DEA-C01 Data Operations and Support Practice Question
A data engineer manages an AWS Glue job that processes JSON files from Amazon S3 and writes Parquet to another S3 location. The job intermittently fails with 'Unable to find catalog table' errors, even though the table exists in the Glue Data Catalog. The job's IAM role has full S3 access but only limited Glue permissions. Which action will resolve the failure with the LEAST privilege?
⚠ Common exam trap
The trap here is assuming that S3 permissions alone are sufficient for AWS Glue jobs, when in fact the Glue Data Catalog requires its own IAM permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add glue:GetTable and glue:GetDatabase permissions for the specific database and table to the job's IAM role.
The job fails because its IAM role cannot call Glue Data Catalog APIs to retrieve table metadata. The minimal fix is to grant glue:GetTable and glue:GetDatabase for the specific database and table. This resolves the error while adhering to least privilege, unlike broad managed policies or irrelevant S3 permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS Glue Data Catalog encryption and update the job's security configuration.
Why it's wrong here
Encryption settings affect data at rest and do not grant permission to read catalog metadata. Enabling encryption would not fix an authorization error; it might even complicate access if the role lacks KMS permissions. This option does not address the missing Glue API permissions that cause the job to fail when looking up the table.
- ✓
Add glue:GetTable and glue:GetDatabase permissions for the specific database and table to the job's IAM role.
Why this is correct
The error indicates the job cannot retrieve table metadata from the Data Catalog. Granting glue:GetTable and glue:GetDatabase scoped to the exact database and table provides the necessary read access without excessive permissions. This aligns with least privilege and directly addresses the missing permission that causes the catalog lookup to fail during job execution.
- ✗
Attach the AWSGlueServiceRole managed policy to the job's IAM role.
Why it's wrong here
The AWSGlueServiceRole managed policy includes broad permissions, such as full S3 and Glue access, which violates least privilege. While it might resolve the error, it grants far more permissions than needed. The scenario specifically asks for the least privilege solution, so using a broad managed policy is not the correct choice here.
- ✗
Modify the job to use a different IAM role that has s3:GetObject permissions on the catalog bucket.
Why it's wrong here
The Glue Data Catalog is not an S3 bucket; it is a separate service. S3 permissions on any bucket do not grant access to catalog metadata. Changing the role to one with only S3 permissions would not resolve the 'Unable to find catalog table' error because the job still lacks Glue API permissions to fetch table definitions.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.