AWS Certified Data Engineer Associate DEA-C01 Practice Question
An automotive startup secures its Amazon S3 data lake with AWS Lake Formation. Every Data Catalog table is tagged with LF-Tag keys dataset (telemetry, images) and sensitivity (pii, public). The data-science IAM role must be able to query only telemetry tables that are public and must automatically be blocked from any new tables that do not satisfy both conditions. Which approach meets these requirements with minimal ongoing administration?
Attach a customer-managed IAM policy that uses ABAC to allow lakeformation:GetDataAccess when resource tags dataset = telemetry and sensitivity = public.
Grant SELECT on the telemetry database and explicitly exclude columns tagged sensitivity = pii.
Add an S3 bucket policy allowing s3:GetObject only on telemetry prefixes and denying objects whose metadata sensitivity = pii.
Create an LF-Tag permission for the IAM role that grants SELECT on tables where dataset = telemetry and sensitivity = public.
LF-Tag-based permissions can grant access to any Data Catalog resources whose tags match a logical expression. Granting the IAM role the SELECT permission on tables where dataset = telemetry and sensitivity = public enforces least privilege and automatically includes any future tables that carry the same tags-no additional administration is needed.
Granting SELECT on individual tables (or on all tables in a database) would still allow access to images tables that happen to be in the same database, and table-by-table grants require updates whenever new telemetry tables are created. S3 bucket policies operate at the object level and cannot enforce Lake Formation table- or column-level controls used by Athena. Finally, an IAM ABAC policy cannot filter Lake Formation data access by dataset or sensitivity because Lake Formation APIs do not support resource tag conditions for GetDataAccess.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are LF-Tags in AWS Lake Formation?
Open an interactive chat with Bash
Why can't S3 bucket policies be used for this scenario?
Open an interactive chat with Bash
What is the advantage of using LF-Tag permissions with logical expressions?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .