AWS Certified Data Engineer Associate DEA-C01 Practice Question

An Amazon Redshift cluster runs in private subnets without a NAT gateway. The cluster must query only the objects in the s3://dept-finance/raw/ prefix by using Redshift Spectrum. A VPC interface endpoint (AWS PrivateLink) for Amazon S3 already exists in the subnets. Which action enforces this restriction while leaving other VPC workloads unaffected?

  • Replace the interface endpoint with an S3 gateway endpoint, associate it with the private subnets, and create a bucket policy that limits access to the raw/ prefix.

  • Modify the Redshift cluster's IAM role to allow s3:GetObject on dept-finance/raw/* and s3:ListBucket on the dept-finance bucket, leaving the endpoint configuration unchanged.

  • Add a bucket policy on the dept-finance bucket that allows GetObject only from the specified VPC endpoint and raw/ prefix while denying all other access paths.

  • Attach a custom IAM endpoint policy to the S3 interface VPC endpoint that permits s3:GetObject on arn:aws:s3:::dept-finance/raw/*, s3:ListBucket on arn:aws:s3:::dept-finance, and denies all other S3 actions.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot