Courseiva
Data Operations and Support →mediumMultiple Choice

DEA-C01 Data Operations and Support Practice Question

A data engineer manages an AWS Glue job that processes JSON files from Amazon S3 and writes Parquet to another S3 location. The job intermittently fails with 'Unable to find catalog table' errors, even though the table exists in the Glue Data Catalog. The job's IAM role has full S3 access but only limited Glue permissions. Which action will resolve the failure with the LEAST privilege?

⚠ Common exam trap

The trap here is assuming that S3 permissions alone are sufficient for AWS Glue jobs, when in fact the Glue Data Catalog requires its own IAM permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add glue:GetTable and glue:GetDatabase permissions for the specific database and table to the job's IAM role.

The job fails because its IAM role cannot call Glue Data Catalog APIs to retrieve table metadata. The minimal fix is to grant glue:GetTable and glue:GetDatabase for the specific database and table. This resolves the error while adhering to least privilege, unlike broad managed policies or irrelevant S3 permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS Glue Data Catalog encryption and update the job's security configuration.

    Why it's wrong here

    Encryption settings affect data at rest and do not grant permission to read catalog metadata. Enabling encryption would not fix an authorization error; it might even complicate access if the role lacks KMS permissions. This option does not address the missing Glue API permissions that cause the job to fail when looking up the table.

  • ✓

    Add glue:GetTable and glue:GetDatabase permissions for the specific database and table to the job's IAM role.

    Why this is correct

    The error indicates the job cannot retrieve table metadata from the Data Catalog. Granting glue:GetTable and glue:GetDatabase scoped to the exact database and table provides the necessary read access without excessive permissions. This aligns with least privilege and directly addresses the missing permission that causes the catalog lookup to fail during job execution.

  • ✗

    Attach the AWSGlueServiceRole managed policy to the job's IAM role.

    Why it's wrong here

    The AWSGlueServiceRole managed policy includes broad permissions, such as full S3 and Glue access, which violates least privilege. While it might resolve the error, it grants far more permissions than needed. The scenario specifically asks for the least privilege solution, so using a broad managed policy is not the correct choice here.

  • ✗

    Modify the job to use a different IAM role that has s3:GetObject permissions on the catalog bucket.

    Why it's wrong here

    The Glue Data Catalog is not an S3 bucket; it is a separate service. S3 permissions on any bucket do not grant access to catalog metadata. Changing the role to one with only S3 permissions would not resolve the 'Unable to find catalog table' error because the job still lacks Glue API permissions to fetch table definitions.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.