AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineer is building an AWS Glue job that reads raw files from an S3 data lake and loads the cleaned data into Amazon Redshift. Corporate security standards require role-based authentication and forbid storage of long-lived secrets in code or configuration. Which approach meets the requirement with the least operational overhead?

  • Add a bucket policy that grants public read access and keep using the default AWSGlueServiceRole without additional permissions.

  • Attach an IAM role with the minimum required S3 and Amazon Redshift permissions to the AWS Glue job and rely on the role's temporary credentials at runtime.

  • Store an IAM user's access key and secret in AWS Secrets Manager and have the job retrieve them for S3 and Redshift access.

  • Generate presigned S3 URLs for every required object and pass the URLs as job arguments so no IAM policies are needed.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot