DEA-C01 Data Ingestion and Transformation Practice Question
Exhibit
Refer to the exhibit. "Effect": "Allow", "Action": [ "kinesis:DescribeStream", "kinesis:GetShardIterator", "kinesis:GetRecords", "kinesis:ListShards" ], "Resource": "arn:aws:kinesis:us-east-1:123456789012:stream/input-stream"
A data engineer is setting up an Amazon Kinesis Data Analytics application to process streaming data from a Kinesis data stream named "input-stream". The application uses a reference data source from an S3 bucket. The engineer has attached the IAM policy shown in the exhibit to the application's IAM role. When starting the application, the engineer receives an 'AccessDeniedException' error. Which additional permission is required?
⚠ Common exam trap
Many candidates confuse the direction of data flow and assume the application needs write permissions (PutRecord/PutRecords) to the input stream, when in fact it only needs read permissions (kinesis:DescribeStream, kinesis:GetShardIterator, kinesis:GetRecords) and the missing permission is for the separate S3 reference data source.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3:GetObject on the S3 bucket containing the reference data
The Kinesis Data Analytics application needs to read reference data from the S3 bucket, which requires the s3:GetObject permission on the bucket and its objects. The error 'AccessDeniedException' indicates the IAM role lacks this specific permission to retrieve the reference data file. Option B correctly adds the missing s3:GetObject action to allow the application to fetch the reference data from S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kinesis:PutRecord on the input stream
Why it's wrong here
PutRecord writes into a Kinesis stream; the application reads from input-stream, so write permission grants nothing toward the AccessDeniedException. It is tempting because the policy may already contain read actions, and PutRecord is correct when the application itself produces records into a downstream stream rather than consuming one.
- ✓
s3:GetObject on the S3 bucket containing the reference data
Why this is correct
Reading reference data from S3 requires object-level read access, which the attached policy omits. Granting s3:GetObject on the bucket holding the reference data supplies the missing action, resolving the AccessDeniedException thrown when Kinesis Data Analytics loads the reference source at application start.
- ✗
kinesis:CreateStream on the input stream
Why it's wrong here
CreateStream provisions a new Kinesis data stream, which the application never does; input-stream already exists. It is tempting because the error names the stream, suggesting a stream-level permission is missing, but CreateStream is correct only when the application must create its own stream at startup.
- ✗
kinesis:PutRecords on the input stream
Why it's wrong here
PutRecords is the batch write API for Kinesis, so it authorises producing records, not consuming them from input-stream. It is tempting because it is a Kinesis action tied to the named stream, and it would be correct when the application writes batches of output records to a downstream stream.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.