DEA-C01 exam dumps

DEA-C01 practice question 490 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 490

Single answer

A company is storing sensitive data in Amazon S3 and needs to ensure that the data is encrypted. They are considering using either client-side encryption or server-side encryption. Which of the following is a key difference between client-side encryption and server-side encryption?

  1. A

    With client-side encryption, encryption happens before data is uploaded to Amazon S3, whereas with server-side encryption, encryption happens after data is uploaded.

  2. B

    Server-side encryption allows customers to manage their own encryption keys, whereas client-side encryption does not.

  3. C

    Client-side encryption enables the use of AWS Key Management Service (KMS) for key management, whereas server-side encryption does not.

  4. D

    With server-side encryption, data is encrypted on the client-side before being sent to Amazon S3.

Show answer and explanation

Correct answer: A

Explanation

Client-side encryption and server-side encryption differ in where the encryption process occurs. With client-side encryption, the data is encrypted before it is sent to Amazon S3, which means the client is responsible for managing the encryption keys. Server-side encryption, on the other hand, encrypts the data once it is received by Amazon S3, and AWS manages the encryption process. This distinction is crucial for determining the appropriate encryption strategy for securing data in storage.

  • A. Correct.

    This is correct. Client-side encryption happens before the data is uploaded to Amazon S3, while server-side encryption occurs after the data is uploaded.

  • B. Incorrect.

    This is incorrect. Server-side encryption can use AWS KMS or AWS-managed keys, but client-side encryption also allows customers to manage their own encryption keys.

  • C. Incorrect.

    This is incorrect. Client-side encryption does not rely on AWS KMS; customers typically manage their own encryption keys outside AWS services.

  • D. Incorrect.

    This is incorrect. Server-side encryption does not encrypt data on the client-side; it performs encryption on the server after receiving the data.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam