DEA-C01 Data Store Management Practice Question
A financial analytics company stores daily transaction records in Amazon S3 as Apache Parquet files, partitioned by year/month/day. The data engineering team queries these files with Amazon Athena. To reduce query runtime and cost, they want to apply fine-grained access control and column-level filtering without changing the files. Which solution should they use?
⚠ Common exam trap
The trap here is assuming that S3 Access Points or IAM policies can enforce column-level access control for Athena queries, when in fact only Lake Formation provides that granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define an AWS Lake Formation table with column-level permissions and use Lake Formation to manage access for Athena users.
AWS Lake Formation is designed to provide granular access control for data lakes built on Amazon S3 and the AWS Glue Data Catalog. It allows administrators to grant or revoke permissions at the database, table, column, and row level. Athena respects these permissions, enabling column-level filtering without data duplication or transformation. This meets the requirement to reduce runtime and cost by limiting data access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define an AWS Lake Formation table with column-level permissions and use Lake Formation to manage access for Athena users.
Why this is correct
AWS Lake Formation provides fine-grained access control at the table, column, and row level for data in the AWS Glue Data Catalog. Athena integrates with Lake Formation to enforce these permissions during queries without modifying underlying data. This directly satisfies the requirement for column-level filtering and access control.
- ✗
Create an AWS Glue Data Catalog table with partition projection and use Amazon S3 Access Points for authorization.
Why it's wrong here
Partition projection improves query performance by avoiding metadata lookups, and S3 Access Points simplify access management, but neither enforces column-level access control for Athena queries. They do not provide the fine-grained, column-level filtering required here, so this solution does not meet the access control requirement.
- ✗
Enable Amazon S3 Block Public Access and use IAM policies with condition keys to filter columns.
Why it's wrong here
S3 Block Public Access and IAM policies control access at the bucket or object level, not at the column level within Parquet files. IAM condition keys cannot parse Parquet schema to restrict specific columns. This does not provide the fine-grained column filtering needed for Athena queries.
- ✗
Store the data in Amazon Redshift Spectrum and use Redshift database roles to restrict column access.
Why it's wrong here
Redshift Spectrum allows querying S3 data, but the requirement specifies querying with Athena. Using Redshift database roles does not apply to Athena queries and would require additional infrastructure. This approach does not meet the goal of reducing Athena runtime and cost with column-level access control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.