DEA-C01 Data Operations and Support Practice Question
A data engineer is troubleshooting an AWS Glue ETL job that fails with the error: 'An error occurred while calling o123.pyWriteDynamicFrame. Access Denied when writing to S3 bucket: my-bucket'. The job uses a Glue service role named 'GlueServiceRole'. Which TWO actions should the engineer take to resolve the issue? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often confuse S3 access errors with network or VPC issues, but S3 is a global service and access is governed by IAM and bucket policies, not VPC placement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check if the S3 bucket policy denies access from the GlueServiceRole.
The error 'Access Denied when writing to S3 bucket' during pyWriteDynamicFrame indicates an S3 authorization failure for the Glue job's execution role, so option D is correct: the engineer must verify that the IAM policy attached to GlueServiceRole includes s3:PutObject (and typically s3:PutObjectAcl) on the target bucket/prefix, since Glue writes output objects to S3 using that role. Option C is also correct because an explicit Deny in the S3 bucket policy overrides any Allow in the IAM policy, so the engineer must check whether the bucket policy denies access from GlueServiceRole. Option A is wrong because disabling S3 Block Public Access is unrelated to a role-based write failure and would weaken security without fixing the permission issue. Option B is wrong because the failure is writing to S3, not to the Glue Data Catalog, so Data Catalog permissions would not resolve the S3 Access Denied error. Option E is wrong because S3 is accessed via AWS public service endpoints and does not require the Glue job to be in the same VPC as the bucket; VPC placement only matters for private endpoint configurations, not for this authorization error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable S3 Block Public Access on the bucket.
Why it's wrong here
Disabling S3 Block Public Access does not grant the Glue service role permission to write; the Access Denied originates from the role's missing s3:PutObject in its IAM policy, not bucket-level public access settings. Block Public Access is intended to prevent accidental public exposure of buckets, so it would be the right control to keep enabled, not disable.
- ✗
Grant the GlueServiceRole permission to write to the AWS Glue Data Catalog.
Why it's wrong here
The failure occurs at pyWriteDynamicFrame writing to S3, so the missing permission is s3:PutObject on my-bucket, not Data Catalog access. Catalog permissions govern metadata operations such as creating or updating tables and partitions; granting them here leaves the S3 write denial unchanged.
- ✓
Check if the S3 bucket policy denies access from the GlueServiceRole.
Why this is correct
An explicit Deny in the bucket policy overrides any Allow in the identity policy, producing Access Denied on s3:PutObject. Inspecting the bucket policy for a deny targeting GlueServiceRole identifies that blocking statement, satisfying the need to find the actual cause.
- ✓
Verify that the IAM policy attached to GlueServiceRole includes s3:PutObject on the bucket.
Why this is correct
The Glue job writes via its service role, so the identity policy must grant s3:PutObject on the target bucket prefix. Verifying that permission exists confirms the role can perform the write, satisfying the requirement to check the identity-based grant.
- ✗
Ensure the Glue job is in the same VPC as the S3 bucket.
Why it's wrong here
S3 access is governed by IAM policies and bucket policies, not network placement; Glue reaches S3 over its public endpoint regardless of VPC. Co-locating in a VPC matters when connecting to resources such as RDS or Redshift inside that VPC, which is not this scenario.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.