AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your company hosts a multi-account data lake. The producer account registers s3://datalake/raw and s3://datalake/curated as data locations in AWS Lake Formation and creates Glue tables under each prefix. An analytics team in a consumer account must query only the curated datasets from Amazon Athena and must never see the raw prefix. Which approach meets the requirements using the least-privilege model?
Attach an S3 bucket policy that allows the consumer account s3:GetObject on s3://datalake/curated/** and run Athena; no Lake Formation permissions are needed.
Disable Lake Formation permissions (enable IAM allowed principals) and use IAM policies to grant the consumer role Glue and S3 read access only to the curated tables.
Make the curated prefix public read and restrict the raw prefix with object-level ACLs, relying on Athena client-side filtering to hide raw data.
Grant the consumer account SELECT permission on the curated tables and DATA_LOCATION_ACCESS on s3://datalake/curated in Lake Formation, let the consumer accept the AWS RAM share, and create a resource link before running Athena queries.
Lake Formation supports fine-grained, cross-account sharing of Data Catalog resources. By granting the consumer account SELECT on only the curated tables and DATA_LOCATION_ACCESS on the exact registered curated prefix, the producer limits both metadata and underlying S3 access. The share is delivered through AWS RAM; after the consumer accepts it and creates a resource link, Athena can read the curated data without visibility to the raw location. The other choices either bypass Lake Formation, expose public access, or grant broad S3/IAM permissions that could reveal the raw data, violating the principle of least privilege.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Lake Formation and how does it help with data access control?
Open an interactive chat with Bash
How does AWS Resource Access Manager (RAM) assist in cross-account data sharing?
Open an interactive chat with Bash
What is a resource link in AWS Lake Formation, and why is it required for Athena queries?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .