DEA-C01 exam dumps

DEA-C01 practice question 466 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 466

Select 2

You are working as a data engineer in a company that uses Amazon Redshift for its data warehouse. The company has multiple teams, including a Finance team and a Marketing team. The Finance team should only have access to the 'finance' schema, while the Marketing team should only have access to the 'marketing' schema. Each user should only be allowed to perform actions (SELECT, INSERT, UPDATE) relevant to their role. How should you configure role-based access control (RBAC) to meet these requirements?

  1. A

    Create separate database users for the Finance and Marketing teams, and grant them access to their respective schemas.

  2. B

    Use Amazon Redshift Groups to define roles for the Finance and Marketing teams, and assign users to the appropriate groups.

  3. C

    Grant the Finance team SELECT, INSERT, and UPDATE permissions on both the 'finance' and 'marketing' schemas to ensure flexibility.

  4. D

    Use schema-level permissions in Amazon Redshift to restrict access to the appropriate schemas for each team.

  5. E

    Enable Amazon Redshift native encryption to ensure data privacy between teams.

Show answer and explanation

Correct answers: B, D

Explanation

The best approach to implement role-based access control in Amazon Redshift is to use groups to define roles for the Finance and Marketing teams and assign permissions at the schema level. This ensures that each team has access only to the data they require, adhering to the principle of least privilege while simplifying user management.

  • A. Incorrect.

    Creating separate database users for each team can work but is not scalable or aligned with best practices for role-based access control. Groups are better suited for managing access by roles or teams.

  • B. Correct.

    Using Amazon Redshift Groups is a best practice for implementing role-based access control, as it simplifies the management of permissions by grouping users by role or team.

  • C. Incorrect.

    Granting the Finance team access to both schemas violates the principle of least privilege, as the Finance team should only access the 'finance' schema.

  • D. Correct.

    Schema-level permissions in Amazon Redshift allow fine-grained access control, ensuring each team has access only to their respective schemas.

  • E. Incorrect.

    Amazon Redshift native encryption is a security feature but does not address role-based access control or access patterns.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam