AWS Certified Data Engineer Associate DEA-C01 Practice Question
A data engineering team is updating the IAM role used by an Amazon Redshift cluster to read data from several Amazon S3 buckets. The compliance team insists that permission changes must remain under the company's control and be reviewable in the IAM policy versions. Which approach meets the requirement while following AWS best practices for least privilege?
Add an inline policy with read-only S3 permissions directly to the Redshift IAM role.
Attach the AWS managed policy AmazonS3ReadOnlyAccess to the Redshift IAM role.
Apply a service control policy (SCP) that allows the Redshift role to list and read objects in the specified buckets.
Create a customer managed policy that grants read-only access to the required S3 buckets and attach it to the Redshift IAM role.
A customer managed policy keeps all permission changes fully under the company's control. The organization can scope the policy to only the required S3 buckets and store new policy versions for audit review. An AWS managed policy such as AmazonS3ReadOnlyAccess cannot be altered and might receive additional permissions when AWS updates it. Inline policies are harder to audit across roles, and service control policies affect the entire account or OU rather than just the Redshift role.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a customer managed policy in AWS?
Open an interactive chat with Bash
Why is the AWS managed policy AmazonS3ReadOnlyAccess not the best practice for least privilege?
Open an interactive chat with Bash
What are inline policies, and why are they harder to audit?
Open an interactive chat with Bash
What is a customer managed policy in AWS?
Open an interactive chat with Bash
Why is least privilege considered an AWS best practice?
Open an interactive chat with Bash
What is the difference between customer managed policies and AWS managed policies?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .