DEA-C01 Data Security and Governance Practice Question
A data engineer must give an Amazon Redshift cluster the ability to load data from an Amazon S3 bucket using the COPY command. The security team prohibits embedding long-term AWS credentials in SQL and requires that access be revoked automatically when the cluster is deleted. The S3 bucket is encrypted with SSE-KMS using a customer managed key. Which approach should the data engineer use?
⚠ Common exam trap
The trap here is assuming the COPY command can accept arbitrary credential parameters, when the supported credential-free path is an IAM role attached to the cluster referenced by ARN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role to the Redshift cluster, grant the role s3:GetObject on the bucket and kms:Decrypt on the customer managed key, and reference the role ARN in the COPY command.
Attaching an IAM role to the Amazon Redshift cluster lets the COPY command assume temporary credentials without any long-term keys in SQL. The role needs s3:GetObject on the bucket and kms:Decrypt on the customer managed key to read SSE-KMS encrypted objects. Because the role is associated with the cluster, deleting the cluster removes that association, so access is revoked automatically as the security team requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the cluster with a database user that has a password stored in AWS Systems Manager Parameter Store and grant that user access to the S3 bucket through a bucket ACL.
Why it's wrong here
A database user password authenticates to Redshift, not to S3, and S3 bucket ACLs cannot grant access to a Redshift database principal. This approach would not let the COPY command read the objects and would leave a static password that must be rotated and revoked manually, so it fails both the access and the revocation requirements.
- ✗
Use the COPY command with the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters populated from an IAM role's temporary credentials obtained by calling AssumeRole from an external application.
Why it's wrong here
COPY does not accept ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters. Injecting temporary credentials obtained elsewhere still embeds them in SQL and requires an external process to refresh them, which the security team prohibits. It also does not tie the permission to the cluster lifecycle, so access would not be revoked automatically on deletion.
- ✗
Create an IAM user with an access key, store the key in AWS Secrets Manager, and pass the secret ARN to the COPY command using the CREDENTIALS clause.
Why it's wrong here
COPY supports a CREDENTIALS clause with an IAM role ARN, not a Secrets Manager secret ARN for a long-term access key. Even if the key were rotated, it remains a long-term credential that survives cluster deletion and would need manual revocation, violating the automatic revocation requirement and the prohibition on embedded credentials.
- ✓
Attach an IAM role to the Redshift cluster, grant the role s3:GetObject on the bucket and kms:Decrypt on the customer managed key, and reference the role ARN in the COPY command.
Why this is correct
Attaching an IAM role to the cluster provides temporary credentials that Redshift assumes automatically, so no long-term keys appear in SQL. Granting s3:GetObject and kms:Decrypt allows the COPY to read SSE-KMS encrypted objects. Because the role is attached to the cluster, deleting the cluster removes the role association, satisfying automatic revocation.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.