DEA-C01 exam dumps

DEA-C01 practice question 439 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 439

Single answer

A company is building a data processing pipeline on AWS. The pipeline uses Amazon EMR clusters to process data stored in Amazon S3. The company wants to restrict access to the EMR cluster, ensuring only authenticated users or applications can access the cluster. They also need to ensure that the access can be temporarily granted to specific users or applications without sharing long-term credentials. Which authentication method should they use?

  1. A

    Password-based authentication using AWS Secrets Manager to securely store credentials for EMR users

  2. B

    Certificate-based authentication by installing SSL certificates on the EMR cluster and storing them in AWS Certificate Manager (ACM)

  3. C

    Role-based authentication by assigning IAM roles to the EMR cluster and using temporary security credentials

  4. D

    Federated authentication by integrating AWS with an external identity provider using SAML

Show answer and explanation

Correct answer: C

Explanation

Role-based authentication is the most appropriate method for securely controlling access to the EMR cluster without using long-term credentials. By assigning IAM roles, temporary security credentials can be issued, and access can be granted or revoked as needed. This approach aligns with AWS best practices for authentication and access control in cloud environments.

  • A. Incorrect.

    Password-based authentication involves managing static credentials, which is not ideal for this scenario because it requires long-term credential management and doesn't support temporary access.

  • B. Incorrect.

    Certificate-based authentication requires manually managing SSL certificates and does not provide a way to temporarily grant access easily. This is more suitable for securing data in transit rather than authenticating users or applications.

  • C. Correct.

    Role-based authentication is the best choice here. By assigning IAM roles to the EMR cluster, temporary security credentials can be issued to users or applications. This method eliminates the need for long-term credentials and securely manages access.

  • D. Incorrect.

    Federated authentication is useful for integrating with external identity providers, but the question specifies controlling access to the EMR cluster directly. While federated access could eventually assign roles, it is not the most direct solution in this scenario.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam