AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your company runs nightly Apache Spark jobs on an Amazon EMR cluster (release 6.x) that ingests raw files from an S3 bucket and then loads aggregated results into an Amazon Redshift RA3 cluster. Compliance mandates that every analytics service involved must store data encrypted at rest with AWS-managed keys while requiring the least operational effort from engineers. Which combination satisfies these requirements?
Encrypt EMR volumes manually with LUKS in a bootstrap action, set the S3 bucket to SSE-S3, and configure the Redshift cluster to use local AES-256 software encryption.
Enable only in-transit encryption on the EMR cluster, require TLS in the S3 bucket policy, and rely on a snapshot copy grant for Redshift.
Use client-side encryption in Spark with a custom key service, configure the S3 bucket for SSE-C with customer-supplied keys, and disable encryption on the Redshift cluster.
Enable EMR encryption at rest with AWS KMS, turn on SSE-KMS for the S3 bucket, and create the Redshift cluster with the default AWS KMS encryption key.
Encryption at rest with the least administration effort is achieved when each service relies on AWS-managed KMS keys. Amazon EMR can be launched with at-rest encryption enabled, which encrypts EBS volumes and EMRFS metadata using AWS KMS. Enabling SSE-KMS on the S3 bucket stores data with KMS-managed keys without any client changes. When an Amazon Redshift cluster is created with encryption turned on, it automatically uses an AWS KMS key (either the default AWS-managed key or a customer-managed one); choosing the default key keeps operational overhead minimal. The other choices either leave one service unencrypted, rely on client-side key management, or use configurations (SSE-S3, custom LUKS scripts, Redshift software AES-256) that do not meet the requirement for AWS-managed KMS keys across all services.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is EMR encryption at rest with AWS KMS?
Open an interactive chat with Bash
How does SSE-KMS work for S3 buckets?
Open an interactive chat with Bash
What is the default AWS KMS key in Amazon Redshift?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .