DEA-C01 Data Security and Governance Practice Question
A data engineer is building an AWS Glue job that reads from a JDBC source and must retrieve the database password at runtime without hardcoding it in the script or job parameters in plaintext. The company already stores the password in AWS Secrets Manager. Which action should the engineer take?
⚠ Common exam trap
The trap here is assuming encrypted job parameters are safe, when the real goal is to keep credentials out of the job definition entirely via a secrets store.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the Glue job role secretsmanager:GetSecretValue on the secret ARN and retrieve the secret in the job using the Glue Secrets Manager connection property.
AWS Glue connections support a secretId property that fetches credentials from Secrets Manager at runtime. Granting the job role GetSecretValue on the specific secret keeps access narrow and avoids plaintext credentials in scripts or parameters, while also enabling rotation and audit through Secrets Manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant the Glue job role secretsmanager:GetSecretValue on the secret ARN and retrieve the secret in the job using the Glue Secrets Manager connection property.
Why this is correct
AWS Glue integrates with Secrets Manager through the connection's secretId property, letting the job fetch credentials at runtime. Granting secretsmanager:GetSecretValue scoped to the specific secret ARN provides least-privilege access. This avoids embedding plaintext credentials in scripts or job parameters while giving the job the password it needs.
- ✗
Embed the password directly in the Glue ETL script and restrict access to the script in Amazon S3.
Why it's wrong here
Embedding credentials in the script means the password is stored alongside code and exposed to anyone who can read the script or its version history. Restricting S3 access reduces but does not eliminate the risk, and rotation becomes a code change. Secrets Manager integration keeps credentials out of the script entirely.
- ✗
Use an IAM database authentication token for the JDBC connection instead of a password.
Why it's wrong here
IAM database authentication works for supported engines such as Amazon RDS for MySQL and PostgreSQL, but it requires the engine and driver to support token-based auth and does not apply to arbitrary JDBC sources. The scenario states the password is already in Secrets Manager, so retrieving that secret is the appropriate, supported approach.
- ✗
Store the password in an AWS Glue job parameter and mark it as encrypted using a KMS key.
Why it's wrong here
Job parameters are visible in the job definition and API responses, and encryption of the parameter does not prevent users with glue:GetJob access from seeing configuration details. It also does not provide rotation or centralized auditing the way Secrets Manager does. The requirement is to avoid plaintext exposure, which a dedicated secret store handles better.
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.