DEA-C01 Data Security and Governance Practice Question
A company uses AWS Lake Formation to manage access to a data lake in Amazon S3. A data engineer needs to grant a specific IAM role access to only the columns containing non-sensitive data in a table, while hiding columns with personally identifiable information (PII). The engineer has already registered the S3 bucket and the table in Lake Formation. What should the engineer do to meet this requirement?
⚠ Common exam trap
Test-takers frequently confuse S3 object-level permissions with column-level permissions, which are enforced by Lake Formation data filters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Lake Formation data filter that excludes the PII columns and grant SELECT permission on the filtered table to the IAM role.
Lake Formation data filters enable column-level security by allowing you to exclude specific columns from a table. When you grant SELECT permission on a filtered table, the user can only access the included columns. This meets the requirement of hiding PII columns while providing access to non-sensitive data, without duplicating data or altering S3 objects.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Lake Formation data filter that excludes the PII columns and grant SELECT permission on the filtered table to the IAM role.
Why this is correct
Lake Formation data filters allow column-level and row-level access control. By creating a data filter that excludes PII columns, the engineer can grant SELECT permission on that filtered view to the IAM role. This ensures the role can query only the non-sensitive columns. This is the correct approach because Lake Formation enforces these permissions at the table level without modifying the underlying data.
- ✗
Attach a bucket policy to the S3 bucket that allows the IAM role to read only specific objects.
Why it's wrong here
A bucket policy controls access to S3 objects, not to columns within those objects. Since the PII and non-PII columns reside in the same S3 object (e.g., a Parquet file), a bucket policy cannot differentiate between them. This approach would either grant access to the entire object or deny it completely, failing to hide only the PII columns as required.
- ✗
Use an IAM policy that denies access to the S3 prefixes containing the PII columns.
Why it's wrong here
S3 prefixes are object-level and do not map to individual columns within a table. PII columns are part of the same S3 objects as non-PII columns when using columnar formats like Parquet. An IAM policy denying access to certain prefixes would either block all data or none, and cannot selectively hide columns. Lake Formation column-level security is the appropriate mechanism.
- ✗
Configure an AWS Glue job to create a new table that omits the PII columns and grant access to that table.
Why it's wrong here
Creating a new table without PII columns is a data duplication approach and does not provide dynamic access control. It also requires maintaining two copies of the data, which can lead to inconsistency and increased storage costs. Lake Formation data filters are designed to provide column-level security without duplicating data, making this option inefficient and not aligned with the requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.