AWS Certified Data Engineer Associate DEA-C01 Practice Question
An analytics team schedules an AWS Glue ETL job in a private subnet with no internet gateway. The job must first call AWS Secrets Manager to retrieve a database password and then write transformed data to a single Amazon S3 bucket. Following AWS security best practices, how should you grant the job only the required permissions?
Assign the managed policy AWSGlueServiceRole to the account's default Glue service role and let the job use that role.
Embed an AWS access key and secret key for an IAM user with the necessary permissions in the job's environment variables.
Add an inline policy to the VPC security group that permits Secrets Manager and S3 access for the job subnet.
Attach a scoped policy that allows secretsmanager:GetSecretValue on the secret ARN and s3:PutObject on the target bucket to the IAM role assumed by the Glue job.
The least-privilege approach is to attach a customer-managed (or inline) policy that grants just secretsmanager:GetSecretValue for the specific secret ARN and s3:PutObject (and related read actions if needed) for the target bucket to the IAM role that the Glue job assumes at run time. Because the job uses a role, short-term credentials are provided automatically. Embedding long-term access keys or relying on the default AWSGlueServiceRole either exposes unnecessary permissions or violates the principle of least privilege. Security groups cannot grant IAM permissions, so they do not solve the authorization requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege in AWS?
Open an interactive chat with Bash
Why can't security groups grant IAM permissions?
Open an interactive chat with Bash
What is the benefit of using IAM roles with short-term credentials for AWS Glue jobs?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .