AWS Certified Data Engineer Associate DEA-C01 Practice Question
An ecommerce company stores hundreds of Parquet datasets in Amazon S3. The analytics team catalogs the data in AWS Glue. They must indicate for each table and column whether the data is public, internal only, or contains customer PII, and they must enforce different Athena permissions based on these classifications. Which solution requires the least ongoing administration?
Maintain separate AWS Glue databases for Public, Internal, and PII data and restrict Athena users to the corresponding database.
Configure custom classifiers in AWS Glue crawlers to label tables and use Glue column-level IAM policies to restrict Athena access.
Create Lake Formation LF-tags for each sensitivity level, attach them to the relevant tables and columns, and grant tag-based permissions to the appropriate IAM principals.
Enable Amazon Macie on the S3 buckets and use Macie findings to automatically block unauthorized Athena queries against sensitive data.
Lake Formation LF-tags let administrators assign business-defined classifications (for example, Public, Internal, PII) to databases, tables, and even individual columns in the AWS Glue Data Catalog. Tag-based access control policies can then be granted to roles or users, and Athena automatically honors those permissions. Custom Glue classifiers only identify file formats, separate catalogs add operational overhead, and Amazon Macie does not provide fine-grained permission enforcement for Athena queries.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Lake Formation LF-tags?
Open an interactive chat with Bash
How does tag-based access control work in Lake Formation?
Open an interactive chat with Bash
Why is using LF-tags more efficient than separate Glue databases or Macie?
Open an interactive chat with Bash
What are Lake Formation LF-tags?
Open an interactive chat with Bash
How does tag-based access control (TBAC) work in AWS Lake Formation?
Open an interactive chat with Bash
Why are custom Glue classifiers or Macie unsuitable for this scenario?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Store Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .