DEA-C01 Data Security and Governance Practice Question
A data engineer needs to share a dataset stored in Amazon S3 with another AWS account. The bucket policy currently grants access only to the owning account. What is the simplest way to grant cross-account access?
⚠ Common exam trap
DEA-C01 often tests the confusion between ACLs and bucket policies, and the misconception that creating a role in the other account is sufficient — candidates forget that the resource owner must also grant permission via a bucket policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy that grants access to the other account's IAM role
A bucket policy is the simplest and most direct way to grant cross-account access because it is a resource-based policy attached to the S3 bucket that can explicitly name the other account's IAM role or account ID as a principal. This avoids the need to create roles or modify ACLs, and it works even when ACLs are disabled (the default for new buckets).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a bucket policy that grants access to the other account's IAM role
Why this is correct
Adding a bucket policy that names the other account's IAM role as principal grants cross-account access directly, satisfying the requirement to share the S3 dataset without extra infrastructure. S3 evaluates the resource-based policy against the requesting role, so no role switching, trust policy, or intermediate service is needed — the simplest mechanism available.
- ✗
Set the object ACL to public-read
Why it's wrong here
Setting an object ACL to public-read exposes the data to every anonymous internet user, not just the other AWS account, breaching least privilege. Public-read ACLs suit deliberately public static assets; cross-account sharing requires a bucket policy naming the other account's principal as grantee.
- ✗
Use an S3 access control list (ACL) to grant access to the other account
Why it's wrong here
S3 ACLs grant permissions only to individual objects or buckets and cannot delegate access to another account's principals at scale; they also predate bucket policies for cross-account sharing. ACLs suit per-object grants to canonical users, but the requirement here is account-level access, which a bucket policy referencing the other account's principal handles directly.
- ✗
Create an IAM role in the other account and attach a policy to it
Why it's wrong here
Creating a role in the consuming account grants that account's identities permissions, but the S3 bucket policy in the owning account still denies access, so the role alone cannot read the objects. IAM roles suit granting your own principals temporary credentials, not authorising a foreign account against your bucket.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.