DEA-C01 Data Security and Governance Practice Question
A data engineer is building an AWS Lake Formation governed data lake. The security team wants to grant a group of analysts access to only the non-sensitive columns of a table in the Data Catalog, while denying access to columns containing Social Security numbers. The analysts use Amazon Athena to query the data. Which Lake Formation permission model should the data engineer use?
⚠ Common exam trap
The trap here is thinking that table-level SELECT plus Athena behavior hides sensitive columns, when table-level access exposes every column.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant column-level SELECT permission on the non-sensitive columns and exclude the Social Security number column.
Lake Formation column-level permissions let you grant SELECT on a subset of columns in a Data Catalog table. Analysts can then query the permitted columns through Athena, and any attempt to select the Social Security number column is denied. Duplicating tables or using broad IAM denies does not achieve the same precise, least-privilege control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant table-level SELECT permission to the analysts and rely on Athena to hide the sensitive columns.
Why it's wrong here
Table-level SELECT grants access to all columns in the table, including the sensitive ones. Athena does not automatically hide columns unless Lake Formation column-level permissions are configured. This approach would expose Social Security numbers to the analysts, violating the security team's requirement to restrict access to non-sensitive columns only.
- ✗
Use an IAM policy that denies athena:GetQueryResults for queries that reference the sensitive column.
Why it's wrong here
IAM policies operate at the API action level and cannot inspect which columns a SQL query references. Denying athena:GetQueryResults would block all query results, not just those involving the sensitive column. This approach cannot selectively restrict column access and would break the analysts' ability to use Athena for any query.
- ✗
Create a separate Data Catalog table that contains only non-sensitive columns and grant access to that table.
Why it's wrong here
Creating a duplicate table with only non-sensitive columns would require an ETL process to keep it in sync and adds storage and maintenance overhead. While it restricts access, it is not the least-privilege permission model that Lake Formation provides natively. The security team asked for column-level access control, not data duplication, so this approach is unnecessarily complex.
- ✓
Grant column-level SELECT permission on the non-sensitive columns and exclude the Social Security number column.
Why this is correct
Lake Formation supports column-level permissions, allowing you to grant SELECT on specific columns of a table. By granting only the non-sensitive columns, the analysts can query those columns in Athena while the Social Security number column remains inaccessible. This directly implements the least-privilege requirement without duplicating data.
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.