AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineering team is updating the IAM role used by an Amazon Redshift cluster to read data from several Amazon S3 buckets. The compliance team insists that permission changes must remain under the company's control and be reviewable in the IAM policy versions. Which approach meets the requirement while following AWS best practices for least privilege?

  • Apply a service control policy (SCP) that allows the Redshift role to list and read objects in the specified buckets.

  • Add an inline policy with read-only S3 permissions directly to the Redshift IAM role.

  • Create a customer managed policy that grants read-only access to the required S3 buckets and attach it to the Redshift IAM role.

  • Attach the AWS managed policy AmazonS3ReadOnlyAccess to the Redshift IAM role.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot