🔥 40% Off Crucial Exams Memberships — This Week Only

3 days, 4 hours remaining!

AWS Certified Data Engineer Associate DEA-C01 Practice Question

An e-commerce company stores customer PII in an Amazon S3 data lake, transforms it with AWS Glue, and loads the results into Amazon Redshift. Compliance states that data at rest must be encrypted with a customer-managed KMS key and that traffic between Glue, S3, and Redshift must be protected with TLS. The team wants the simplest solution that avoids code changes. Which approach meets these requirements?

  • Keep the S3 bucket unencrypted, let the Glue job encrypt output files before writing to Redshift, and control traffic with network ACLs instead of TLS.

  • Turn on SSE-S3 on the bucket, keep the default Glue settings, encrypt Redshift with the AWS-managed key, and rely on VPC endpoints for traffic.

  • Enable SSE-KMS with a customer CMK on the S3 bucket, create a Glue security configuration that uses the CMK, encrypt the Redshift cluster with the same CMK, and set require_SSL=true.

  • Use the Amazon S3 Encryption Client for client-side encryption with a customer key, configure Glue to decrypt objects, and enable SSL to an unencrypted Redshift cluster.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot