Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to grant an IAM role read-only access to Amazon DynamoDB tables in a specific AWS account. Which IAM policy element should be used to restrict access to only the 'GetItem' and 'Query' actions?

⚠ Common exam trap

DEA-C01 often tests confusion between IAM policy elements, particularly Action versus Resource, where candidates might mistakenly think Resource specifies the allowed operations instead of the target AWS resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Action

The Action element in an IAM policy specifies the AWS API operations that the policy allows or denies. To restrict access to only 'GetItem' and 'Query' on DynamoDB tables, you list these actions in the Action element, e.g., 'dynamodb:GetItem' and 'dynamodb:Query'. This directly controls which operations the role can perform, making it the correct choice for limiting permissions to specific actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Resource

    Why it's wrong here

    The Resource element names the DynamoDB table ARNs the statement applies to; it cannot restrict which API actions are permitted. It tempts because scoping resources is essential for least privilege, and would be correct when limiting access to specific tables rather than all tables in the account.

  • ✓

    Action

    Why this is correct

    The Action element lists the specific API operations a policy allows or denies, so specifying dynamodb:GetItem and dynamodb:Query grants exactly those read-only calls and nothing else. This directly satisfies the stem's constraint of restricting access to only those two DynamoDB actions within the account.

  • ✗

    Effect

    Why it's wrong here

    Effect only declares whether the statement allows or denies access; it cannot enumerate the permitted DynamoDB API actions. It tempts because every policy requires an Effect value, and Allow would be correct when the goal is simply granting access without action-level restriction.

  • ✗

    Condition

    Why it's wrong here

    Condition adds constraints such as source IP or MFA to an already-defined permission; it does not select which DynamoDB actions are allowed. It tempts because conditions tighten access, and would be correct when restricting GetItem calls to requests from a specific VPC endpoint.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.