AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineering team owns a producer Amazon Redshift cluster in account A (us-east-1). Business analysts in account B need always-up-to-date read-only access to six tables that contain no PII. The solution must minimize data movement, prevent analysts from creating or modifying database objects, and follow the principle of least privilege. Which approach meets these requirements?

  • Configure VPC peering between the two clusters and create federated external tables in account B that reference the producer tables. Grant the analysts role permission to query the external tables.

  • On the producer cluster, create a datashare, add the six tables, and authorize account B. On the consumer cluster, create a database from the datashare, then grant USAGE on the database and SELECT on the shared tables to the analysts role.

  • Create a manual snapshot of the producer cluster, share the snapshot with account B, and have account B restore it to its own cluster. Grant the analysts role read-only access on the restored cluster.

  • Unload the six tables to an encrypted Amazon S3 bucket. Use AWS Lake Formation cross-account resource links to grant the analysts role SELECT access to the unloaded data.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot