Courseiva

CCNA Data Security Governance Questions

21 of 246 questions · Page 4/4 · Data Security Governance topic · Answers revealed

226
MCQhard

A company uses AWS Glue to process data from Amazon S3. The data contains personally identifiable information (PII). The data engineer needs to automatically detect and mask PII fields before the data is loaded into Amazon Redshift. Which combination of AWS services should be used?

A.Amazon Macie and AWS Glue
B.Amazon CloudWatch Logs and AWS Lambda
C.Amazon S3 Object Lambda and AWS Glue
D.AWS IAM Access Analyzer and AWS Glue
AnswerA

Amazon Macie uses managed and custom data identifiers to detect PII in S3, publishing findings that drive the masking logic. AWS Glue then applies those detections during ETL, masking fields before writing to Redshift. Together they deliver automated detection and masking without manual schema inspection.

Why this answer

Option A is correct because Amazon Macie uses machine learning to automatically discover and classify PII in S3 data, and AWS Glue can then apply transforms (e.g., via a Glue ETL job or Glue Studio) to mask or redact those fields before loading into Redshift. Macie identifies sensitive data locations, and Glue performs the masking during the ETL pipeline, satisfying the requirement to detect and mask PII automatically.

Exam trap

DEA-C01 often tests the assumption that any AWS service with 'access' or 'analyzer' in its name can detect PII — candidates pick IAM Access Analyzer or S3 Object Lambda instead of Macie, which is the only service purpose-built for PII discovery.

How to eliminate wrong answers

Option B is wrong because CloudWatch Logs and Lambda are for log monitoring and event-driven compute, not for PII detection or data masking in S3-to-Redshift pipelines. Option C is wrong because S3 Object Lambda is used to transform data on retrieval via a Lambda function, but it does not provide automatic PII detection/classification like Macie, and it is not the standard combination for Glue-based ETL masking. Option D is wrong because IAM Access Analyzer identifies resource policies that grant external access — it does not detect or mask PII content.

227
MCQeasy

A company's security policy states that no S3 bucket in the data platform account may ever be made public, even accidentally. A data engineer must implement a guardrail that blocks any attempt to set a public bucket ACL or public bucket policy, regardless of who makes the change. Which solution enforces this requirement?

A.Configure AWS Config with the s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited managed rules and rely on their evaluations.
B.Turn on S3 server access logging and create an Amazon EventBridge rule that notifies the security team when a public ACL is applied.
C.Create an S3 bucket policy that denies s3:PutBucketAcl and s3:PutBucketPolicy for all principals in the account.
D.Enable S3 Block Public Access at the account level and ensure the setting remains on for all existing and future buckets.
AnswerD

Account-level S3 Block Public Access applies to every bucket in the account, including buckets created later, and overrides any public ACL or policy that would otherwise grant public access. It can be enforced through AWS Organizations so member accounts cannot turn it off. This directly satisfies the requirement to block public access regardless of which principal attempts the change, with no per-bucket maintenance.

Why this answer

S3 Block Public Access at the account level prevents public ACLs and policies for every bucket, including future ones, and can be locked down via AWS Organizations. Detective controls such as AWS Config rules or logging only report exposure after the fact. The requirement is preventive, account-wide, and independent of who attempts the change, which the account-level block setting delivers.

Exam trap

The trap here is choosing a detective control such as an AWS Config rule or logging, when the requirement demands prevention before public access is granted.

228
MCQmedium

A company uses Amazon Kinesis Data Streams to ingest real-time financial data. The security team requires that all data be encrypted at rest using a customer-managed AWS KMS key, and that the key be rotated annually. The data engineer needs to configure the Kinesis stream to meet these requirements. Which combination of actions should the data engineer take?

A.Enable server-side encryption on the Kinesis stream using the StartStreamEncryption API with the customer-managed KMS key, and enable automatic key rotation on the KMS key.
B.Enable encryption at rest by setting the Kinesis stream's EncryptionType to KMS and specifying a customer-managed key, then manually rotate the key by creating a new key and updating the stream configuration every year.
C.Use AWS CloudFormation to deploy the Kinesis stream with the KmsKeyId property set to a customer-managed key, and set the EnableKeyRotation property to true on the key resource.
D.Configure the Kinesis stream to use AWS-managed KMS keys for encryption, and create a custom AWS Lambda function that rotates the key every 365 days.
AnswerA

The StartStreamEncryption API enables server-side encryption for a Kinesis stream using a specified KMS key. By specifying a customer-managed key, the stream data is encrypted at rest with that key. Enabling automatic key rotation on the KMS key ensures the key is rotated annually, meeting the requirement. This is the correct and direct way to achieve both encryption and rotation.

Why this answer

To encrypt a Kinesis data stream at rest with a customer-managed KMS key, you use the StartStreamEncryption API, specifying the stream and the KMS key. This enables server-side encryption. To rotate the key annually, you enable automatic key rotation on the customer-managed KMS key.

AWS KMS automatically rotates the key material every year when automatic rotation is enabled. This combination meets both requirements with minimal effort.

Exam trap

The trap here is thinking that AWS-managed KMS keys can be rotated by the customer or that manual rotation is necessary, when automatic rotation is available for customer-managed keys.

229
MCQhard

A data engineer is designing a solution to securely store and rotate database credentials used by an application. The credentials should be automatically rotated every 90 days. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.AWS Key Management Service (KMS)
D.AWS Identity and Access Management (IAM)
AnswerA

AWS Secrets Manager natively stores database credentials and performs scheduled rotation via Lambda functions, satisfying the 90-day automatic rotation constraint. Unlike Parameter Store, which lacks built-in rotation, it directly manages credential lifecycle for RDS and other databases, meeting the security requirement without custom orchestration.

Why this answer

AWS Secrets Manager is designed specifically for storing, managing, and automatically rotating secrets such as database credentials. It natively supports rotation schedules (e.g., every 90 days) using Lambda rotation functions, and integrates with RDS, Redshift, and DocumentDB for managed rotation. This directly meets the requirement for automatic rotation every 90 days.

Exam trap

DEA-C01 often tests the confusion between Secrets Manager and Parameter Store, where candidates pick Parameter Store for secret rotation even though it lacks built-in automatic rotation.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store can store secrets securely (as SecureString), but it does not provide built-in automatic rotation; you would need to implement custom rotation logic. Option C is wrong because AWS KMS is a key management service for encryption keys, not for storing and rotating database credentials; it can encrypt secrets but does not manage their lifecycle. Option D is wrong because IAM is for identity and access management, not for storing or rotating secrets; it manages permissions, not credentials storage.

230
MCQeasy

A data engineer is using AWS Glue to transform data stored in Amazon S3. The security team requires that data in transit between AWS Glue and Amazon S3 be encrypted. The engineer wants to ensure that all connections use TLS. Which action should the engineer take to enforce encryption in transit for AWS Glue jobs accessing S3?

A.Enable SSL/TLS for the Glue connection and set the require_ssl parameter to true in the JDBC URL.
B.Attach a bucket policy to the S3 bucket that denies requests where aws:SecureTransport is false.
C.Configure the Glue job to use a VPC endpoint for S3 and enable encryption on the endpoint.
D.Set the Glue job parameter --encryption-mode to SSE-S3.
AnswerB

To enforce encryption in transit for S3, a bucket policy can deny any requests that do not use TLS, by checking the aws:SecureTransport condition key. This ensures that all access, including from AWS Glue, must use HTTPS. This is the standard method to require encryption in transit for S3.

Why this answer

Enforcing encryption in transit for S3 is done by adding a bucket policy that denies requests when aws:SecureTransport is false. This ensures that all clients, including AWS Glue, must use HTTPS/TLS when accessing the bucket. Other options either address encryption at rest or do not enforce TLS.

Exam trap

The trap here is confusing encryption at rest settings like SSE-S3 or VPC endpoints with encryption in transit, which requires TLS enforcement via bucket policy.

231
MCQmedium

A company uses AWS Glue to process data stored in Amazon S3. The security team mandates that all data in transit between AWS Glue and Amazon S3 must be encrypted with TLS. The Glue job connects to S3 using the AWS SDK. Which configuration should the data engineer implement to enforce TLS encryption for the Glue job's S3 connections?

A.Configure the Glue job to use a VPC endpoint for S3 and enable AWS PrivateLink.
B.Attach an S3 bucket policy that denies requests where aws:SecureTransport is false.
C.Set the Glue job parameter --encryption-mode to TLS.
D.Enable default encryption on the S3 bucket with SSE-KMS.
AnswerB

An S3 bucket policy with a condition that denies access when aws:SecureTransport is false enforces that all requests to the bucket use TLS. This policy applies to any client, including AWS Glue, ensuring data in transit is encrypted. This is the standard AWS method to enforce TLS for S3 access.

Why this answer

To enforce TLS for all connections to an S3 bucket, including from AWS Glue, an S3 bucket policy that denies requests when aws:SecureTransport is false is the correct approach. This condition evaluates the transport protocol and blocks non-TLS requests. It is a best practice recommended by AWS for ensuring data in transit encryption.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, or assuming Glue has a built-in TLS enforcement parameter.

232
Multi-Selectmedium

A data engineer manages an AWS Lake Formation governed data lake. Analysts in the finance department must query only the rows in a shared Amazon S3 table where the region column equals 'EMEA', while analysts in the marketing department must see all rows but must not see the customer_email column. Which TWO Lake Formation configurations should the data engineer implement to meet these requirements? (Choose two.)

Select 2 answers
A.Create a data filter on the table that excludes the customer_email column and grant SELECT on the table with that data filter to the marketing analyst role.
B.Define an AWS Glue Data Catalog table property named column.filter with the value customer_email and a table property row.filter with the value region='EMEA', then grant DESCRIBE to both roles.
C.Create a data filter on the table that includes a row filter expression of region = 'EMEA' and grant SELECT on the table with that data filter to the finance analyst role.
D.Register the S3 location with Lake Formation in hybrid access mode and grant the analysts ALL permissions so that IAM policies alone control row and column visibility.
E.Attach an IAM policy to the finance analyst role that denies s3:GetObject on any S3 prefix whose object metadata does not contain a region tag of EMEA.
AnswersA, C

A Lake Formation data filter can specify an included column list that omits customer_email. Granting SELECT with that column-scoped data filter to the marketing role means queries through integrated engines return all rows but cannot project the excluded column. This implements the column-level restriction without duplicating the underlying S3 data.

Why this answer

Lake Formation data filters are the native mechanism for row-level and column-level security. A data filter with a row expression scopes which rows a principal can read, and a data filter with an included column list scopes which columns are visible. Granting SELECT with the appropriate data filter to each analyst role enforces both requirements across integrated engines without copying or duplicating the underlying S3 objects.

Exam trap

The trap here is reaching for IAM or S3 object metadata to express row predicates, when those layers cannot filter individual rows inside a data file and Lake Formation data filters are the intended control.

233
MCQhard

A company is designing a data pipeline using Amazon Kinesis Data Streams. The data includes personally identifiable information (PII). The security team requires that data be encrypted at rest using a customer-managed KMS key. How should the data engineer configure the Kinesis stream?

A.Configure the Kinesis stream to use AWS CloudHSM for encryption.
B.Enable server-side encryption on the Kinesis stream and specify the customer-managed KMS key.
C.Store the encrypted data in S3 and use Kinesis to stream the S3 object keys.
D.Use client-side encryption in the producer application to encrypt data before sending to Kinesis.
AnswerB

Server-side encryption with a customer-managed KMS key encrypts data at rest within the stream's storage layer, satisfying the requirement for customer-controlled key management. Kinesis Data Streams supports specifying a customer-managed key rather than the AWS-owned default, giving the security team the key control and rotation they demanded.

Why this answer

Amazon Kinesis Data Streams supports server-side encryption (SSE) with AWS KMS, and you can choose either an AWS-managed key (aws/kinesis) or a customer-managed KMS key. To meet the requirement of encryption at rest with a customer-managed key, you enable SSE on the stream and specify the customer-managed KMS key, which Kinesis uses to encrypt data as it is written to storage.

Exam trap

DEA-C01 often tests the confusion between client-side encryption (producer encrypts before sending) and server-side encryption with a customer-managed KMS key, which is what the requirement explicitly asks for.

How to eliminate wrong answers

Option A is wrong because CloudHSM is not an encryption option for Kinesis Data Streams; Kinesis SSE integrates with AWS KMS, not CloudHSM directly, so this configuration is not supported. Option C is wrong because storing data in S3 and streaming only object keys does not encrypt the Kinesis stream itself and changes the architecture rather than satisfying the requirement that the stream be encrypted at rest with a customer-managed KMS key. Option D is wrong because client-side encryption encrypts data before it reaches Kinesis, but it does not provide server-side encryption at rest with a KMS key and does not meet the stated requirement of using a customer-managed KMS key for the stream.

234
MCQmedium

A company is using AWS Lake Formation to manage access to a data lake in S3. They want to grant a data analyst access to specific columns in a table, but not to the entire table. Which Lake Formation feature should be used?

A.Row-level security (cell-level filtering)
B.IAM policies on the S3 bucket
C.Column-level filtering
D.Tag-based access control (TBAC)
AnswerC

Column-level filtering in Lake Formation applies column-level permissions on a table, letting the analyst query only the granted columns while excluded columns are hidden. This satisfies the stem's requirement to restrict access to specific columns rather than the entire table.

Why this answer

Lake Formation column-level filtering allows granting access to specific columns in a table without granting access to the entire table. Option A (row-level security) controls access to rows, not columns. Option B (IAM policies on the S3 bucket) would grant access to the entire dataset or bucket, not specific columns.

Option D (tag-based access control) uses tags to manage permissions but does not provide column-level granularity.

235
MCQhard

A data engineer needs to grant a data scientist access to query a Glue Data Catalog database but must prevent the data scientist from seeing the underlying S3 data locations. Which approach should be used?

A.Use a Glue resource policy to restrict access to the database
B.Grant the data scientist IAM permissions to access the Glue Data Catalog and the underlying S3 data
C.Create a VPC endpoint for Glue and S3 to restrict network access
D.Use AWS Lake Formation to grant SELECT permission on the database and tables without granting S3 access
AnswerD

Lake Formation enforces table-level permissions through its own access layer, so the data scientist queries via Athena without IAM or S3 bucket policies exposing the storage location. Granting SELECT on the database and tables satisfies the query requirement while the underlying S3 paths remain hidden, because Lake Formation mediates access rather than S3 directly.

Why this answer

AWS Lake Formation allows fine-grained access control at the database, table, and column level without requiring direct S3 permissions. By granting SELECT on the Glue Data Catalog database and tables through Lake Formation, the data scientist can query the data via Athena or Redshift Spectrum while Lake Formation handles credential vending to access S3 on their behalf. This meets the requirement of preventing the data scientist from seeing the underlying S3 locations.

Exam trap

DEA-C01 often tests the misconception that Glue resource policies alone can restrict S3 visibility — candidates must recognize that only Lake Formation's credential vending hides S3 locations while still enabling queries.

How to eliminate wrong answers

Option A is wrong because a Glue resource policy controls access to the Data Catalog API itself but does not provide a mechanism to query data without S3 permissions, nor does it hide S3 locations from users who also have S3 access. Option B is wrong because granting IAM permissions to both Glue and S3 would allow the data scientist to see and access the S3 bucket directly, violating the requirement. Option C is wrong because a VPC endpoint only controls network routing and does not provide authorization or hide S3 locations from IAM principals.

236
Multi-Selecteasy

A data engineer is setting up a data pipeline using AWS DMS to migrate data from an on-premises database to Amazon RDS for MySQL. The data must be encrypted in transit. Which TWO options can the engineer use? (Choose TWO.)

Select 2 answers
A.Use VPC peering between on-premises and AWS
B.Enable SSL encryption on the DMS endpoint
C.Set up a VPN connection between on-premises and AWS
D.Use KMS to encrypt the DMS connection
E.Use a VPC endpoint for DMS
AnswersB, C

AWS DMS endpoints expose an SSL mode setting; enabling it encrypts replication traffic between the source, replication instance and target. This directly satisfies the in-transit encryption requirement for the on-premises to Amazon RDS for MySQL migration.

Why this answer

Option B is correct because AWS DMS endpoints for MySQL support SSL/TLS, and enabling the SSL encryption setting on the source and target endpoints causes DMS to negotiate an encrypted connection to the database, satisfying the in-transit encryption requirement. Option C is correct because a VPN connection (AWS Site-to-Site VPN) creates an IPsec-encrypted tunnel between the on-premises network and the AWS VPC, protecting data in transit as it crosses the public internet to reach Amazon RDS for MySQL. Option A is not correct because VPC peering only connects AWS VPCs to each other and does not extend to an on-premises network, so it cannot secure this migration path.

Option D is not correct because AWS KMS provides encryption at rest for stored data and keys, not encryption of the DMS network connection in transit. Option E is not correct because a VPC endpoint (AWS PrivateLink) provides private connectivity to AWS services within AWS, not an encrypted path from an on-premises database to RDS.

237
Drag & Dropmedium

Arrange the steps to implement data encryption at rest for an Amazon Redshift cluster using AWS KMS.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, create the KMS key. Then launch a new encrypted cluster, specify the key, configure, and verify encryption.

238
MCQmedium

A company uses Amazon Redshift for data warehousing. The security team requires that all data loading into Redshift be encrypted in transit. Which configuration ensures this requirement is met?

A.Use a VPC security group to restrict access
B.Configure the Redshift cluster to require SSL connections
C.Use client-side encryption before loading data
D.Enable server-side encryption on the Redshift cluster
AnswerB

Setting the cluster parameter require_ssl to true rejects any connection or COPY/UNLOAD operation that does not use TLS, so data in transit is encrypted. This directly satisfies the mandate that all loading into Redshift be encrypted in transit, without altering at-rest encryption or IAM permissions.

Why this answer

Configuring the Redshift cluster to require SSL connections (require_ssl = true in the parameter group) enforces TLS for all client connections, ensuring data is encrypted in transit during loads. This is the direct configuration that satisfies the in-transit encryption requirement.

Exam trap

The trap is confusing encryption at rest (SSE on the cluster) with encryption in transit (SSL required) — candidates pick server-side encryption thinking it covers network traffic.

How to eliminate wrong answers

Option A is wrong because VPC security groups control network reachability, not encryption; they do not encrypt traffic. Option C is wrong because client-side encryption protects data at rest before upload, not the in-transit channel to Redshift. Option D is wrong because server-side encryption on Redshift encrypts data at rest on disk, not data moving over the network.

239
MCQhard

A data engineer is troubleshooting an issue where an Amazon Redshift query returns an error: 'ERROR: permission denied for relation table_name'. The user has been granted SELECT on the table. What is the most likely cause?

A.The user's session has timed out.
B.The user does not have CONNECT permission on the database.
C.The table is in a different schema than expected.
D.The user does not have USAGE permission on the schema.
AnswerD

Redshift requires USAGE on the containing schema before SELECT on a table is honoured. Without schema USAGE, the query fails with permission denied even though SELECT was granted, making the missing schema-level privilege the most likely cause.

Why this answer

In Amazon Redshift, to access a table, a user must have USAGE permission on the schema containing the table, in addition to SELECT or other table-level permissions. Without USAGE on the schema, the user receives a 'permission denied for relation' error even if SELECT is granted. Option D is correct.

Option A (session timeout) would cause a different error or disconnection. Option B (no CONNECT permission) would prevent connecting to the database. Option C (wrong schema) would result in a 'schema not found' error, not a permission denied error.

240
MCQmedium

A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The engineer needs to grant a specific IAM role access to only the columns containing non-sensitive data in a table stored in the AWS Glue Data Catalog. The role should not have access to sensitive columns. What should the engineer do?

A.Grant the IAM role SELECT permission on the table, and then apply an IAM policy that denies access to the columns with sensitive data.
B.Use AWS Glue Data Catalog resource policies to deny access to the sensitive columns for the IAM role.
C.Create a Lake Formation data filter that excludes the sensitive columns, and grant the IAM role SELECT permission on the table with the data filter applied.
D.Create a view in Amazon Athena that selects only the non-sensitive columns, and grant the IAM role access to the view instead of the table.
AnswerC

Lake Formation data filters allow column-level and row-level access control. By creating a data filter that excludes sensitive columns and granting SELECT with that filter, the IAM role can access only the non-sensitive columns. This is the intended way to implement fine-grained access control in Lake Formation and meets the requirement precisely.

Why this answer

AWS Lake Formation provides column-level security through data filters. By creating a data filter that excludes sensitive columns and granting SELECT with that filter, the engineer ensures the IAM role can only access the permitted columns. This is the native and most secure method for fine-grained access control in Lake Formation.

Exam trap

The trap here is assuming that IAM policies or Glue Data Catalog resource policies can enforce column-level permissions, when in fact only Lake Formation data filters provide that capability.

241
Multi-Selectmedium

A data engineer must give an AWS Glue ETL job access to an S3 bucket that is encrypted with SSE-KMS using a customer managed key. The Glue job runs under an IAM role. The security team wants the least-privilege permissions required for the job to read and write objects in that bucket. Which TWO actions must be included in the IAM role's policy? (Choose two.)

Select 2 answers
A.kms:ListKeys on the customer managed key.
B.kms:Decrypt on the customer managed key.
C.kms:GenerateDataKey on the customer managed key.
D.kms:ScheduleKeyDeletion on the customer managed key.
E.kms:CreateGrant on the customer managed key.
AnswersB, C

When S3 objects are encrypted with SSE-KMS, reading an object requires the caller to have kms:Decrypt on the key that protects the object. The Glue job role must include this action or S3 returns AccessDenied during the read. Without it, the job cannot decrypt the data even if it has s3:GetObject.

Why this answer

Reading SSE-KMS encrypted objects requires kms:Decrypt on the key, and writing them requires kms:GenerateDataKey so S3 can obtain a fresh data key per object. These two KMS actions, combined with the appropriate s3:GetObject and s3:PutObject permissions, give the Glue job the minimum cryptographic access it needs without granting administrative key management capabilities.

Exam trap

The trap here is forgetting that SSE-KMS adds KMS permissions on top of S3 permissions, so an S3-only policy will still fail with AccessDenied.

242
Multi-Selectmedium

A company needs to enforce encryption at rest for all data stored in Amazon S3. Which of the following are valid methods to achieve this? (Choose TWO.)

Select 2 answers
A.Use Amazon S3 Transfer Acceleration.
B.Enable default bucket encryption using SSE-S3.
C.Enable S3 Versioning.
D.Use client-side encryption before uploading objects.
E.Use SSL/TLS for all S3 API calls.
AnswersB, D

Default bucket encryption with SSE-S3 applies AES-256 encryption automatically to every object written to the bucket, satisfying encryption at rest without per-object configuration. It is a bucket-level setting, so new uploads inherit it and existing unencrypted objects are not retroactively encrypted.

Why this answer

Option B is correct because enabling default bucket encryption with SSE-S3 causes Amazon S3 to automatically encrypt every object at rest using AES-256 with S3-managed keys, satisfying the requirement without any client changes. Option D is correct because client-side encryption encrypts the data before it ever reaches S3, so the objects are stored in encrypted form and remain protected at rest regardless of server-side settings. Option A is incorrect because S3 Transfer Acceleration only speeds up uploads over AWS edge locations and does not encrypt data at rest.

Option C is incorrect because S3 Versioning only preserves multiple object versions and does not provide encryption. Option E is incorrect because SSL/TLS protects data in transit between the client and S3, not data at rest in the bucket.

243
MCQmedium

Refer to the exhibit. A data engineer applies the following S3 bucket policy to an S3 bucket. What does this policy enforce?

A.Denies all uploads unless SSE-S3 is used
B.Allows only SSE-S3 encrypted uploads
C.Allows any type of server-side encryption
D.Requires that all objects uploaded to the bucket be encrypted with SSE-KMS
AnswerD

The policy's Deny on s3:PutObject triggers when the s3:x-amz-server-side-encryption header is absent or does not equal aws:kms, so uploads must specify SSE-KMS encryption. This enforces the SSE-KMS requirement rather than merely AES256 or transport encryption.

Why this answer

The bucket policy uses a Deny effect with a condition that checks if the s3:x-amz-server-side-encryption header is not 'aws:kms'. This means any PutObject request that does not use SSE-KMS will be denied. Therefore, the policy enforces that all objects uploaded must be encrypted with SSE-KMS.

Option A is incorrect because the policy does not mention SSE-S3; it denies if not SSE-KMS. Option B is incorrect because it requires SSE-KMS, not SSE-S3. Option C is incorrect because the policy only allows SSE-KMS, not any type of server-side encryption.

Option D is correct.

244
MCQeasy

A data engineer needs to store encryption keys used for protecting data in Amazon S3 and automatically rotate them every year. Which service should be used?

A.AWS KMS
B.AWS CloudHSM
C.AWS Certificate Manager
D.AWS Secrets Manager
AnswerA

AWS KMS stores customer master keys and supports automatic annual rotation, satisfying the yearly rotation constraint. S3 server-side encryption with SSE-KMS references these keys, so key material never leaves KMS and rotation is transparent to applications reading the protected objects.

Why this answer

AWS KMS is the managed service for creating, storing, and rotating encryption keys, and it supports automatic annual rotation for customer managed keys. It integrates natively with S3 SSE-KMS, making it the correct choice for key storage and yearly rotation.

Exam trap

The trap is confusing key management (KMS) with secret management (Secrets Manager) or certificate management (ACM) — only KMS handles encryption key storage and rotation.

How to eliminate wrong answers

Option B is wrong because CloudHSM provides dedicated hardware security modules for custom key management but does not offer automatic annual rotation as a built-in feature; it requires manual key management. Option C is wrong because Certificate Manager manages TLS/SSL certificates, not data encryption keys. Option D is wrong because Secrets Manager stores secrets like passwords and API keys, not encryption keys for S3 data.

245
MCQeasy

A company wants to enforce that all data in Amazon S3 is encrypted at rest. They want to automatically reject any PUT request that does not include encryption headers. What S3 feature should they use?

A.Bucket policy with a condition for encryption headers
B.Default encryption
C.MFA Delete
D.S3 Block Public Access
AnswerA

A bucket policy with `s3:PutObject` denied unless `s3:x-amz-server-side-encryption` is present rejects unencrypted PUT requests at the authorisation layer, satisfying the requirement to block uploads lacking encryption headers. This enforces encryption at rest without relying on client compliance or post-upload remediation.

Why this answer

An S3 bucket policy with a condition such as s3:x-amz-server-side-encryption or s3:x-amz-server-side-encryption-aws-kms-key-id can explicitly deny any PutObject request that lacks the required encryption headers. This enforces encryption at rest by rejecting unencrypted uploads at the API level, which is exactly the requirement. Default encryption alone does not reject unencrypted PUTs — it only encrypts them automatically.

Exam trap

DEA-C01 often tests whether candidates confuse default encryption (which silently encrypts but does not reject) with a bucket policy condition (which actively denies unencrypted PUTs) — the requirement to reject is the key differentiator.

How to eliminate wrong answers

Option B is wrong because default bucket encryption (SSE-S3 or SSE-KMS) transparently encrypts objects even when the client sends no encryption headers, so it does not reject unencrypted PUT requests — the opposite of the requirement. Option C is wrong because MFA Delete protects against accidental or malicious deletion of object versions; it has nothing to do with encryption enforcement. Option D is wrong because S3 Block Public Access prevents public ACLs and policies; it does not inspect or require encryption headers on PUT requests.

246
MCQeasy

A data engineer needs to share a dataset from an S3 bucket in Account A with users in Account B. The dataset must remain encrypted at rest with an S3-managed key. What is the MOST secure way to grant cross-account access?

A.Make the bucket public and use bucket policies to allow only Account B users.
B.Create a bucket policy that grants cross-account access to an IAM role in Account B.
C.Use S3 object ACLs to grant access to Account B's root user.
D.Use an S3 VPC endpoint to allow Account B users through private IPs.
AnswerB

A bucket policy granting access to an IAM role in Account B satisfies the cross-account requirement without exposing long-lived credentials. Account B users assume that role via AWS STS, receiving temporary credentials scoped by the trust policy. SSE-S3 encryption remains intact, since S3-managed keys need no cross-account KMS permissions, unlike SSE-KMS.

Why this answer

A bucket policy granting access to the IAM role in Account B is the recommended secure method for cross-account access to S3 objects encrypted with S3-managed keys. Option A is insecure because it grants public access. Option C is incorrect because ACLs are legacy and less secure for cross-account scenarios.

Option D is incorrect because while S3 VPC endpoints are a valid AWS feature that provides private connectivity to S3, they do not grant cross-account access; bucket policies are still required to authorize access.

← PreviousPage 4 of 4 · 246 questions total

Ready to test yourself?

Try a timed practice session using only Data Security Governance questions.