DEA-C01 Data Operations and Support Practice Question
A data engineer is setting up a data pipeline using Amazon Kinesis Data Firehose to deliver data to Amazon S3. The data must be transformed using an AWS Lambda function before delivery. Which THREE steps are required to configure this?
⚠ Common exam trap
DEA-C01 often tests the misconception that S3 event notifications are needed to trigger Lambda for Firehose transformation, but Firehose directly invokes Lambda; candidates must remember the direct integration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an AWS Lambda function that transforms the data.
Option B is correct because Firehose data transformation requires an AWS Lambda function (a standard regional Lambda function, not Lambda@Edge) that receives batches of records and returns transformed records in the expected Firehose format. Option C is correct because the Firehose delivery stream assumes an IAM role, and that role must include lambda:InvokeFunction permission on the transformation function so Firehose can call it. Option E is correct because you must enable and select the Lambda function in the Firehose delivery stream's processing configuration (the Lambda transformation processor) so records are transformed before being written to Amazon S3. Option A is wrong because Lambda@Edge runs at CloudFront edge locations for viewer/origin request and response events, not for Firehose record transformation. Option D is wrong because S3 event notifications trigger actions after objects land in S3; Firehose invokes the transformation Lambda itself, so no S3 event notification is needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Lambda@Edge function in the same Region.
Why it's wrong here
Lambda@Edge runs only at CloudFront edge locations for viewer and origin request/response manipulation, and cannot serve as a Firehose transformation function. It is tempting because Lambda@Edge is a Lambda variant, but it would be correct for customising content delivery at CloudFront edge locations, not processing streaming records.
- ✓
Create an AWS Lambda function that transforms the data.
Why this is correct
Firehose requires a Lambda function to perform record transformation; the function must exist and be selected in the delivery stream's processing configuration. Creating it is therefore a mandatory step before Firehose can invoke it on incoming records.
- ✓
Attach an IAM role to the Firehose delivery stream that grants permission to invoke the Lambda function.
Why this is correct
Firehose assumes an IAM role to call Lambda on your behalf, so the delivery stream's role must carry lambda:InvokeFunction permission for the transformation function. Without this trust and permission grant, the required Lambda-based transformation cannot execute, and records would be delivered untransformed.
- ✗
Configure an S3 event notification to trigger the Lambda function when new data arrives.
Why it's wrong here
S3 event notifications fire on object creation in a bucket, but Firehose invokes the Lambda transformation itself before delivery, so no S3 event trigger is involved. S3 event notifications would be correct for triggering processing after objects land, such as post-delivery validation or downstream workflows.
- ✓
Configure the Kinesis Data Firehose delivery stream to use the Lambda function as a data transformation source.
Why this is correct
Firehose only invokes Lambda when the delivery stream's configuration explicitly names the function as its transformation processor. This satisfies the stem's requirement that data be transformed before S3 delivery, enabling Firehose to buffer, invoke, and write the processed records.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.