AWS Certified Data Engineer Associate DEA-C01 Practice Question
An analytics team stores daily click-stream files in an Amazon S3 bucket named prod-clicks. Several AWS Glue jobs, partner applications, and third-party tools PUT and GET objects by using the bucket REST endpoint. A recent compliance audit mandates that every request to the bucket be encrypted in transit, and the team cannot modify any calling application. Which action should a data engineer take to meet the requirement consistently?
Create an Amazon CloudFront distribution for the bucket, require HTTPS at the viewer connection, and give applications the distribution URL.
Attach a bucket policy that denies any request where the aws:SecureTransport condition key is false, ensuring only HTTPS traffic is accepted.
Enable server-side encryption with AWS KMS (SSE-KMS) and rotate the KMS key annually.
Turn on S3 Block Public Access for the bucket at both the account and bucket levels.
Adding a bucket policy that denies requests when the aws:SecureTransport condition key is false forces all callers-regardless of the client, SDK version, or network path-to use HTTPS. Because HTTPS provides TLS, data is encrypted while in transit. The change is enforced by Amazon S3 itself, so no application code or endpoint change is required. SSE-KMS protects data at rest only, S3 Block Public Access does not enforce TLS, and placing CloudFront in front of the bucket would require clients to use the distribution URL, violating the no-code-change constraint.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the aws:SecureTransport condition key do in an S3 bucket policy?
Open an interactive chat with Bash
What is the difference between encryption in transit and encryption at rest?
Open an interactive chat with Bash
Why is CloudFront not a suitable alternative in this scenario?
Open an interactive chat with Bash
What is the aws:SecureTransport condition key in an S3 bucket policy?
Open an interactive chat with Bash
Why doesn't server-side encryption (SSE-KMS) meet the requirement for encrypting data in transit?
Open an interactive chat with Bash
How does enforcing HTTPS with a bucket policy differ from using CloudFront in this scenario?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .