AWS Certified Data Engineer Associate DEA-C01 Practice Question

An industrial IoT platform collects sensitive telemetry on edge devices and uploads the data to an Amazon S3 bucket. A compliance mandate states that neither plaintext data nor encryption keys may ever leave the devices or be visible to AWS services. Each device can perform symmetric encryption but should remain simple to operate. Which approach best satisfies the compliance requirement while minimizing operational overhead?

  • Upload the data to the S3 bucket with server-side encryption using a customer-managed AWS KMS key (SSE-KMS).

  • Include a customer-provided encryption key in each PUT request so the bucket uses server-side encryption with customer-provided keys (SSE-C).

  • Stream the telemetry unencrypted into Amazon Kinesis Data Firehose and enable encryption with an AWS managed KMS key before delivery to S3.

  • Use the AWS Encryption SDK on each device to perform client-side encryption and upload the resulting ciphertext object to S3 with no server-side encryption setting.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot