AWS Certified Data Engineer Associate DEA-C01 Practice Question
An analytics team processes confidential credit-card data with an Amazon EMR cluster that runs Apache Spark. Source files reside in Amazon S3 (accessed through EMRFS), and Spark writes temporary and shuffle data to the cluster's EBS volumes. Compliance mandates that all data at rest be encrypted with AWS-managed KMS keys while minimizing administrative overhead. Which approach satisfies these requirements?
Install dm-crypt in a bootstrap action to encrypt each EBS volume and configure client-side encryption (CSE-KMS) for all S3 operations.
Create an EMR security configuration that enables SSE-KMS for EMRFS with the default aws/s3 AWS-managed key and turns on EBS encryption using the default aws/ebs AWS-managed key, then launch the cluster with this configuration.
Use Hadoop Transparent Data Encryption for on-cluster data and store the master key on an EC2 key server, leaving the S3 objects unencrypted.
Enable local disk encryption with a customer-managed KMS key and enforce SSE-S3 on the S3 bucket.
An EMR security configuration can apply AWS-managed KMS keys to each storage layer in one step. Selecting server-side encryption with KMS (SSE-KMS) for EMRFS and keeping the default key alias aws/s3 encrypts every new object in S3. The same configuration can enable EBS encryption; choosing the default key alias aws/ebs automatically encrypts all root and attached EBS volumes without extra scripting or key rotation. No custom keys are created, so administrative effort stays low. The other options either depend on customer-managed or S3-managed keys, omit one of the storage layers, or add manual encryption steps, so they do not meet the stated requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SSE-KMS and how does it work in Amazon EMR?
Open an interactive chat with Bash
How does EBS encryption work in an EMR cluster?
Open an interactive chat with Bash
Why is an EMR security configuration recommended for encryption?
Open an interactive chat with Bash
What is SSE-KMS in the context of Amazon S3?
Open an interactive chat with Bash
How does EBS encryption work with AWS-managed keys?
Open an interactive chat with Bash
What is an EMR security configuration, and how is it used?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .