Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring an AWS Lake Formation permissions model for a data lake in Amazon S3. Analysts must query a table through Amazon Athena and see only rows where the 'region' column equals 'EU'. The engineer has already registered the S3 location with Lake Formation and created the table in the AWS Glue Data Catalog. Which action should the engineer take to enforce the row-level restriction?

⚠ Common exam trap

The trap here is assuming that IAM policies or S3 bucket policies can enforce row-level filtering, when only Lake Formation data filters operate at that granularity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Lake Formation data filter that includes the expression region='EU' and grant SELECT on the table with that data filter to the analysts' IAM role.

Lake Formation data filters are the correct mechanism for row-level security. By creating a data filter with the expression region='EU' and granting SELECT with that filter, the analyst's queries through Athena automatically receive the filter condition. This enforcement happens at the Lake Formation permission layer, so it applies consistently regardless of how the query is written, and the underlying data remains unchanged.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM policy that allows Athena StartQueryExecution only when the query string contains region='EU'.

    Why it's wrong here

    IAM policies for Athena cannot inspect the SQL query text to enforce row-level filtering. Even if they could, analysts could craft queries that bypass the condition or use aliases. This approach is brittle, not enforceable at the data layer, and does not satisfy the requirement for consistent row-level security across all queries.

  • ✗

    Create an S3 bucket policy that denies GetObject for objects whose keys do not start with 'EU/'.

    Why it's wrong here

    The data is stored in Parquet files that may contain multiple regions per object, so S3 object-key conditions cannot filter individual rows. S3 policies operate at the object level, not the row level, and cannot enforce a condition on a column value. This option would either block all access or allow all rows, failing the requirement.

  • ✓

    Create a Lake Formation data filter that includes the expression region='EU' and grant SELECT on the table with that data filter to the analysts' IAM role.

    Why this is correct

    Lake Formation data filters allow row-level and cell-level security by attaching a filter expression to a table resource. When you grant SELECT with a data filter, Athena queries automatically include the filter condition, so analysts only see rows where region equals 'EU'. This is the native Lake Formation mechanism for row-level access control without modifying the underlying data.

  • ✗

    Create a separate Athena workgroup for the analysts and configure the workgroup to append a WHERE clause to every query.

    Why it's wrong here

    Athena workgroups control query settings such as output location and encryption, but they cannot automatically inject or enforce WHERE clauses on queries. Users can still run queries that ignore any suggested filter. This approach does not provide a security boundary and would not prevent analysts from viewing rows outside the EU region.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.