DEA-C01 Data Operations and Support Practice Question
A data engineer manages an AWS Glue ETL job that reads from an Amazon S3 bucket and writes to an Amazon Redshift table. The job runs daily and recently started failing with the error 'Unable to find a suitable security group for the connection'. The Glue connection is configured with a VPC, subnet, and security group. The engineer verifies that the IAM role has the necessary permissions and the S3 bucket is accessible. What is the most likely cause of this error?
⚠ Common exam trap
The trap here is assuming the error is about network routing or IAM permissions, when it specifically points to a security group mismatch with the subnet's VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The security group specified in the Glue connection does not exist or is not in the same VPC as the subnet.
The error 'Unable to find a suitable security group for the connection' occurs when the security group specified in the Glue connection is invalid for the subnet. This typically happens if the security group does not exist, is in a different VPC, or is not associated with the subnet's VPC. Ensuring the security group and subnet are in the same VPC and that the security group exists resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The security group attached to the Glue connection does not allow outbound traffic to the Redshift cluster on the required port.
Why it's wrong here
Incorrect. The error message specifically indicates that Glue cannot find a suitable security group, not that the security group is blocking outbound traffic. If outbound rules were the issue, the job would fail with a timeout or connection refused error, not a security group selection error. The problem is likely related to security group configuration or subnet mapping.
- ✗
The IAM role used by the Glue job lacks permissions to describe security groups in the VPC.
Why it's wrong here
Incorrect. The error is about finding a suitable security group, not about permissions to describe them. If the IAM role lacked ec2:DescribeSecurityGroups, the error would be an authorization failure. Glue's VPC connection validation checks for the existence and compatibility of the security group, not IAM permissions.
- ✗
The Glue connection is associated with a subnet that does not have a route to the Redshift cluster.
Why it's wrong here
Incorrect. While routing is important, the error explicitly states that Glue cannot find a suitable security group. This suggests the security group is missing, misconfigured, or not associated with the subnet. Routing issues typically manifest as timeouts or unreachable host errors, not as security group selection failures.
- ✓
The security group specified in the Glue connection does not exist or is not in the same VPC as the subnet.
Why this is correct
Correct. AWS Glue requires that the security group and subnet belong to the same VPC. If the security group is deleted, renamed, or belongs to a different VPC, Glue cannot use it and throws this error. This is a common misconfiguration when VPC settings are changed or when the connection is created with incorrect parameters.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.