DEA-C01 exam dumps

DEA-C01 practice question 462 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 462

Single answer

You are a Data Engineer managing an AWS environment for a large organization. Your team needs access to an Amazon S3 bucket that stores raw data for analytics processing. According to the principle of least privilege, what is the best approach to granting access?

  1. A

    Grant full access to the S3 bucket to all users in your team.

  2. B

    Create an IAM policy that grants only the required read and write permissions for the S3 bucket and attach it to a specific IAM role.

  3. C

    Use the root user credentials to access the S3 bucket and share it with the team.

  4. D

    Create an IAM policy that grants access to all S3 buckets in your AWS account and attach it to the team's IAM group.

Show answer and explanation

Correct answer: B

Explanation

The principle of least privilege ensures that users are granted only the permissions necessary to perform their tasks. By creating a narrowly scoped IAM policy that provides access only to the specific S3 bucket and the required permissions, you minimize the risk of unauthorized actions or data exposure while maintaining security best practices.

  • A. Incorrect.

    Granting full access to the S3 bucket to all users in your team violates the principle of least privilege as it provides more permissions than what is necessary.

  • B. Correct.

    Creating an IAM policy that grants only the required read and write permissions for the S3 bucket and attaching it to a specific IAM role adheres to the principle of least privilege by restricting access to only what is needed.

  • C. Incorrect.

    Using the root user credentials is a security risk and violates the principle of least privilege. The root user should only be used for account-level administrative tasks and not for routine access.

  • D. Incorrect.

    Granting access to all S3 buckets in the AWS account provides excessive permissions, violating the principle of least privilege, as it exceeds the scope of what is required for the task.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam