Courseiva

DEA-C01 Data Ingestion and Transformation Practice Question

A data engineer needs to run an AWS Glue ETL job that reads from an Amazon S3 bucket in another AWS account. The bucket owner has granted cross-account access, and the Glue job runs with an IAM role in the engineer's account. The job fails with an access denied error when reading the source objects. Which change is required to allow the Glue job to read the cross-account S3 data?

⚠ Common exam trap

The trap here is assuming a Glue catalog resource link also grants data access, when it only shares metadata and never authorizes S3 object reads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add an S3 bucket policy in the source account that grants the Glue job's IAM role s3:GetObject and s3:ListBucket on the bucket.

S3 authorization evaluates both identity-based policies in the caller's account and resource-based policies on the bucket. Because the Glue job's role lives in a different account than the bucket, the bucket owner must attach a bucket policy granting s3:GetObject and s3:ListBucket to that role. Catalog sharing and service-role policies do not extend to cross-account object reads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add an S3 bucket policy in the source account that grants the Glue job's IAM role s3:GetObject and s3:ListBucket on the bucket.

    Why this is correct

    Cross-account S3 access requires both the caller's IAM role to allow the S3 actions and the bucket owner to grant those actions through a bucket policy. Since the role already runs in the engineer's account, the missing piece is the resource-based policy in the source account. Adding s3:GetObject and s3:ListBucket for that role resolves the denial.

  • ✗

    Recreate the Glue job in the source account so it uses a role owned by the bucket owner.

    Why it's wrong here

    Moving the job into the source account would work but is a drastic architectural change and not a required configuration fix. The scenario states the bucket owner already granted cross-account access, implying a bucket policy is the intended mechanism. Recreating the job adds operational overhead and duplicates resources unnecessarily.

  • ✗

    Attach the AWSGlueServiceRole managed policy to the Glue job's IAM role in the engineer's account.

    Why it's wrong here

    AWSGlueServiceRole grants Glue service permissions for resources in the same account and does not include cross-account S3 object access. The role already has its in-account permissions; the denial originates from the source bucket lacking a policy for this principal. Adding a broader managed policy in the consumer account cannot override the source account's resource policy.

  • ✗

    Enable AWS Glue Data Catalog cross-account sharing by creating a resource link to the source account's catalog.

    Why it's wrong here

    Resource links share catalog metadata such as table definitions between accounts; they do not grant permission to read the underlying S3 objects. The failure is an S3 access denial, not a catalog lookup problem. Creating a resource link would let the job see table metadata but the S3 read would still be denied.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.