Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to grant an IAM user access to query a specific table in Amazon Athena, but the user should not be able to view other tables in the same database. Which method should the engineer use?

⚠ Common exam trap

DEA-C01 often tests whether candidates know that IAM policies cannot filter by table name in Athena, so they pick an IAM policy or S3 bucket policy instead of Lake Formation for table-level access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Lake Formation to grant SELECT permission on the specific table to the user

AWS Lake Formation provides fine-grained access control at the table and column level, so granting SELECT permission on the specific table to the IAM user restricts them to that table while denying access to others in the same database. This is the intended service for table-level Athena permissions. It integrates with the Glue Data Catalog to enforce permissions at query time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM policy that allows athena:StartQueryExecution and restrict the query by table name

    Why it's wrong here

    StartQueryExecution grants the ability to run queries but carries no table-level condition key, so it cannot restrict the user to one table within the database. This action-level policy suits granting broad query capability when catalog-level scoping is handled separately.

  • ✓

    Use AWS Lake Formation to grant SELECT permission on the specific table to the user

    Why this is correct

    Lake Formation provides table-level grants within a database, so granting SELECT on the single table lets the user query it while other tables remain inaccessible. Athena alone cannot enforce such granular per-table restrictions through IAM policies.

  • ✗

    Apply an S3 bucket policy that restricts access to the table's underlying data

    Why it's wrong here

    An S3 bucket policy governs access to the underlying objects, not to the Athena table metadata, so the user could still list and query other tables in the same database. Bucket policies are the right control when restricting access to specific data files rather than to catalog objects.

  • ✗

    Create a separate Athena workgroup with a query limit that only allows queries on that table

    Why it's wrong here

    A workgroup governs query output location, encryption and per-query data limits, not which tables a principal may reference, so other tables remain visible and queryable. Workgroups are the correct control for isolating query costs, results and concurrency between teams.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.