DEA-C01 exam dumps

DEA-C01 practice question 447 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 447

Select 2

A data engineering team is building a data pipeline on AWS that ingests sensitive customer data into Amazon S3, processes it using AWS Glue, and stores the transformed data in Amazon Redshift. The team must ensure that only specific IAM roles used by AWS Glue and Amazon Redshift have access to the S3 bucket. Which combination of authorization mechanisms should be implemented to meet this requirement?

  1. A

    Use S3 bucket policies to explicitly allow access for the required IAM roles only.

  2. B

    Attach an S3 Access Point to the bucket and restrict its access to the required IAM roles.

  3. C

    Attach an IAM policy to the required roles, granting them access to the S3 bucket.

  4. D

    Enable S3 Block Public Access on the bucket and rely on default permissions.

  5. E

    Use AWS Lake Formation to manage access to the S3 bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the requirement of restricting access to the S3 bucket for specific IAM roles, a combination of S3 bucket policies and IAM role policies should be used. Bucket policies allow you to explicitly define access permissions at the bucket level, while IAM policies attached to the roles ensure that only those roles can access the bucket. This approach aligns with AWS best practices for secure authorization and access management.

  • A. Correct.

    This is correct because S3 bucket policies can be used to explicitly define which IAM roles or users have access to the bucket, providing fine-grained control over access permissions.

  • B. Incorrect.

    This is incorrect because while S3 Access Points are useful for managing access, they are not directly used to restrict access to specific IAM roles in this scenario.

  • C. Correct.

    This is correct because attaching an IAM policy to the roles ensures that only those roles have the necessary permissions to access the S3 bucket, following the principle of least privilege.

  • D. Incorrect.

    This is incorrect because enabling S3 Block Public Access only prevents public access to the bucket but does not restrict access to specific IAM roles.

  • E. Incorrect.

    This is incorrect because AWS Lake Formation is primarily used for managing access to data lakes, not for restricting access to an S3 bucket in this specific pipeline.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam