DEA-C01 Data Security and Governance Practice Question
A data engineer manages an AWS Glue Data Catalog shared across teams. Analysts in one team must be able to query only the sales database and its tables, while another team owns the marketing database. The engineer wants permissions managed centrally in Lake Formation and wants the analysts to be able to create their own temporary tables but not alter the sales tables. Which combination of Lake Formation grants should the engineer apply?
⚠ Common exam trap
The trap here is granting ALL or ALTER on a database to enable temporary tables, which also hands analysts the ability to modify or drop production tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant DESCRIBE and SELECT on the sales database and its tables to the analysts, and grant CREATE_TABLE on a separate scratch database for their temporary tables.
Least privilege in Lake Formation separates read permissions from modification and creation rights. DESCRIBE and SELECT on the sales database and tables allow discovery and querying, while withholding ALTER and DROP prevents changes to production tables. CREATE_TABLE on a dedicated scratch database lets analysts build temporary tables safely, keeping marketing data and the sales schema protected and centrally governed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant ALL on the sales database to the analysts and rely on IAM policies to restrict which tables they can alter.
Why it's wrong here
Lake Formation ALL on a database includes CREATE_TABLE, ALTER, and DROP, giving analysts far more than query access and violating the requirement that they not alter sales tables. IAM policies alone cannot restrict Lake Formation table-level operations once the catalog grant allows them. This over-permissioned grant also risks access to unintended resources and does not isolate a scratch area for temporary tables.
- ✗
Grant SELECT on the sales tables and DESCRIBE on the sales database, and grant ALL on the marketing database to the analysts.
Why it's wrong here
Granting ALL on the marketing database gives the analysts control over another team's data, which is the opposite of least privilege and violates the ownership boundary. The requirement is that analysts query only the sales database; broad rights on marketing would allow them to create, alter, and drop marketing tables. The scratch-database approach for temporary tables is also missing here.
- ✗
Grant DESCRIBE and SELECT on the sales database and tables, and grant ALTER on the sales database so analysts can create temporary tables there.
Why it's wrong here
ALTER on the sales database permits schema changes to its tables, contradicting the requirement that analysts not alter sales tables. It also does not cleanly separate temporary-table creation from production data. Using a dedicated scratch database with CREATE_TABLE isolates self-service objects from the sales database, which is the safer and intended pattern.
- ✓
Grant DESCRIBE and SELECT on the sales database and its tables to the analysts, and grant CREATE_TABLE on a separate scratch database for their temporary tables.
Why this is correct
Granting DESCRIBE and SELECT on the sales database and tables lets analysts discover and query that data without altering it, since ALTER and DROP are separate permissions not granted. CREATE_TABLE on a dedicated scratch database allows them to build temporary tables without touching the sales database. This least-privilege combination satisfies both query access and safe self-service while keeping marketing data inaccessible.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.