DEA-C01 exam dumps

DEA-C01 practice question 491 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 491

Single answer

You are working as a data engineer for a company that processes sensitive customer data. The company uses Amazon S3 for data storage and wants to ensure data at rest is encrypted. However, they are unsure whether to use client-side encryption or server-side encryption. Which of the following is a characteristic of client-side encryption?

  1. A

    Encryption keys are managed and stored by AWS.

  2. B

    Encryption and decryption are handled entirely on the client side before data is uploaded or downloaded.

  3. C

    AWS Key Management Service (KMS) is required for encryption and decryption.

  4. D

    Data is encrypted after it is uploaded to S3.

Show answer and explanation

Correct answer: B

Explanation

Client-side encryption requires that all encryption and decryption operations happen on the client’s system, and AWS does not manage or store the encryption keys. This contrasts with server-side encryption, where AWS handles encryption and manages keys. Choosing client-side encryption is often used when the organization wants full control over the encryption keys for compliance or security reasons.

  • A. Incorrect.

    This is incorrect because in client-side encryption, encryption keys are not managed by AWS. They are managed by the client or an external key management solution.

  • B. Correct.

    This is correct because client-side encryption involves encrypting the data locally on the client side before it is uploaded to AWS services like S3. Similarly, decryption is handled on the client side after downloading the data.

  • C. Incorrect.

    This is incorrect because AWS KMS is not mandatory for client-side encryption. Clients can use their own key management solutions or libraries to handle encryption.

  • D. Incorrect.

    This is incorrect because in client-side encryption, data is encrypted before it is uploaded to S3, not after.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam