AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineer is developing a Python AWS Lambda function that runs inside a VPC and writes transformed CSV files to an Amazon S3 bucket in the same AWS account. The company prohibits hard-coding or storing long-lived access keys. According to AWS best practices for authentication, which approach will allow the function to authenticate to S3 while complying with the policy?

  • Use an S3 Access Point, and reference its ARN when creating the Lambda function; no IAM configuration is required.

  • Add a bucket ACL granting write permission to the Lambda service's public IP addresses.

  • Store an IAM user's access key and secret key in AWS Secrets Manager and read them at runtime.

  • Configure an IAM role with S3 write permissions and assign it as the Lambda execution role.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot