DEA-C01 Data Security and Governance Practice Question
A data engineer needs to grant a data scientist access to query a Glue Data Catalog database but must prevent the data scientist from seeing the underlying S3 data locations. Which approach should be used?
⚠ Common exam trap
DEA-C01 often tests the misconception that Glue resource policies alone can restrict S3 visibility — candidates must recognize that only Lake Formation's credential vending hides S3 locations while still enabling queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Lake Formation to grant SELECT permission on the database and tables without granting S3 access
AWS Lake Formation allows fine-grained access control at the database, table, and column level without requiring direct S3 permissions. By granting SELECT on the Glue Data Catalog database and tables through Lake Formation, the data scientist can query the data via Athena or Redshift Spectrum while Lake Formation handles credential vending to access S3 on their behalf. This meets the requirement of preventing the data scientist from seeing the underlying S3 locations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a Glue resource policy to restrict access to the database
Why it's wrong here
A Glue resource policy governs access to the Data Catalog database and tables, but it does not mask the S3 storage location metadata returned to the data scientist. It is tempting because resource policies do control catalog-level permissions, yet hiding locations requires Lake Formation column/table permissions or a catalog view that omits the storage descriptor.
- ✗
Grant the data scientist IAM permissions to access the Glue Data Catalog and the underlying S3 data
Why it's wrong here
Granting IAM permissions to both the Glue Data Catalog and the underlying S3 bucket gives the data scientist direct visibility of the S3 locations, contradicting the requirement to hide them. It is tempting because IAM policies are the standard access mechanism, but the scenario needs Lake Formation or a Glue catalog view that withholds the storage descriptor.
- ✗
Create a VPC endpoint for Glue and S3 to restrict network access
Why it's wrong here
A VPC endpoint controls network reachability, not metadata visibility; the data scientist would still see S3 locations in the Data Catalog. It is tempting because it restricts access paths, and would be correct for keeping Glue and S3 traffic off the public internet, not for hiding storage locations.
- ✓
Use AWS Lake Formation to grant SELECT permission on the database and tables without granting S3 access
Why this is correct
Lake Formation enforces table-level permissions through its own access layer, so the data scientist queries via Athena without IAM or S3 bucket policies exposing the storage location. Granting SELECT on the database and tables satisfies the query requirement while the underlying S3 paths remain hidden, because Lake Formation mediates access rather than S3 directly.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.