DEA-C01 Data Security and Governance Practice Question
A company has a multi-account AWS environment with a centralized data lake in the Security account. Data producers in other accounts use AWS Glue to write data to S3 buckets in the Security account. The Security account uses AWS Lake Formation to manage permissions. The data engineer is setting up cross-account access so that users in the Producer account can query the data using Athena in their own account. The engineer has registered the S3 buckets and Data Catalog tables in Lake Formation. The IAM roles in the Producer account have the necessary permissions. However, when a user in the Producer account tries to query the table, they get an AccessDenied error. The error message indicates that the principal is not authorized to perform lakeformation:GetTable on the resource. What is the most likely cause?
⚠ Common exam trap
DEA-C01 often tests the misconception that IAM policies alone are sufficient for cross-account Lake Formation access, when in fact Lake Formation requires an explicit grant to the external principal, and the error message's mention of lakeformation:GetTable is the key clue that distinguishes it from S3 or KMS issues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lake Formation permissions in the Security account do not include a grant to the Producer account's IAM role.
The error explicitly states the principal is not authorized to perform lakeformation:GetTable, which is a Lake Formation permission check, not an S3, KMS, or Glue resource policy check. In Lake Formation cross-account access, the data owner (Security account) must grant table and data location permissions directly to the external IAM principal (the Producer account's role) using the Lake Formation GrantPermissions API or console. Without this explicit grant, Lake Formation denies the GetTable call before any S3 or KMS access is even attempted. Since the IAM roles already have the necessary permissions, the missing piece is the Lake Formation grant in the Security account.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Glue Data Catalog resource policy is missing a statement to allow cross-account access.
Why it's wrong here
The Glue Data Catalog resource policy controls direct Data Catalog API access; Lake Formation-governed tables enforce permissions through Lake Formation grants instead, and the error explicitly names lakeformation:GetTable. A Data Catalog resource policy is correct when Glue or Athena accesses catalog objects outside Lake Formation governance.
- ✗
The S3 bucket policy does not allow the Producer account's IAM role to read the data.
Why it's wrong here
The error names lakeformation:GetTable, so the failure sits in Lake Formation permission grants, not S3 object reads; bucket policies govern data access, which is never reached. S3 bucket policies would be the right control when Athena reads objects directly without Lake Formation governance, or for granting raw object-level access.
- ✗
The KMS key policy does not allow the Producer account's IAM role to decrypt objects.
Why it's wrong here
KMS decryption failures surface as KMS AccessDenied on objects during reads, not as lakeformation:GetTable denial before query planning. A KMS key policy is the right fix when the principal already holds Lake Formation and S3 permissions but encrypted objects cannot be decrypted.
- ✓
The Lake Formation permissions in the Security account do not include a grant to the Producer account's IAM role.
Why this is correct
Cross-account Lake Formation access requires two grants: the resource owner grants permissions to the external principal, and the recipient account grants its role access. The Security account never granted the Producer role, so lakeformation:GetTable fails despite correct IAM permissions.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.