AWS Certified Data Engineer Associate DEA-C01 Practice Question

An encrypted data lake is stored in an Amazon S3 bucket owned by the Security AWS account. Application teams in three other accounts must upload objects that remain encrypted with server-side AWS KMS and can be decrypted only by analysts in the Security account. Which configuration meets these requirements with minimal key-management overhead?

  • Turn on default bucket encryption with the AWS managed key aws/s3 and give the application roles s3:PutObject permission.

  • Create a separate customer-managed KMS key in each application account, grant the Security account decryption, and configure the bucket to accept uploads encrypted with the corresponding key.

  • Define a single customer-managed KMS key in the Security account. In its key policy allow the application-account roles only kms:Encrypt, kms:GenerateDataKey*, and kms:ReEncrypt* actions. Require SSE-KMS with that key ARN in the bucket policy.

  • Provide presigned PUT URLs that include SSE-C headers so each application team supplies its own client-side key when uploading.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot