Courseiva

DEA-C01 Data Operations and Support Practice Question

A data engineer is setting up a data pipeline using Amazon Kinesis Data Firehose to deliver data to Amazon S3. The data must be transformed using an AWS Lambda function before delivery. Which THREE steps are required to configure this?

⚠ Common exam trap

DEA-C01 often tests the misconception that S3 event notifications are needed to trigger Lambda for Firehose transformation, but Firehose directly invokes Lambda; candidates must remember the direct integration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS Lambda function that transforms the data.

Option B is correct because Firehose data transformation requires an AWS Lambda function (a standard regional Lambda function, not Lambda@Edge) that receives batches of records and returns transformed records in the expected Firehose format. Option C is correct because the Firehose delivery stream assumes an IAM role, and that role must include lambda:InvokeFunction permission on the transformation function so Firehose can call it. Option E is correct because you must enable and select the Lambda function in the Firehose delivery stream's processing configuration (the Lambda transformation processor) so records are transformed before being written to Amazon S3. Option A is wrong because Lambda@Edge runs at CloudFront edge locations for viewer/origin request and response events, not for Firehose record transformation. Option D is wrong because S3 event notifications trigger actions after objects land in S3; Firehose invokes the transformation Lambda itself, so no S3 event notification is needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Lambda@Edge function in the same Region.

    Why it's wrong here

    Lambda@Edge runs only at CloudFront edge locations for viewer and origin request/response manipulation, and cannot serve as a Firehose transformation function. It is tempting because Lambda@Edge is a Lambda variant, but it would be correct for customising content delivery at CloudFront edge locations, not processing streaming records.

  • ✓

    Create an AWS Lambda function that transforms the data.

    Why this is correct

    Firehose requires a Lambda function to perform record transformation; the function must exist and be selected in the delivery stream's processing configuration. Creating it is therefore a mandatory step before Firehose can invoke it on incoming records.

  • ✓

    Attach an IAM role to the Firehose delivery stream that grants permission to invoke the Lambda function.

    Why this is correct

    Firehose assumes an IAM role to call Lambda on your behalf, so the delivery stream's role must carry lambda:InvokeFunction permission for the transformation function. Without this trust and permission grant, the required Lambda-based transformation cannot execute, and records would be delivered untransformed.

  • ✗

    Configure an S3 event notification to trigger the Lambda function when new data arrives.

    Why it's wrong here

    S3 event notifications fire on object creation in a bucket, but Firehose invokes the Lambda transformation itself before delivery, so no S3 event trigger is involved. S3 event notifications would be correct for triggering processing after objects land, such as post-delivery validation or downstream workflows.

  • ✓

    Configure the Kinesis Data Firehose delivery stream to use the Lambda function as a data transformation source.

    Why this is correct

    Firehose only invokes Lambda when the delivery stream's configuration explicitly names the function as its transformation processor. This satisfies the stem's requirement that data be transformed before S3 delivery, enabling Firehose to buffer, invoke, and write the processed records.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.