Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to share a dataset stored in Amazon S3 with another AWS account. The bucket policy currently grants access only to the owning account. What is the simplest way to grant cross-account access?

⚠ Common exam trap

DEA-C01 often tests the confusion between ACLs and bucket policies, and the misconception that creating a role in the other account is sufficient — candidates forget that the resource owner must also grant permission via a bucket policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a bucket policy that grants access to the other account's IAM role

A bucket policy is the simplest and most direct way to grant cross-account access because it is a resource-based policy attached to the S3 bucket that can explicitly name the other account's IAM role or account ID as a principal. This avoids the need to create roles or modify ACLs, and it works even when ACLs are disabled (the default for new buckets).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a bucket policy that grants access to the other account's IAM role

    Why this is correct

    Adding a bucket policy that names the other account's IAM role as principal grants cross-account access directly, satisfying the requirement to share the S3 dataset without extra infrastructure. S3 evaluates the resource-based policy against the requesting role, so no role switching, trust policy, or intermediate service is needed — the simplest mechanism available.

  • ✗

    Set the object ACL to public-read

    Why it's wrong here

    Setting an object ACL to public-read exposes the data to every anonymous internet user, not just the other AWS account, breaching least privilege. Public-read ACLs suit deliberately public static assets; cross-account sharing requires a bucket policy naming the other account's principal as grantee.

  • ✗

    Use an S3 access control list (ACL) to grant access to the other account

    Why it's wrong here

    S3 ACLs grant permissions only to individual objects or buckets and cannot delegate access to another account's principals at scale; they also predate bucket policies for cross-account sharing. ACLs suit per-object grants to canonical users, but the requirement here is account-level access, which a bucket policy referencing the other account's principal handles directly.

  • ✗

    Create an IAM role in the other account and attach a policy to it

    Why it's wrong here

    Creating a role in the consuming account grants that account's identities permissions, but the S3 bucket policy in the owning account still denies access, so the role alone cannot read the objects. IAM roles suit granting your own principals temporary credentials, not authorising a foreign account against your bucket.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.