AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineering team runs a producer application on Amazon EC2 instances in a private subnet. The application must publish messages to an Amazon MSK cluster. Security requires that both the client and the brokers present X.509 certificates issued by the company's private CA and that no plaintext credentials are stored or transmitted. Which authentication mechanism should the team configure on the MSK cluster to meet these requirements?

  • Enable mutual TLS authentication using certificates issued by an ACM Private CA.

  • Configure SASL/IAM authentication and attach an IAM policy that allows kafka:Connect to the EC2 instance role.

  • Use TLS encryption with the broker's certificate only and rely on network security groups for client trust.

  • Enable SASL/SCRAM authentication and store user credentials in AWS Secrets Manager.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot