AWS Certified Data Engineer Associate DEA-C01 Practice Question
An AWS Glue ETL job running in Account A must write Parquet files to an Amazon S3 data lake owned by Account B. Security policy states that data must be encrypted at rest with a customer-managed KMS key that resides in Account B. Which approach meets the requirement while following the principle of least privilege?
Modify the Glue script to perform client-side encryption with the AWS Encryption SDK, upload objects with the x-amz-server-side-encryption: AES256 header, and store the data key in AWS Secrets Manager.
Configure the Glue job to use SSE-S3 for all writes, relying on Amazon S3 automatic encryption without additional KMS permissions.
Create a customer-managed KMS key in Account B, update the key policy to allow Account A's Glue execution role kms:Encrypt and kms:GenerateDataKey*, configure the job's security configuration for SSE-KMS with the key's full ARN, and grant the role PutObject permission on the bucket.
Enable default bucket encryption on the data-lake bucket with the AWS managed key aws/s3 and add a bucket policy that permits the Glue role to upload objects.
SSE-KMS can be used across accounts only with a customer-managed KMS key. The key owner (Account B) must add the external principal to the key policy and grant only the encryption permissions required for uploads (kms:Encrypt and kms:GenerateDataKey*). The Glue job in Account A then references the key's full ARN in its S3Encryption configuration, so Amazon S3 encrypts each object with that key. AWS managed keys (aws/s3) cannot be shared across accounts, SSE-S3 provides no control over key ownership, and SSE-C client-side encryption does not satisfy the requirement to use the Account B CMK.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SSE-KMS and how does it work for cross-account encryption?
Open an interactive chat with Bash
Why is a customer-managed KMS key preferred over AWS-managed keys for this use case?
Open an interactive chat with Bash
What is the principle of least privilege, and how does it apply here?
Open an interactive chat with Bash
What is SSE-KMS encryption and how does it work across AWS accounts?
Open an interactive chat with Bash
Why can't AWS managed keys (aws/s3) be used for encryption across accounts?
Open an interactive chat with Bash
What are the differences between client-side encryption and server-side encryption in AWS?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .