AWS Certified Data Engineer Associate DEA-C01 Practice Question
A company stores multiple datasets in a single Amazon S3 bucket. Objects are tagged Team=. AWS Glue jobs run under IAM roles that carry the same Team tag. The security team wants each job to read only objects matching its Team tag, without creating new policies when new teams join. Which authorization approach will best satisfy this requirement?
Implement ABAC by attaching one IAM policy that allows s3:GetObject when the principal's Team tag matches the object's Team tag.
Provision an S3 Access Point per team and use access point resource policies to restrict read access to the corresponding role.
Apply S3 object ACLs that grant read permission to each team's IAM role whenever new data is uploaded.
Create a dedicated IAM role and managed policy for each team that grants access to that team's S3 prefix.
Attribute-based access control (ABAC) allows a single IAM policy to enforce that the Team tag on the calling principal matches the Team tag on the S3 object. A condition such as "s3:ResourceTag/Team == aws:PrincipalTag/Team" dynamically authorizes access whenever matching tags are present, so new teams can be onboarded simply by tagging roles and objects. Creating separate roles or managed policies, maintaining ACLs, or configuring individual S3 Access Points would all require ongoing manual updates and therefore do not meet the stated goal.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ABAC in AWS and how does it differ from RBAC?
Open an interactive chat with Bash
What is the purpose of the s3:ResourceTag and aws:PrincipalTag conditions in an ABAC IAM policy?
Open an interactive chat with Bash
Why is managing tags for ABAC policies more scalable than using S3 ACLs or multiple IAM roles?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .