AWS Certified Data Engineer Associate DEA-C01 Practice Question
Your team runs an AWS Glue Spark job that copies data from an ingest bucket to a curated bucket in the same account. According to the principle of least privilege, you must update the job's IAM role so it can read from the ingest bucket and write only to the curated bucket-nothing else. Which approach best meets the requirement?
Create a customer managed policy that allows s3:GetObject on the ingest bucket and s3:PutObject on the curated bucket, then attach it to the Glue role.
Add an inline policy to the IAM user who owns the Glue job granting s3:* on all buckets, then have the job assume that user.
Attach the AWS managed policy AmazonS3FullAccess to the Glue role to allow unrestricted access to S3.
Attach the AWS managed policy AmazonS3ReadOnlyAccess to the Glue role and rely on bucket ACLs to enable writes.
Creating a narrowly-scoped customer managed policy and attaching it to the Glue service role follows least-privilege guidance. The policy grants exactly the two actions the job performs-s3:GetObject on the ingest bucket and s3:PutObject on the curated bucket-so the role cannot list, delete, or access any other buckets. AmazonS3FullAccess permits s3:* on all buckets, far exceeding what is needed. AmazonS3ReadOnlyAccess blocks writes entirely and still grants read access to every bucket. Granting s3:* to an IAM user and having the job assume that user both violates least privilege and ignores the recommended practice of using a dedicated service role for Glue.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the principle of least privilege in AWS?
Open an interactive chat with Bash
What is a customer managed policy in AWS?
Open an interactive chat with Bash
Why is using an inline policy for an IAM user not recommended for AWS Glue roles?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .