DEA-C01 Cross-account S3 access Practice Question
A company uses AWS Glue for ETL jobs. The data engineer needs to ensure that the Glue job can access an S3 bucket in another account. What is the recommended approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an IAM role to the Glue job with permissions to access the bucket, and configure the bucket policy to allow the role
For a Glue job in one account to access an S3 bucket in another account, the standard approach is to grant the Glue job's IAM role permissions to perform S3 actions on the bucket and configure the bucket policy in the target account to allow that role's ARN. Option A is technically possible if the target account's role trusts the Glue job's account and the job has sts:AssumeRole permissions, but this adds unnecessary complexity and is not the recommended method. Option C is incorrect because Glue jobs do not have resource-based policies. Option D is incorrect because Glue jobs cannot use static access keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM role in the target account and have the Glue job assume that role
Why it's wrong here
It is possible for a Glue job to assume an IAM role in another account using sts:AssumeRole, but this is not the recommended approach for cross-account S3 access. The standard pattern is to use a bucket policy in the target account that grants access to the Glue job's IAM role. Option A adds complexity and requires additional trust configuration.
- ✓
Assign an IAM role to the Glue job with permissions to access the bucket, and configure the bucket policy to allow the role
Why this is correct
Correct. To allow a Glue job in one account to access an S3 bucket in another account, the Glue job's IAM role must have the necessary S3 permissions, and the bucket policy in the target account must explicitly grant those permissions to the role's ARN. This is the recommended cross-account access pattern.
- ✗
Configure the S3 bucket policy to allow the Glue job's IAM role and also set the Glue job's resource-based policy
Why it's wrong here
Incorrect. AWS Glue jobs do not have resource-based policies (like Lambda does). They rely solely on IAM roles for permissions. Therefore, setting a resource-based policy on the Glue job is not possible.
- ✗
Store AWS access keys for the target account in AWS Secrets Manager and have the Glue job retrieve them
Why it's wrong here
Incorrect. AWS Glue jobs cannot use static AWS access keys from Secrets Manager. They authenticate using an IAM role assigned to the job. Storing access keys is not a supported or secure method for Glue to access AWS resources.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,711 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.