AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineer configured an Amazon Redshift RA3 cluster to query Parquet files in an S3 data lake by using Redshift Spectrum. The cluster assumes the IAM role "redshift-lf-role", which already has AmazonS3ReadOnlyAccess and AWSGlueConsoleFullAccess attached. When analysts run SELECT statements on an external schema, they receive an "access denied" error. Which change will most closely follow the principle of least privilege while allowing the queries to succeed?

  • Add the IAM role "redshift-lf-role" to the Lake Formation administrator list to remove all permission checks.

  • In Lake Formation, grant the IAM role "redshift-lf-role" the SELECT permission on the specific Data Catalog database and table.

  • Add an inline IAM policy that allows s3:GetObject on the data lake bucket and disable the Lake Formation permission model.

  • Attach the AWS managed policy AmazonAthenaFullAccess to the IAM role so Redshift Spectrum can inherit Athena permissions.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot