Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer must give an AWS Glue ETL job temporary access to data in an Amazon S3 bucket without creating long-term IAM user access keys. The job runs on a schedule and must retrieve credentials automatically. Which mechanism should the engineer use?

⚠ Common exam trap

The trap here is treating Secrets Manager or pre-signed URLs as the default way to give compute services credentials, when AWS compute services such as Glue should use an attached IAM role for automatic temporary credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM role to the AWS Glue job and let the service assume it to obtain temporary credentials automatically.

AWS Glue jobs are associated with an IAM role that the service assumes to call other AWS services. The Glue runtime and AWS SDK automatically obtain temporary credentials from that role, so the job can read S3 data without any stored access keys. This satisfies the no-long-term-credentials requirement and follows AWS best practice for service-to-service authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach an IAM role to the AWS Glue job and let the service assume it to obtain temporary credentials automatically.

    Why this is correct

    AWS Glue jobs run with an IAM role that the service assumes on your behalf, and the AWS SDK and Glue runtime retrieve temporary credentials automatically. No access keys are created or stored, and permissions are governed by the role's policies. This is the standard, secure way to grant a Glue job access to S3.

  • ✗

    Store an IAM user's access key and secret key in AWS Secrets Manager and have the Glue job retrieve them at runtime.

    Why it's wrong here

    Long-term IAM user access keys stored in Secrets Manager still exist as permanent credentials and must be rotated manually. This violates the requirement to avoid long-term keys and adds secret-management overhead. AWS Glue natively supports IAM roles, so introducing static keys is unnecessary and less secure than role-based credentials.

  • ✗

    Generate a pre-signed URL for each S3 object and pass the URLs as job parameters to the Glue script.

    Why it's wrong here

    Pre-signed URLs grant time-limited access to individual objects and would need to be regenerated as objects change or URLs expire. Managing URLs for every object in a scheduled job is impractical and does not scale. The Glue service already provides temporary credentials through an IAM role, making pre-signed URLs the wrong tool here.

  • ✗

    Create an IAM user with programmatic access and embed the access key in the Glue job script as a hard-coded variable.

    Why it's wrong here

    Hard-coding access keys in a script exposes long-term credentials in code and logs, which directly contradicts the requirement to avoid long-term keys. It also creates a rotation and revocation burden. IAM roles for Glue jobs eliminate static credentials entirely, so this approach is both insecure and unnecessary.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.