DEA-C01 Data Security and Governance Practice Question
A data engineer needs to grant an IAM role read-only access to Amazon DynamoDB tables in a specific AWS account. Which IAM policy element should be used to restrict access to only the 'GetItem' and 'Query' actions?
⚠ Common exam trap
DEA-C01 often tests confusion between IAM policy elements, particularly Action versus Resource, where candidates might mistakenly think Resource specifies the allowed operations instead of the target AWS resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Action
The Action element in an IAM policy specifies the AWS API operations that the policy allows or denies. To restrict access to only 'GetItem' and 'Query' on DynamoDB tables, you list these actions in the Action element, e.g., 'dynamodb:GetItem' and 'dynamodb:Query'. This directly controls which operations the role can perform, making it the correct choice for limiting permissions to specific actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource
Why it's wrong here
The Resource element names the DynamoDB table ARNs the statement applies to; it cannot restrict which API actions are permitted. It tempts because scoping resources is essential for least privilege, and would be correct when limiting access to specific tables rather than all tables in the account.
- ✓
Action
Why this is correct
The Action element lists the specific API operations a policy allows or denies, so specifying dynamodb:GetItem and dynamodb:Query grants exactly those read-only calls and nothing else. This directly satisfies the stem's constraint of restricting access to only those two DynamoDB actions within the account.
- ✗
Effect
Why it's wrong here
Effect only declares whether the statement allows or denies access; it cannot enumerate the permitted DynamoDB API actions. It tempts because every policy requires an Effect value, and Allow would be correct when the goal is simply granting access without action-level restriction.
- ✗
Condition
Why it's wrong here
Condition adds constraints such as source IP or MFA to an already-defined permission; it does not select which DynamoDB actions are allowed. It tempts because conditions tighten access, and would be correct when restricting GetItem calls to requests from a specific VPC endpoint.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.