AWS Certified Data Engineer Associate DEA-C01 Practice Question

An automotive startup secures its Amazon S3 data lake with AWS Lake Formation. Every Data Catalog table is tagged with LF-Tag keys dataset (telemetry, images) and sensitivity (pii, public). The data-science IAM role must be able to query only telemetry tables that are public and must automatically be blocked from any new tables that do not satisfy both conditions. Which approach meets these requirements with minimal ongoing administration?

  • Attach a customer-managed IAM policy that uses ABAC to allow lakeformation:GetDataAccess when resource tags dataset = telemetry and sensitivity = public.

  • Grant SELECT on the telemetry database and explicitly exclude columns tagged sensitivity = pii.

  • Add an S3 bucket policy allowing s3:GetObject only on telemetry prefixes and denying objects whose metadata sensitivity = pii.

  • Create an LF-Tag permission for the IAM role that grants SELECT on tables where dataset = telemetry and sensitivity = public.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot