DEA-C01 exam dumps

DEA-C01 practice question 456 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 456

Select 2

You are tasked with setting up fine-grained access control for an Amazon S3 bucket that contains sensitive customer data. The access should be granted only to specific users from different departments based on their assigned roles and tags. Which combination of authorization methods should you prioritize to meet this requirement?

  1. A

    Role-based access control using IAM roles

  2. B

    Policy-based access control using resource policies

  3. C

    Tag-based access control using IAM policies with condition keys

  4. D

    Attribute-based access control using identity attributes from an external identity provider

  5. E

    IP-based access control using VPC endpoint policies

Show answer and explanation

Correct answers: A, C

Explanation

To implement fine-grained access control for an Amazon S3 bucket based on user roles and tags, you should prioritize role-based access control using IAM roles and tag-based access control using IAM policies with condition keys. These methods allow you to dynamically grant permissions based on user roles and resource tags, aligning with your requirement to restrict access to specific users from different departments. Other methods, such as resource policies and VPC endpoint policies, do not provide the necessary granularity or dynamic capabilities required in this scenario.

  • A. Correct.

    Role-based access control using IAM roles is a fundamental method to assign permissions based on user roles, ensuring that users have the appropriate level of access.

  • B. Incorrect.

    Policy-based access control using resource policies is useful for granting access to specific AWS resources, but it does not inherently support dynamic conditions like tags or user attributes.

  • C. Correct.

    Tag-based access control using IAM policies with condition keys allows for fine-grained permissions by evaluating resource tags and user attributes, making it suitable for department-level access control.

  • D. Incorrect.

    Attribute-based access control using identity attributes from an external identity provider is not natively supported for S3 bucket access control in AWS, so it is not applicable in this scenario.

  • E. Incorrect.

    IP-based access control using VPC endpoint policies is focused on controlling network access and does not address user or department-specific permissions.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam