DEA-C01 Data Security and Governance Practice Question
A company stores raw customer records in an Amazon S3 bucket and processes them with AWS Glue. A governance requirement states that a specific tag named DataClass must exist on every catalog table, and any table missing that tag must not be queryable. Where should the data engineer enforce this requirement with the least operational effort?
⚠ Common exam trap
The trap here is assuming IAM can evaluate Glue Data Catalog tags in a policy condition, when tag-based enforcement belongs to Lake Formation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Lake Formation tag-based access control by defining an LF-Tag and granting table permissions only when the DataClass tag value matches.
Lake Formation tag-based access control centralizes permission decisions on tags instead of individual tables. Defining an LF-Tag named DataClass and granting access only for matching tag values means any table lacking the required tag value has no applicable grant and is therefore not queryable, satisfying the governance rule with minimal administrative effort.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS CloudTrail data events on the S3 bucket and alert when untagged tables are queried.
Why it's wrong here
CloudTrail data events record S3 object-level API activity and provide audit evidence, not enforcement. Alerting after a query has already run does not prevent access to untagged tables, so it fails the requirement to block queries on tables missing the tag.
- ✗
Write an AWS Lambda function that scans the Data Catalog hourly and deletes any table missing the DataClass tag.
Why it's wrong here
Deleting catalog tables removes metadata and breaks downstream jobs; it is destructive and does not reflect the requirement that tables simply not be queryable. A scheduled scan also introduces a window during which untagged tables remain accessible, so it is not immediate or low effort.
- ✗
Attach an IAM policy to all analyst roles that denies glue:GetTable unless the table has the DataClass tag.
Why it's wrong here
IAM policies cannot evaluate AWS Glue Data Catalog tags in a condition on glue:GetTable, because those tags are not IAM condition keys. The policy would either deny everything or have no effect on tag evaluation, so it cannot enforce the requirement as described.
- ✓
Use AWS Lake Formation tag-based access control by defining an LF-Tag and granting table permissions only when the DataClass tag value matches.
Why this is correct
Lake Formation tag-based access control lets an LF-Tag named DataClass be attached to catalog resources, and permissions are granted based on tag values rather than per-table grants. Tables without the required tag value receive no matching grant, so they are not queryable, which enforces the rule centrally with minimal ongoing effort.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.