AWS Certified Data Engineer Associate DEA-C01 Practice Question

Your company maintains a data lake in account A registered with AWS Lake Formation. Data scientists in a separate AWS account (account B) must query two specific tables in Amazon Athena while having no visibility into other tables or objects in the bucket. The security team wants to avoid adding bucket policies or manual object-level ACLs and enforce least privilege at the table level. Which approach meets these requirements?

  • In account A, use Lake Formation Grant Permissions to share SELECT and DESCRIBE on the two tables directly with the Athena execution role ARN from account B; have account B accept the AWS RAM share and create resource links before running queries.

  • Attach an S3 bucket policy that allows the account B role s3:GetObject on the entire data-lake prefix and rely on Athena workgroup settings for query isolation.

  • Export the two tables to a new S3 location, replicate the data to a bucket in account B, and grant full access to that bucket.

  • Create an AWS Glue Data Catalog resource policy that shares the tables with account B, then let account B query them without additional Lake Formation grants.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot