Courseiva
Database SecurityhardMultiple ChoiceObjective-mapped

DBS-C01 Deterministic encryption Practice Question

A company uses Amazon DynamoDB with a global secondary index (GSI) and client-side encryption using the AWS Encryption SDK. The security team requires that the partition key and sort key be searchable by the application but not stored in plaintext in the table. Which approach should be taken?

⚠ Common exam trap

Candidates often assume that partition and sort keys must be stored in plaintext to be indexed, but deterministic encryption allows indexed attributes to be encrypted while still supporting equality searches via a GSI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Encrypt the entire item client-side and use a secondary index on the encrypted keys.

The requirement is to prevent partition and sort keys from being stored in plaintext while still allowing the application to search by them. Option A achieves this by using client-side deterministic encryption (supported by the AWS Encryption SDK) for the entire item, which encrypts the keys. Because the encryption is deterministic, the same plaintext key always produces the same ciphertext, so a global secondary index can be built on the encrypted key attributes. The application encrypts the search key and queries the GSI using that encrypted value, enabling search without exposing plaintext keys. Option C leaves keys in plaintext, violating the requirement. Options B and D do not address client-side encryption and cannot prevent plaintext key storage in the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Encrypt the entire item client-side and use a secondary index on the encrypted keys.

    Why this is correct

    Correct. Deterministic encryption of the entire item, including keys, allows a GSI on the encrypted keys to be searchable without storing plaintext keys.

  • Use server-side encryption with a KMS key and enable DynamoDB Streams to decrypt on read.

    Why it's wrong here

    Incorrect. Server-side encryption only protects data at rest; DynamoDB still stores keys in plaintext internally and applications can read them.

  • Use client-side encryption to encrypt only the non-key attributes, leaving the partition and sort keys in plaintext.

    Why it's wrong here

    Incorrect. This option stores partition and sort keys in plaintext, directly contradicting the requirement that they not be stored in plaintext.

  • Use DynamoDB encryption at rest with a customer-managed KMS key.

    Why it's wrong here

    Incorrect. Encryption at rest with a customer-managed KMS key does not prevent keys from being stored in plaintext; it only encrypts the data at the storage layer.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,663 original DBS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DBS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DBS-C01 exam.