DEA-C01 exam dumps

DEA-C01 practice question 455 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 455

Select 3

A company is using Amazon S3 to store sensitive customer data. They want to ensure that only specific users or services can access this data based on their roles, policies, and resource tags. Which combination of authorization methods would allow the company to enforce these access controls effectively?

  1. A

    Use IAM policies to define permissions for specific roles or users.

  2. B

    Apply bucket policies with condition keys to enforce tag-based access control.

  3. C

    Attach resource-based policies to the S3 bucket to manage access.

  4. D

    Use IAM roles to grant access to AWS services without individual credentials.

  5. E

    Enable multi-factor authentication (MFA) at the bucket level for authorization.

Show answer and explanation

Correct answers: A, B, D

Explanation

To enforce effective access controls for sensitive S3 data, using IAM policies ensures role-based access, bucket policies with condition keys support tag-based access, and IAM roles provide secure service-to-service access. These methods collectively provide robust and flexible authorization mechanisms. MFA, while important for authentication, does not control access based on roles, policies, or tags.

  • A. Correct.

    IAM policies are fundamental to defining permissions for users and roles to access AWS resources. They can be customized for precise access controls.

  • B. Correct.

    Bucket policies with condition keys allow for tag-based access controls, enabling fine-grained access management based on resource tags.

  • C. Incorrect.

    While resource-based policies can manage access, they are typically not used in combination with tag-based and role-based methods in this scenario.

  • D. Correct.

    IAM roles are essential for granting temporary access to AWS services without requiring individual credentials, making them suitable for service-to-service communication or temporary access scenarios.

  • E. Incorrect.

    MFA is an additional layer of security for authentication but is not an authorization method to enforce role-based, policy-based, or tag-based access controls.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam