Courseiva

DEA-C01 Data Operations and Support Practice Question

A data engineer is using AWS Lake Formation to manage access to a data lake stored in Amazon S3. The engineer grants SELECT permission on a table in the AWS Glue Data Catalog to an IAM role used by an Amazon Athena user. However, the user still cannot query the table and receives an 'Access Denied' error. The engineer verifies that the IAM role has the necessary AWS Lake Formation permissions and that the S3 bucket policy allows access. What is the most likely cause of the issue?

⚠ Common exam trap

The trap here is assuming that granting Lake Formation table permissions alone is sufficient, overlooking the need to register the S3 location with Lake Formation for it to manage data access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AWS Lake Formation data lake location is not registered.

The root cause is that the S3 data location is not registered with AWS Lake Formation. Even with Lake Formation table permissions, if the underlying S3 path is not registered, Lake Formation cannot manage access, and Athena queries fail with 'Access Denied'. Registering the location enables Lake Formation to control S3 permissions and grant access based on its policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM role lacks permissions to the AWS Glue Data Catalog.

    Why it's wrong here

    If the IAM role lacked permissions to the AWS Glue Data Catalog, the user would not be able to see the table at all, often resulting in a different error such as 'Table not found' or 'Insufficient permissions'. The scenario states that the engineer granted Lake Formation permissions, which typically include the necessary Data Catalog access. Moreover, the error is 'Access Denied' on query, suggesting the table is visible but data access is blocked.

  • ✗

    The S3 bucket policy does not grant access to the IAM role.

    Why it's wrong here

    The engineer already verified that the S3 bucket policy allows access. Even if it did not, Lake Formation can manage S3 permissions via its own service role, so the user's IAM role might not need direct S3 access. The error is likely due to Lake Formation's fine-grained access control intercepting the request, not the bucket policy. Thus, this is not the most likely cause.

  • ✗

    The IAM role requires an explicit DENY in the S3 bucket policy.

    Why it's wrong here

    An explicit DENY would indeed cause 'Access Denied', but the scenario says the bucket policy allows access, so there is no explicit deny. Moreover, Lake Formation often bypasses S3 bucket policies for registered locations. This option is incorrect because it contradicts the given information and is not a typical requirement. The issue is more likely related to Lake Formation configuration.

  • ✓

    The AWS Lake Formation data lake location is not registered.

    Why this is correct

    For Lake Formation to enforce and grant access to data in S3, the S3 location must be registered with Lake Formation. If the location is not registered, Lake Formation cannot manage permissions on the underlying data, and queries will fail with 'Access Denied' even if table-level permissions are granted. Registering the location allows Lake Formation to assume control of S3 access for that path.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.