AWS Certified Data Engineer Associate DEA-C01 Practice Question
An AWS data engineering team manages a data lake with AWS Lake Formation. A production Amazon Redshift cluster has been integrated with Lake Formation to run Spectrum queries. Only tables in the sales Data Catalog database that carry the LF-tag key env with value prod must be queryable from the cluster. Using the principle of least privilege, which Lake Formation configuration will satisfy the requirement?
Add the Amazon Redshift IAM role to the Lake Formation administrators group.
Grant the Amazon Redshift IAM role the SELECT permission on the sales database in Lake Formation.
Assign the LF-tag env=prod to the required tables and grant the Amazon Redshift IAM role SELECT permission on the env=prod LF-tag.
Update the S3 bucket policy to allow the Amazon Redshift IAM role GetObject access to the sales bucket.
Lake Formation evaluates permissions in the order LF-tag-based, explicit table, then database. The most granular, least-privilege solution is to tag only the required tables and grant the Amazon Redshift IAM role SELECT permission on that LF-tag. Granting permissions at the database level, making the role an LF admin, or relying solely on the S3 bucket policy would expose additional resources beyond the tagged tables. The LF-tag permission therefore meets the requirement while adhering to least privilege.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an LF-tag in AWS Lake Formation?
Open an interactive chat with Bash
What is the principle of least privilege in AWS?
Open an interactive chat with Bash
How does Amazon Redshift Spectrum integrate with AWS Lake Formation?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .