Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is managing an AWS Glue Data Catalog that contains metadata for tables in Amazon S3. The security team requires that access to the Data Catalog be restricted based on the user's department, and that users can only see tables that belong to their department. The Data Catalog tables are tagged with a 'Department' key. Which AWS feature should the engineer use to enforce this requirement?

⚠ Common exam trap

The trap here is assuming that IAM policies alone can enforce tag-based access to Glue Data Catalog tables, when Lake Formation is required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Lake Formation tag-based access control (LF-TBAC) with tags on Data Catalog resources and matching IAM principals.

AWS Lake Formation tag-based access control (LF-TBAC) allows you to define permissions using tags on Data Catalog resources and IAM principals. This enables attribute-based access control, so users can only access tables with matching tags. This is the recommended way to implement fine-grained, scalable access control for the Glue Data Catalog. Other options either do not support tag-based filtering for the catalog or address the wrong resource.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon S3 bucket policies that restrict access to objects based on the 'Department' tag on the S3 objects.

    Why it's wrong here

    S3 bucket policies control access to S3 objects, not Data Catalog metadata. The requirement is to restrict access to the Data Catalog tables, not the underlying data. While S3 policies can use tags, they do not govern Glue Data Catalog permissions. Lake Formation provides the necessary layer for catalog access control.

  • ✓

    AWS Lake Formation tag-based access control (LF-TBAC) with tags on Data Catalog resources and matching IAM principals.

    Why this is correct

    AWS Lake Formation supports tag-based access control, which allows you to define permissions based on tags attached to Data Catalog resources and IAM principals. By tagging tables with a Department key and assigning matching tags to users, you can grant or deny access dynamically. This meets the requirement for department-based access without managing individual table permissions.

  • ✗

    AWS Glue resource policies that allow or deny access based on the 'Department' tag.

    Why it's wrong here

    AWS Glue resource policies are used for cross-account access and are attached to catalogs, databases, or tables. They do not support tag-based conditions for filtering tables by department. Resource policies are coarse-grained and cannot dynamically match user attributes to tags. Lake Formation is the correct service for this use case.

  • ✗

    IAM policies with condition keys that match the 'Department' tag on the Data Catalog tables.

    Why it's wrong here

    IAM policies can use condition keys, but the AWS Glue Data Catalog does not support resource tags in IAM policy conditions for fine-grained access to tables. IAM alone cannot filter tables based on tags; Lake Formation is required for table-level and tag-based permissions. This approach would not enforce the department restriction.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.