
AWSCertified Data Engineer - Associate
Domain 4Objective 2
Task 4.2: Apply Authorization Mechanisms DEA-C01 Practice Questions (Page 1)
Part of the Content Domain 4: Data Security and Governance domain, which accounts for 18% of the DEA-C01 exam. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 2–3 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
7concepts
18%of the exam
Questions 1–5
- 1
A data engineering team maintains an IAM policy that grants access to an Amazon S3 bucket used by multiple applications. The policy has grown over time with overlapping statements. Which statement accurately describes how IAM evaluates the policy and reflects a best practice for maintaining least privilege?
Select an answer first - 2
A data engineer needs to grant a data analyst access to a specific table in a data lake managed by AWS Lake Formation. Which Lake Formation permission should the engineer grant?
Select an answer first - 3
A data engineer wants to allow a Lambda function to read a SecureString parameter from AWS Systems Manager Parameter Store. Which IAM action must be allowed in the Lambda function's execution role?
Select an answer first - 4
A data engineer needs to store a database password for an application. The password must be automatically rotated every 30 days. Which AWS service is designed for this purpose?
Select an answer first - 5
A data engineer needs to create a database user in Amazon Redshift that will be used by an ETL job. Which SQL command should the engineer use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DEA-C01” is a trademark of its owner, used for identification only.