DEA-C01 Data Security and Governance Practice Question
A data engineer is using AWS Lake Formation to manage access to a data lake in Amazon S3. The company wants to grant a data analyst read-only access to specific columns in a table stored in the AWS Glue Data Catalog. The analyst should not be able to see other columns or any rows that contain sensitive data. The engineer sets up Lake Formation permissions on the table, granting SELECT on specific columns. However, when the analyst queries the table using Amazon Athena, they can see all columns. What is the most likely reason?
⚠ Common exam trap
The trap here is assuming that Lake Formation permissions alone are sufficient, while ignoring that direct IAM access to S3 can bypass those permissions entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The analyst has IAM permissions that allow direct access to the S3 bucket, bypassing Lake Formation.
Lake Formation enforces fine-grained access control only when users do not have direct IAM permissions to the underlying data. If the analyst has IAM permissions to read the S3 bucket, they can bypass Lake Formation and access all columns and rows. To enforce column-level security, the analyst's IAM policy must not allow direct S3 access; all data access must be mediated through Lake Formation. The other options are either incorrect or would produce different errors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Glue Data Catalog table definition does not include the column-level metadata required for Lake Formation.
Why it's wrong here
Lake Formation uses the Glue Data Catalog to store table metadata, including column definitions. The table definition already includes all columns; Lake Formation permissions are applied on top of that metadata. The absence of special metadata is not the cause. The issue is that the analyst can bypass Lake Formation due to direct S3 access.
- ✓
The analyst has IAM permissions that allow direct access to the S3 bucket, bypassing Lake Formation.
Why this is correct
Lake Formation uses a permission model that requires the principal to have no direct IAM access to the underlying S3 data. If the analyst has IAM permissions to read the S3 bucket, they can bypass Lake Formation's column-level restrictions and access all data directly. To enforce Lake Formation permissions, the analyst's IAM policy must not allow direct S3 access, and all access should go through Lake Formation-enabled services.
- ✗
Lake Formation column-level permissions are not supported for Athena queries.
Why it's wrong here
Lake Formation supports column-level permissions for Athena and other integrated services. When configured correctly, Athena respects these permissions. The issue is not lack of support but likely a misconfiguration or bypass. Column-level security is a core feature of Lake Formation and works with Athena when the data access is properly governed.
- ✗
The analyst's IAM role lacks the lakeformation:GetDataAccess permission.
Why it's wrong here
lakeformation:GetDataAccess is required for services like Athena to obtain temporary credentials from Lake Formation to access data. If missing, the analyst would receive an access denied error, not see all columns. Since the analyst can see all columns, they likely have direct S3 access, making this permission irrelevant to the symptom.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.