DEA-C01 Data Security and Governance Practice Question
A data engineer must give an AWS Glue ETL job temporary access to data in an Amazon S3 bucket without creating long-term IAM user access keys. The job runs on a schedule and must retrieve credentials automatically. Which mechanism should the engineer use?
⚠ Common exam trap
The trap here is treating Secrets Manager or pre-signed URLs as the default way to give compute services credentials, when AWS compute services such as Glue should use an attached IAM role for automatic temporary credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an IAM role to the AWS Glue job and let the service assume it to obtain temporary credentials automatically.
AWS Glue jobs are associated with an IAM role that the service assumes to call other AWS services. The Glue runtime and AWS SDK automatically obtain temporary credentials from that role, so the job can read S3 data without any stored access keys. This satisfies the no-long-term-credentials requirement and follows AWS best practice for service-to-service authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach an IAM role to the AWS Glue job and let the service assume it to obtain temporary credentials automatically.
Why this is correct
AWS Glue jobs run with an IAM role that the service assumes on your behalf, and the AWS SDK and Glue runtime retrieve temporary credentials automatically. No access keys are created or stored, and permissions are governed by the role's policies. This is the standard, secure way to grant a Glue job access to S3.
- ✗
Store an IAM user's access key and secret key in AWS Secrets Manager and have the Glue job retrieve them at runtime.
Why it's wrong here
Long-term IAM user access keys stored in Secrets Manager still exist as permanent credentials and must be rotated manually. This violates the requirement to avoid long-term keys and adds secret-management overhead. AWS Glue natively supports IAM roles, so introducing static keys is unnecessary and less secure than role-based credentials.
- ✗
Generate a pre-signed URL for each S3 object and pass the URLs as job parameters to the Glue script.
Why it's wrong here
Pre-signed URLs grant time-limited access to individual objects and would need to be regenerated as objects change or URLs expire. Managing URLs for every object in a scheduled job is impractical and does not scale. The Glue service already provides temporary credentials through an IAM role, making pre-signed URLs the wrong tool here.
- ✗
Create an IAM user with programmatic access and embed the access key in the Glue job script as a hard-coded variable.
Why it's wrong here
Hard-coding access keys in a script exposes long-term credentials in code and logs, which directly contradicts the requirement to avoid long-term keys. It also creates a rotation and revocation burden. IAM roles for Glue jobs eliminate static credentials entirely, so this approach is both insecure and unnecessary.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.