Courseiva

DEA-C01 Data Ingestion and Transformation Practice Question

A data engineer runs an AWS Glue job that reads from a JDBC connection to a PostgreSQL database. The job fails with a 'Connection timed out' error. The Glue job runs in a VPC with the appropriate security group. What is the most likely cause?

⚠ Common exam trap

The trap is confusing security groups with NACLs—candidates often blame the security group, but when the SG is stated as correct, the stateless NACL is the next network-layer suspect for timeouts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The network ACL associated with the Glue job's subnet is blocking outbound traffic.

A network ACL (NACL) is a stateless subnet-level firewall that can block outbound traffic. If the NACL associated with the Glue job's subnet does not allow outbound traffic to the PostgreSQL database's port (e.g., 5432), the connection times out. Since the security group is stated to be appropriate, the NACL is the most likely remaining network-layer cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The network ACL associated with the Glue job's subnet is blocking outbound traffic.

    Why this is correct

    Security groups are stateful and already correct, so the remaining subnet-level control is the network ACL. A stateless NACL blocking outbound traffic to the PostgreSQL port or return ephemeral range would cause the JDBC connection to time out, matching the reported error.

  • ✗

    The Glue job does not have permission to access the database.

    Why it's wrong here

    Permission failures surface as authorisation or access-denied errors, not connection timeouts; the JDBC driver would report authentication or privilege problems after connecting. IAM permissions govern which AWS APIs the job may call, and would be the cause if the job failed before reaching the database.

  • ✗

    The security group does not allow inbound traffic from the Glue job.

    Why it's wrong here

    The stem states the security group is appropriate, so inbound rules already permit the Glue job's traffic. Security group misconfiguration would be the cause if the stem had not confirmed correct rules; here the timeout points to the route out of the subnet, such as a missing NAT gateway or route table entry.

  • ✗

    The database credentials are incorrect.

    Why it's wrong here

    Incorrect credentials produce an authentication failure, such as a password or access-denied error, once the TCP connection reaches PostgreSQL. Credentials are the cause when the endpoint is reachable but the login is rejected, not when the connection itself never completes.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.