
AWSCertified Data Engineer - Associate
Domain 4Objective 2
Task 4.2: Apply Authorization Mechanisms DEA-C01 Practice Questions (Page 2)
Part of the Content Domain 4: Data Security and Governance domain, which accounts for 18% of the DEA-C01 exam. AWS does not publish an official question count, but from its 130-minute exam (~50–85 total, ~9–15 in this domain), expect 2–3 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
7concepts
18%of the exam
Questions 6–10
- 6
A data engineer wants to allow an EC2 instance to retrieve a database secret from AWS Secrets Manager. Which IAM element is required in the identity-based policy attached to the instance's IAM role?
Select an answer first - 7
A data engineer needs to grant a user in Amazon Redshift the ability to read data from a table. Which SQL command should the engineer use?
Select an answer first - 8
A data engineer needs to create an IAM policy that allows a specific IAM role to read objects from only the 'sales-data' prefix in an Amazon S3 bucket. The engineer must ensure the policy is written in a way that IAM can evaluate. Which statement is a required element of a custom IAM policy?
Select an answer first - 9
A data engineer wants to create a group in Amazon Redshift and add a user to that group. Which two SQL commands are needed?
Select an answer first - 10
A data engineer needs to store a database password in AWS Systems Manager Parameter Store. The password must be encrypted at rest. Which parameter type should the engineer use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by AWS. “DEA-C01” is a trademark of its owner, used for identification only.