AWS Certified Data Engineer Associate DEA-C01 Practice Question

An analytics team in Account A must query customer tables stored as Parquet files in several Amazon S3 buckets that belong to Account B. Analysts should see only the rows for the sales region they cover. Queries will run from Amazon Athena and Amazon Redshift Spectrum. Which Lake Formation configuration in Account B meets these security and access requirements while minimizing operational overhead?

  • Use S3 bucket policies that restrict access to region-specific prefixes and create IAM roles that analysts in Account A assume to access those prefixes.

  • Register the S3 locations with Lake Formation, create a Data Filter for each region, grant SELECT permission on the tables using the appropriate filter, and share the governed tables and filters with Account A through AWS Resource Access Manager.

  • Register the S3 locations, create LF-Tags for each region, grant LF-Tag permissions to Account A, and rely on LF-Tags to provide row-level security.

  • Copy each region's data into separate S3 buckets, create region-specific Athena workgroups, and restrict workgroup membership with IAM policies.

AWS Certified Data Engineer Associate DEA-C01
Data Store Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot