DEA-C01 Data Operations and Support Practice Question
A data engineer is troubleshooting a failed AWS Glue ETL job that reads from an S3 bucket and writes to an Amazon Redshift table. The job fails with a permission error. Which IAM policy addition is MOST likely required for the Glue job's role?
⚠ Common exam trap
DEA-C01 often tests the confusion between the Redshift JDBC connection path (which needs redshift:GetClusterCredentials) and the Redshift Data API path (which needs redshift-data:* actions), so candidates pick DataAPI permissions for a JDBC-based Glue job.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add redshift:GetClusterCredentials
AWS Glue jobs that write to Amazon Redshift using the native Redshift connection (not the Redshift Data API) authenticate by calling redshift:GetClusterCredentials to obtain temporary database credentials for the job role. Without that permission, the Glue connection cannot obtain a username/password and the job fails with an access-denied error even though the S3 read side works.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add redshift:DataAPI
Why it's wrong here
redshift:DataAPI is not a valid IAM action; the Redshift Data API is invoked through redshift-data actions such as ExecuteStatement, which authorise SQL execution. It is tempting because the Data API does run SQL, but it would be the correct choice when calling ExecuteStatement against a cluster.
- ✗
Add redshift:ModifyCluster
Why it's wrong here
redshift:ModifyCluster changes cluster configuration such as node type or maintenance settings; it does not authorise writing rows into a table. It is tempting because it is a Redshift action, but it would be the correct choice when resizing or reconfiguring the cluster itself, not for ETL writes.
- ✗
Add redshift:DescribeStatement
Why it's wrong here
redshift:DescribeStatement returns metadata about a previously submitted SQL statement; it grants no write access to the Redshift table, so the permission error persists. It is tempting because it sounds like a data-movement permission, but it is the correct choice when polling the status of an asynchronous statement.
- ✓
Add redshift:GetClusterCredentials
Why this is correct
When Glue writes to Redshift using the Redshift JDBC connector with IAM authentication, the job role must call redshift:GetClusterCredentials to obtain temporary database credentials. Without it, the connection fails with a permission error before any data is written.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.