DEA-C01 Data Store Management Practice Question
A data engineer is designing a data lake on Amazon S3 using AWS Lake Formation. The engineer needs to grant fine-grained access to specific columns and rows of a table to different analysts. Which two actions should the engineer take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that broad IAM policies or S3 Block Public Access can provide fine-grained access, when Lake Formation requires explicit registration and data filters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a Lake Formation data filter that specifies column and row expressions.
To enforce column- and row-level security with Lake Formation, the engineer must first register the S3 location so Lake Formation can manage the data. Then, data filters can be created to define which columns and rows are accessible. These two steps together enable fine-grained permissions, while other options do not provide the required access controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define a Lake Formation data filter that specifies column and row expressions.
Why this is correct
Data filters in Lake Formation allow you to define column-level and row-level access controls. You can grant permissions on a filtered view of the table, restricting which columns and rows an analyst can see. This directly meets the requirement for fine-grained access.
- ✗
Use AWS Glue crawlers to update the Data Catalog with new partitions.
Why it's wrong here
Glue crawlers update metadata in the Data Catalog but do not enforce access controls. They are useful for discovering new data and partitions, but they do not grant or restrict access to columns or rows. This action is unrelated to fine-grained security.
- ✓
Register the S3 data location with Lake Formation.
Why this is correct
Registering the S3 location with Lake Formation enables Lake Formation to manage access to the underlying data. Without registration, Lake Formation cannot enforce fine-grained permissions on the data. This is a prerequisite for applying column- and row-level security through Lake Formation.
- ✗
Enable S3 Block Public Access on the bucket.
Why it's wrong here
S3 Block Public Access prevents accidental public exposure of objects, but it does not provide fine-grained access control for specific users. It is a security best practice but does not grant column- or row-level permissions. This action alone does not meet the requirement.
- ✗
Create an IAM policy that allows s3:GetObject on the entire bucket.
Why it's wrong here
An IAM policy granting s3:GetObject on the entire bucket would allow access to all objects, bypassing any fine-grained controls. Lake Formation permissions are enforced in addition to IAM, but broad S3 permissions could still expose data if not properly restricted. This does not provide column- or row-level security.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.