AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineering team must allow an AWS Glue job running in account A to write objects to an Amazon S3 bucket that belongs to account B. The solution must prevent storage of long-lived credentials inside the job code and must operate without human interaction. Which authentication method should the team use?

  • Configure an IAM role in account B and allow the AWS Glue job to assume that role by using AWS STS.

  • Generate a pre-signed S3 URL and embed it in the Glue job parameters before each run.

  • Create an IAM user in account B, store its access keys in AWS Secrets Manager, and retrieve them from the job at runtime.

  • Upload an X.509 client certificate so the Glue job can use mutual TLS authentication with Amazon S3.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot