AWS Certified Data Engineer Associate DEA-C01 Practice Question
A data engineering team uses an AWS Glue ETL job to write daily Parquet files to an Amazon S3 bucket. A new compliance rule mandates that the encryption key protecting these files must rotate automatically every 90 days without exposing plaintext key material or requiring code changes. How should the team meet this requirement?
Continue using SSE-KMS with the AWS managed key (aws/s3) since AWS automatically rotates that key.
Enable SSE-S3 on the bucket and rotate the IAM access keys used by the Glue job every 90 days.
Configure S3 default encryption with SSE-KMS using a customer-managed KMS key and set the key's RotationPeriodInDays to 90; reference the same key in the Glue job.
Add client-side encryption to the Glue script with the AWS Encryption SDK, generate a new data key every 90 days, and store it in AWS Secrets Manager.
Configuring bucket-level SSE-KMS with a customer-managed KMS key and enabling automatic rotation at a 90-day interval satisfies all constraints. AWS KMS creates a new key version every 90 days while retaining previous versions for transparent decryption, so no application changes are needed. AWS-managed keys rotate only every 365 days, SSE-S3 offers no controllable key rotation, and a client-side scheme would require code that handles plaintext keys and manages its own rotation schedule.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SSE-KMS and how does it differ from other S3 encryption options?
Open an interactive chat with Bash
How does key rotation work in AWS KMS with customer-managed keys?
Open an interactive chat with Bash
Why can AWS-managed keys not meet the 90-day rotation compliance rule?
Open an interactive chat with Bash
What is SSE-KMS and how does it differ from SSE-S3?
Open an interactive chat with Bash
How does automatic key rotation work in customer-managed KMS keys?
Open an interactive chat with Bash
Why is AWS-managed key rotation not suitable for this use case?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .