Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer needs to grant a data analyst read access to specific columns in a table registered in the AWS Glue Data Catalog, while hiding other columns that contain personally identifiable information. The analyst uses Amazon Athena to query the table. Which Lake Formation feature should the engineer use?

⚠ Common exam trap

It's easy for candidates to confuse resource links with column-level permissions; resource links alone do not provide column filtering.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Lake Formation column-level permissions to grant SELECT on only the allowed columns.

Lake Formation column-level permissions allow granular control over which columns a principal can access. By granting SELECT only on specific columns, the analyst can query the table via Athena but will receive errors or filtered results for unauthorized columns. This is the intended feature for hiding PII while enabling access to other data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Glue Studio to create an ETL job that copies only the allowed columns to a new table and grant access to that table.

    Why it's wrong here

    Creating a separate table with only allowed columns via ETL duplicates data and adds maintenance overhead. It does not provide dynamic column-level security; any changes to the source schema or permissions require updating the ETL job. Lake Formation column-level permissions are designed for this exact purpose and are more efficient and secure.

  • ✓

    Use Lake Formation column-level permissions to grant SELECT on only the allowed columns.

    Why this is correct

    Lake Formation supports fine-grained access control, including column-level permissions. You can grant SELECT on a subset of columns in a table. When the analyst queries via Athena, Lake Formation filters the columns, and the analyst can only see the permitted columns. This directly meets the requirement to hide PII columns while allowing access to others.

  • ✗

    Create a resource link to the table and grant SELECT on the link.

    Why it's wrong here

    A resource link is a Data Catalog object that points to a shared database or table, often used for cross-account sharing. Granting SELECT on a resource link gives access to the entire table, not column-level filtering. It does not provide the ability to hide specific columns. To restrict columns, you must use column-level permissions within Lake Formation, not just a resource link.

  • ✗

    Apply an IAM policy to the analyst that allows s3:GetObject on the S3 path of the table.

    Why it's wrong here

    Granting s3:GetObject on the underlying S3 path would allow the analyst to read the raw data files directly, bypassing Lake Formation and exposing all columns, including PII. This is a security risk and does not achieve column-level filtering. IAM policies alone cannot enforce column-level access when using Lake Formation-governed tables.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.