Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to grant a data scientist access to query a Glue Data Catalog database but must prevent the data scientist from seeing the underlying S3 data locations. Which approach should be used?

⚠ Common exam trap

DEA-C01 often tests the misconception that Glue resource policies alone can restrict S3 visibility — candidates must recognize that only Lake Formation's credential vending hides S3 locations while still enabling queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Lake Formation to grant SELECT permission on the database and tables without granting S3 access

AWS Lake Formation allows fine-grained access control at the database, table, and column level without requiring direct S3 permissions. By granting SELECT on the Glue Data Catalog database and tables through Lake Formation, the data scientist can query the data via Athena or Redshift Spectrum while Lake Formation handles credential vending to access S3 on their behalf. This meets the requirement of preventing the data scientist from seeing the underlying S3 locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a Glue resource policy to restrict access to the database

    Why it's wrong here

    A Glue resource policy governs access to the Data Catalog database and tables, but it does not mask the S3 storage location metadata returned to the data scientist. It is tempting because resource policies do control catalog-level permissions, yet hiding locations requires Lake Formation column/table permissions or a catalog view that omits the storage descriptor.

  • ✗

    Grant the data scientist IAM permissions to access the Glue Data Catalog and the underlying S3 data

    Why it's wrong here

    Granting IAM permissions to both the Glue Data Catalog and the underlying S3 bucket gives the data scientist direct visibility of the S3 locations, contradicting the requirement to hide them. It is tempting because IAM policies are the standard access mechanism, but the scenario needs Lake Formation or a Glue catalog view that withholds the storage descriptor.

  • ✗

    Create a VPC endpoint for Glue and S3 to restrict network access

    Why it's wrong here

    A VPC endpoint controls network reachability, not metadata visibility; the data scientist would still see S3 locations in the Data Catalog. It is tempting because it restricts access paths, and would be correct for keeping Glue and S3 traffic off the public internet, not for hiding storage locations.

  • ✓

    Use AWS Lake Formation to grant SELECT permission on the database and tables without granting S3 access

    Why this is correct

    Lake Formation enforces table-level permissions through its own access layer, so the data scientist queries via Athena without IAM or S3 bucket policies exposing the storage location. Granting SELECT on the database and tables satisfies the query requirement while the underlying S3 paths remain hidden, because Lake Formation mediates access rather than S3 directly.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.