt` is used for re-encrypting data under a different KMS key, which is not needed for standard S3 read/write operations with SSE-KMS. Option D is wrong because `kms:Encrypt` is used to encrypt plaintext data directly with a KMS key, but S3 SSE-KMS requires `kms:GenerateDataKey` (not `kms:Encrypt`) to obtain a data key for object-level encryption.

225
MCQeasy

A media company stores video files in an Amazon S3 bucket. The bucket policy allows access only from a specific VPC. The company has enabled S3 Server Access Logs to monitor access. Recently, the security team found that some requests were coming from an IP address outside the allowed VPC. They suspect that the bucket policy may have an incorrect condition. What should they check first?

A.Verify that the bucket policy uses the 'aws:SourceVpc' condition key with the correct VPC ID.
B.Review the S3 Server Access Logs to identify the source IP addresses.
C.Ensure that the IAM role used by the application has the correct permissions.
D.Check if the bucket policy allows public access.
AnswerA

The aws:SourceVpc condition key only matches when the request arrives through a VPC endpoint. A typo or wrong VPC ID in that condition lets external IP addresses bypass the intended restriction, so verify it first.

Why this answer

The first thing to check is the bucket policy condition key. The 'aws:SourceVpc' condition key is used to restrict access to a specific VPC, but if it is misconfigured (e.g., wrong VPC ID or incorrect condition operator), requests from outside the VPC might be allowed. Verifying this key ensures the policy is correctly enforcing the VPC restriction.

Exam trap

DEA-C01 often tests the confusion between diagnosing and fixing. Candidates might choose to review logs (Option B) as a first step, but the question asks what to check first to address the suspected policy condition error, making the policy condition the priority.

How to eliminate wrong answers

Option B is wrong because reviewing S3 Server Access Logs can identify source IPs but does not directly address the policy misconfiguration; it's a diagnostic step, not a fix. Option C is wrong because IAM role permissions are separate from bucket policy conditions; even with correct IAM, a misconfigured bucket policy could allow access. Option D is wrong because checking for public access is not specific to the VPC condition issue; the policy might not be public but still have an incorrect VPC condition.

← PreviousPage 3 of 4 · 246 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Data Security Governance questions.