DEA-C01 Data Security and Governance Practice Question
A data engineer is configuring an AWS Lake Formation permissions model for a data lake in Amazon S3. Analysts must query a table through Amazon Athena and see only rows where the 'region' column equals 'EU'. The engineer has already registered the S3 location with Lake Formation and created the table in the AWS Glue Data Catalog. Which action should the engineer take to enforce the row-level restriction?
⚠ Common exam trap
The trap here is assuming that IAM policies or S3 bucket policies can enforce row-level filtering, when only Lake Formation data filters operate at that granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Lake Formation data filter that includes the expression region='EU' and grant SELECT on the table with that data filter to the analysts' IAM role.
Lake Formation data filters are the correct mechanism for row-level security. By creating a data filter with the expression region='EU' and granting SELECT with that filter, the analyst's queries through Athena automatically receive the filter condition. This enforcement happens at the Lake Formation permission layer, so it applies consistently regardless of how the query is written, and the underlying data remains unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM policy that allows Athena StartQueryExecution only when the query string contains region='EU'.
Why it's wrong here
IAM policies for Athena cannot inspect the SQL query text to enforce row-level filtering. Even if they could, analysts could craft queries that bypass the condition or use aliases. This approach is brittle, not enforceable at the data layer, and does not satisfy the requirement for consistent row-level security across all queries.
- ✗
Create an S3 bucket policy that denies GetObject for objects whose keys do not start with 'EU/'.
Why it's wrong here
The data is stored in Parquet files that may contain multiple regions per object, so S3 object-key conditions cannot filter individual rows. S3 policies operate at the object level, not the row level, and cannot enforce a condition on a column value. This option would either block all access or allow all rows, failing the requirement.
- ✓
Create a Lake Formation data filter that includes the expression region='EU' and grant SELECT on the table with that data filter to the analysts' IAM role.
Why this is correct
Lake Formation data filters allow row-level and cell-level security by attaching a filter expression to a table resource. When you grant SELECT with a data filter, Athena queries automatically include the filter condition, so analysts only see rows where region equals 'EU'. This is the native Lake Formation mechanism for row-level access control without modifying the underlying data.
- ✗
Create a separate Athena workgroup for the analysts and configure the workgroup to append a WHERE clause to every query.
Why it's wrong here
Athena workgroups control query settings such as output location and encryption, but they cannot automatically inject or enforce WHERE clauses on queries. Users can still run queries that ignore any suggested filter. This approach does not provide a security boundary and would not prevent analysts from viewing rows outside the EU region.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.