DEA-C01 Data Security and Governance Practice Question
A data engineer is using AWS Lake Formation to manage permissions on a Data Catalog table backed by Amazon S3. Analysts query the table with Amazon Athena. The security team wants analysts to see only rows where the region column equals 'EU' and to prevent them from viewing the customer_id column entirely. Which combination of Lake Formation features should the engineer implement?
⚠ Common exam trap
The trap here is assuming that IAM policies or Lake Formation LF-Tags can filter individual data rows, when row-value filtering requires a data filter with a row expression.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define a Lake Formation data filter with a row filter expression region='EU' and exclude the customer_id column, then grant the analysts SELECT on the table with that filter.
Lake Formation data filters combine row filter expressions with column selection. A row filter of region='EU' restricts visible rows, and excluding customer_id from the filter removes that column from query results. Granting analysts SELECT on the table through the filter applies both restrictions automatically for Athena and other integrated engines without duplicating or transforming the underlying data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Glue DataBrew to create a project that removes the customer_id column and filters to EU rows, then publish the result as a new table for analysts.
Why it's wrong here
DataBrew creates a transformed copy of the data, which duplicates storage and requires refresh whenever source data changes. It also does not enforce the restrictions for queries against the original table. Lake Formation data filters enforce row and column limits at query time without copying data, so DataBrew is the wrong mechanism here.
- ✓
Define a Lake Formation data filter with a row filter expression region='EU' and exclude the customer_id column, then grant the analysts SELECT on the table with that filter.
Why this is correct
Lake Formation data filters support both row filter expressions and column inclusion or exclusion. A filter with region='EU' limits visible rows, excluding customer_id hides that column, and granting SELECT with the filter enforces both restrictions for Athena queries. This directly matches the stated row and column requirements.
- ✗
Attach a tag-based access control policy to the table that grants access only when the analyst's IAM principal carries a tag matching the region value.
Why it's wrong here
Lake Formation tag-based access control governs access to databases, tables, and columns based on LF-Tags, but it does not filter rows by data values such as region. The region condition requires a row filter expression, and hiding a column requires column exclusion. Tagging alone cannot satisfy both requirements.
- ✗
Create an IAM policy that allows Athena access only to the S3 prefix containing EU data and deny access to the customer_id column in the Data Catalog.
Why it's wrong here
IAM policies cannot express column-level denies on a Data Catalog table, and S3 prefixes rarely align with row values such as region. Analysts could still query the table through Athena and see other regions if the table location covers all data. This approach does not deliver row or column filtering at the catalog level.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.