AWS Certified Data Engineer Associate DEA-C01 Practice Question
An Amazon EMR cluster runs in a private subnet without a NAT gateway. Jobs must upload logs to an Amazon S3 bucket in the same account, but writes now fail with AccessDenied errors. The cluster uses the default EMR_EC2_DefaultRole. What should the data engineer do to enable logging while ensuring traffic stays on the AWS network?
Enable server-side encryption with AWS KMS on the S3 bucket and configure the cluster for SSE-KMS.
Store an access key for an IAM user with S3 permissions in AWS Secrets Manager and retrieve it from a bootstrap action.
Update the EMR_EC2_DefaultRole policy to allow s3:PutObject on the log bucket and create a gateway VPC endpoint for Amazon S3 in the VPC route tables.
Attach the AmazonS3FullAccess managed policy to EMR_EC2_DefaultRole and add an internet gateway route to the private subnet.
EMR nodes obtain temporary credentials from the instance-profile role, so the role must include permission to write to the specific log bucket. Because the cluster is in a private subnet and must avoid public internet paths, traffic to Amazon S3 has to use a gateway VPC endpoint. Granting s3:PutObject permission to EMR_EC2_DefaultRole and creating the S3 gateway endpoint together provide the required authorization and a private network route. Retrieving long-term keys from Secrets Manager still violates best practices and adds operational risk. Allowing full S3 access and routing through an internet gateway exposes the subnet to the internet and breaks the privacy requirement. Enabling server-side encryption changes data-at-rest settings but does not address the missing permission or network path that caused AccessDenied.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a gateway VPC endpoint?
Open an interactive chat with Bash
What is EMR_EC2_DefaultRole?
Open an interactive chat with Bash
Why doesn’t storing an access key in Secrets Manager meet best practices?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .