DEA-C01 Data Operations and Support Practice Question
A data engineer is troubleshooting a failed AWS Glue ETL job that reads from a JDBC source. The error log shows 'java.sql.SQLException: Connection timed out'. The job previously ran successfully. Which of the following is the MOST likely cause?
⚠ Common exam trap
AWS often tests the distinction between authentication errors (wrong credentials) and network connectivity errors (timeout), and candidates may confuse the Glue job timeout setting with a network timeout.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security group for the source database no longer allows traffic from the Glue job's IP range.
The error 'Connection timed out' indicates a network-level failure, not an authentication or schema issue. Since the job previously ran successfully, the most likely cause is that the security group for the source database no longer allows inbound traffic from the Glue job's IP range. AWS Glue ETL jobs run in a VPC with elastic network interfaces, and the security group rules must permit traffic on the JDBC port (e.g., 5432 for PostgreSQL, 3306 for MySQL).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The JDBC connection string has incorrect credentials.
Why it's wrong here
Incorrect credentials produce an authentication failure, not a connection timeout, and the job previously succeeded with the same string. Credential errors fit scenarios where the password rotated or a secret was misconfigured; here the network path to the JDBC endpoint is what stopped responding.
- ✗
The source database schema has changed.
Why it's wrong here
A schema change causes column mismatch or parse errors during read, not a TCP-level connection timeout. Schema drift is the likely cause when queries fail with missing or renamed columns; a timeout indicates the JDBC endpoint became unreachable, for example via security group or subnet change.
- ✗
The Glue job's timeout setting is too low.
Why it's wrong here
A low job timeout terminates the Glue run with a timeout status, not a java.sql.SQLException from the JDBC driver. Raising the timeout suits long-running jobs that complete but exceed the configured duration; the driver-level connection timeout points to network reachability instead.
- ✓
The security group for the source database no longer allows traffic from the Glue job's IP range.
Why this is correct
A security group rule change blocking the Glue job's ENI traffic causes the JDBC connection to time out, matching the sudden failure after prior success. Network ACLs or credentials would produce different errors, so the revoked inbound rule is the likely cause.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on DEA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A data engineer needs to troubleshoot a failed AWS Glue job that reads from an Amazon RDS for MySQL database. The error log shows 'Communications link failure'. Which step should the engineer take FIRST?
easy- A.Increase the job timeout and retry count.
- ✓ B.Check that the security group associated with the Glue job allows outbound traffic to the RDS database.
- C.Verify that the database username and password are correct in the Glue connection.
- D.Confirm that the table schema in MySQL matches the Glue Data Catalog.
Why B: 'Communications link failure' is a JDBC/MySQL error indicating the client cannot establish a TCP connection to the database — typically a network reachability problem, not authentication or schema. Since AWS Glue jobs run in an AWS-managed VPC (or a customer VPC via a connection), the first thing to verify is that the Glue job's security group permits outbound traffic to the RDS instance on port 3306. Checking network connectivity before credentials or schema is the correct troubleshooting order.
Variation 2. A data engineer notices that an AWS Glue ETL job is failing intermittently with the error 'Connection refused'. The job reads from Amazon RDS for MySQL and writes to Amazon S3. What is the MOST likely cause?
easy- A.The RDS instance has reached its maximum number of connections.
- ✓ B.The security group for the RDS instance is not allowing inbound traffic from the Glue job's subnet.
- C.The Glue job is using too many DPUs and hitting resource limits.
- D.The IAM role associated with the Glue job lacks permissions to write to the S3 bucket.
Why B: The 'Connection refused' error indicates a network connectivity issue between the AWS Glue ETL job and Amazon RDS for MySQL. The most likely cause is that the security group for the RDS instance is not configured to allow inbound traffic on the MySQL port (3306) from the subnet or security group used by the Glue job. Option A (max connections) would result in a 'too many connections' error, not 'connection refused'. Option C (DPU limits) would cause resource-related errors, not a connection refusal. Option D (IAM permissions) would lead to an access denied error when writing to S3, not a connection error. Therefore, option B is correct.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.