DEA-C01 Data Operations and Support Practice Question
A data engineer needs to ensure that an AWS Glue job has access to an Amazon RDS database in a private subnet. The Glue job will run in a VPC and requires a security group and subnet configuration. Which combination of steps should the engineer take?
⚠ Common exam trap
The trap here is thinking that a VPC endpoint for AWS Glue is needed or that making RDS public is acceptable, when in fact a VPC connection with proper security groups is the correct approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Glue job with a VPC connection, specify a subnet and security group, and ensure the security group allows outbound traffic to the RDS database's security group.
For an AWS Glue job to access an Amazon RDS database in a private subnet, the job must be configured with a VPC connection that specifies the subnet and security group. The security group must allow outbound traffic to the RDS database's security group on the database port. This ensures network connectivity while maintaining security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Glue Studio to create a connection to RDS, which automatically configures the necessary VPC settings and security groups.
Why it's wrong here
AWS Glue Studio can help create connections, but it does not automatically configure VPC settings and security groups for you. You must still specify the VPC, subnet, and security group details. This option incorrectly suggests that Glue Studio handles all networking automatically, which is not the case.
- ✓
Configure the Glue job with a VPC connection, specify a subnet and security group, and ensure the security group allows outbound traffic to the RDS database's security group.
Why this is correct
To run a Glue job in a VPC, you must provide a VPC connection that includes subnet and security group settings. The security group must allow outbound traffic to the RDS database's security group on the database port. This is the correct and minimal configuration for Glue to access RDS in a private subnet.
- ✗
Attach an IAM role to the Glue job with permissions to access RDS, and configure the RDS database to be publicly accessible.
Why it's wrong here
Making the RDS database publicly accessible is a security risk and is not required if the Glue job runs in the same VPC. IAM permissions alone are not sufficient for network connectivity; the Glue job still needs VPC configuration to reach the private subnet. This option misses the necessary network setup.
- ✗
Create a VPC endpoint for AWS Glue, configure the Glue job with a VPC connection, and attach a security group that allows outbound traffic to the RDS database.
Why it's wrong here
A VPC endpoint for AWS Glue is not required for Glue to access RDS within a VPC. Glue jobs run in an elastic network interface within your VPC when configured with a VPC connection. The security group must allow outbound traffic to the RDS database, but the VPC endpoint is unnecessary and adds complexity. This option includes an extraneous step.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.