Courseiva

DEA-C01 Data Security and Governance Practice Question

A company stores raw customer records in an Amazon S3 bucket and processes them with AWS Glue. A governance requirement states that a specific tag named DataClass must exist on every catalog table, and any table missing that tag must not be queryable. Where should the data engineer enforce this requirement with the least operational effort?

⚠ Common exam trap

The trap here is assuming IAM can evaluate Glue Data Catalog tags in a policy condition, when tag-based enforcement belongs to Lake Formation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Lake Formation tag-based access control by defining an LF-Tag and granting table permissions only when the DataClass tag value matches.

Lake Formation tag-based access control centralizes permission decisions on tags instead of individual tables. Defining an LF-Tag named DataClass and granting access only for matching tag values means any table lacking the required tag value has no applicable grant and is therefore not queryable, satisfying the governance rule with minimal administrative effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS CloudTrail data events on the S3 bucket and alert when untagged tables are queried.

    Why it's wrong here

    CloudTrail data events record S3 object-level API activity and provide audit evidence, not enforcement. Alerting after a query has already run does not prevent access to untagged tables, so it fails the requirement to block queries on tables missing the tag.

  • ✗

    Write an AWS Lambda function that scans the Data Catalog hourly and deletes any table missing the DataClass tag.

    Why it's wrong here

    Deleting catalog tables removes metadata and breaks downstream jobs; it is destructive and does not reflect the requirement that tables simply not be queryable. A scheduled scan also introduces a window during which untagged tables remain accessible, so it is not immediate or low effort.

  • ✗

    Attach an IAM policy to all analyst roles that denies glue:GetTable unless the table has the DataClass tag.

    Why it's wrong here

    IAM policies cannot evaluate AWS Glue Data Catalog tags in a condition on glue:GetTable, because those tags are not IAM condition keys. The policy would either deny everything or have no effect on tag evaluation, so it cannot enforce the requirement as described.

  • ✓

    Use AWS Lake Formation tag-based access control by defining an LF-Tag and granting table permissions only when the DataClass tag value matches.

    Why this is correct

    Lake Formation tag-based access control lets an LF-Tag named DataClass be attached to catalog resources, and permissions are granted based on tag values rather than per-table grants. Tables without the required tag value receive no matching grant, so they are not queryable, which enforces the rule centrally with minimal ongoing effort.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.