Courseiva
Data Store Management →hardMultiple Choice

DEA-C01 Data Store Management Practice Question

A data engineer is using AWS Lake Formation to manage fine-grained access control on an Amazon S3 data lake. The engineer has registered the S3 bucket as a Lake Formation data location and created a table in the AWS Glue Data Catalog. The engineer needs to grant a data analyst permission to query only specific columns (customer_id, order_date) in the sales table using Amazon Athena, while hiding other columns (credit_card_number, address). The analyst uses an IAM role that has no direct S3 permissions. Which action should the engineer take?

⚠ Common exam trap

The trap here is assuming that an Athena view or IAM policy can enforce column-level security when Lake Formation is managing the data lake. Only Lake Formation's column-level permissions prevent direct access to hidden columns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant the analyst's IAM role SELECT permission on the sales table in Lake Formation, and then use Lake Formation column-level security to include only the customer_id and order_date columns.

Lake Formation column-level security is designed to grant SELECT on specific columns while hiding others. By granting SELECT on the table and then specifying included columns, the analyst can query only those columns. Because the analyst's IAM role lacks direct S3 permissions, all data access goes through Lake Formation, which enforces the column restrictions and provides temporary credentials. This meets the requirement without granting broad S3 access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant the analyst's IAM role SELECT permission on the sales table in Lake Formation, and then use Lake Formation column-level security to include only the customer_id and order_date columns.

    Why this is correct

    Lake Formation column-level security allows granting SELECT on specific columns. By granting SELECT on the table and then applying column filters, the analyst can query only the allowed columns. Since the analyst's role has no direct S3 permissions, Lake Formation provides temporary credentials for data access, enforcing the column-level restrictions.

  • ✗

    Create an IAM policy that allows s3:GetObject on the sales table's S3 prefix, and attach it to the analyst's role. Then use Athena to restrict columns via a view.

    Why it's wrong here

    Granting direct S3 permissions bypasses Lake Formation's fine-grained access control, allowing the analyst to access all columns if they use other tools. While an Athena view can restrict columns, it does not prevent direct S3 access. This approach violates the principle of least privilege and does not meet the requirement to hide sensitive columns.

  • ✗

    Use AWS Glue DataBrew to create a dataset that includes only the allowed columns, and grant the analyst access to that dataset.

    Why it's wrong here

    AWS Glue DataBrew is a visual data preparation tool, not an access control mechanism. Creating a dataset does not restrict the analyst from querying the original table if they have permissions. This approach adds unnecessary complexity and does not enforce column-level security on the sales table in Athena.

  • ✗

    Grant the analyst's IAM role DESCRIBE and SELECT on the sales table in Lake Formation, and then create an Athena view that selects only the allowed columns.

    Why it's wrong here

    Lake Formation does not support granting SELECT at the table level and then restricting columns via an Athena view; column-level security must be applied in Lake Formation itself. An Athena view does not enforce column-level permissions if the user has table-level SELECT, because they can query the table directly. This does not hide the sensitive columns.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.