DEA-C01 Data Ingestion and Transformation Practice Question
A company uses Amazon Kinesis Data Streams to ingest clickstream data. The data must be transformed and stored in Amazon S3 for batch analytics. The engineer wants to use AWS Lambda for transformation. Which TWO configurations are required? (Choose two.)
⚠ Common exam trap
DEA-C01 often tests the required components for Lambda-Kinesis integration, and candidates may confuse optional error handling (SQS) or alternative services (Firehose) with mandatory configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an event source mapping from the Kinesis stream to the Lambda function.
Option D is correct because AWS Lambda consumes records from Kinesis Data Streams through an event source mapping, which polls the stream using the enhanced fan-out or standard iterator and invokes the function with batches of records. Option E is correct because the Lambda execution role must include IAM permissions for the required actions, such as kinesis:GetRecords, kinesis:GetShardIterator, kinesis:DescribeStream, and kinesis:ListShards to read the stream, plus s3:PutObject to store the transformed data in Amazon S3. Option A is not required because Kinesis Data Firehose is a separate delivery service; the Lambda function can write directly to S3 using the AWS SDK, and Firehose is not a mandatory intermediary. Option B is incorrect because a Kinesis data stream cannot send records directly to Amazon S3; it requires a consumer such as Lambda or Firehose. Option C is incorrect because an SQS dead-letter queue for Lambda errors is an optional reliability configuration, not a required configuration for transforming and storing the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the Lambda function to write to S3 via Kinesis Data Firehose.
Why it's wrong here
Firehose performs its own transformation via Lambda invocation, so routing Lambda output through it duplicates transformation and adds an unnecessary hop. The stem's Lambda function must write directly to S3. Firehose is the right choice when no separate transformation compute exists and buffering plus format conversion are needed.
- ✗
Configure the Kinesis stream to send records directly to S3.
Why it's wrong here
Kinesis Data Streams has no native S3 delivery mechanism; records leave only via consumers such as Lambda or Firehose. The stem requires Lambda transformation, so this bypasses the compute entirely. Direct stream-to-S3 delivery is not a configurable feature at all, making the option tempting only to those assuming Kinesis offers Firehose-style managed delivery.
- ✗
Set up an SQS queue as a destination for Lambda errors.
Why it's wrong here
An SQS dead-letter queue captures failed invocations, but the stem asks for the two configurations required to transform records and land them in S3. Error handling is optional resilience, not a prerequisite for the pipeline. It would be correct when the requirement explicitly includes capturing and reprocessing failed Lambda events.
- ✓
Create an event source mapping from the Kinesis stream to the Lambda function.
Why this is correct
An event source mapping registers the Kinesis stream as a Lambda trigger, letting the service poll shards, batch records, and invoke the function with checkpointing. Without it, Lambda cannot consume the stream for transformation before writing to S3.
- ✓
Assign an IAM role to Lambda with permissions to read from Kinesis and write to S3.
Why this is correct
Lambda needs an execution role granting kinesis:GetRecords, GetShardIterator, DescribeStream and s3:PutObject, since it assumes this role to poll the stream and deliver transformed records. Without these identity-based permissions, the Kinesis event source mapping cannot read shards and S3 writes fail, so the transformation pipeline breaks.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.