AWS Certified Data Engineer Associate DEA-C01 Practice Question

An AWS Glue ETL job processes files that contain PII. The source and destination Amazon S3 buckets must enforce encryption at rest with customer-managed keys. Security forbids use of the default aws/s3 KMS key and wants other AWS accounts to read the output. Which approach meets these requirements with the least operational effort?

  • Enable SSE-S3 on both buckets and add a bucket policy that denies uploads without encryption.

  • Implement client-side encryption in the Glue job using a key stored in AWS Secrets Manager, then upload the encrypted objects.

  • Enable SSE-KMS with the AWS managed key (aws/s3) and create S3 Access Points for the external accounts.

  • Enable SSE-KMS with a customer-managed key, configure bucket default encryption to use that key, and add the external accounts to the key policy and bucket policy.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot