AWS Certified Data Engineer Associate DEA-C01 Practice Question

A company stores multiple datasets in a single Amazon S3 bucket. Objects are tagged Team=. AWS Glue jobs run under IAM roles that carry the same Team tag. The security team wants each job to read only objects matching its Team tag, without creating new policies when new teams join. Which authorization approach will best satisfy this requirement?

  • Implement ABAC by attaching one IAM policy that allows s3:GetObject when the principal's Team tag matches the object's Team tag.

  • Provision an S3 Access Point per team and use access point resource policies to restrict read access to the corresponding role.

  • Apply S3 object ACLs that grant read permission to each team's IAM role whenever new data is uploaded.

  • Create a dedicated IAM role and managed policy for each team that grants access to that team's S3 prefix.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot