DEA-C01 Practice Exam: AWS Certified Data Engineer - Associate
Glue, Kinesis, Redshift, Lake Formation — build pipelines that move data without catching fire.
What you'll be tested on
- Data Ingestion and Transformation
- Data Store Management
- Data Operations and Support
- Data Security and Governance
Sample DEA-C01 questions
A data engineer is configuring an AWS Glue job to read data from an Amazon S3 bucket. The data engineer has set up the necessary AWS Glue connection details and an associated IAM role. However, when the data engineer attempts to run the AWS Glue job, the data engineer receives an error message that indicates that there are problems with the Amazon S3 VPC gateway endpoint. The data engineer must resolve the error and connect the AWS Glue job to the S3 bucket. Which solution will meet this requirement?
- Update the AWS Glue security group to allow inbound traffic from the Amazon S3 VPC gateway endpoint.
- Configure an S3 bucket policy to explicitly grant the AWS Glue job permissions to access the S3 bucket.
- Review the AWS Glue job code to ensure that the AWS Glue connection details include a fully qualified domain name.
- Verify that the VPC's route table includes inbound and outbound routes for the Amazon S3 VPC gateway endpoint.
Show answer
D — Verify that the VPC's route table includes inbound and outbound routes for the Amazon S3 VPC gateway endpoint.Gateway VPC endpoints for S3 work by adding entries to route tables that direct S3 traffic through the endpoint. If the route table associated with the subnets used by the Glue connection lacks routes to the S3 gateway endpoint, the Glue job cannot reach S3, producing the endpoint error. Verifying and fixing the route table entries resolves connectivity. Security groups do not apply to gateway endpoints, so option A is wrong. A bucket policy (B) would cause an access denied error, not an endpoint connectivity error. A fully qualified domain name (C) is irrelevant to gateway endpoint routing.
A retail company has a customer data hub in an Amazon S3 bucket. Employees from many countries use the data hub to support company-wide analytics. A governance team must ensure that the company's data analysts can access data only for customers who are within the same country as the analysts. Which solution will meet these requirements with the LEAST operational effort?
- Create a separate table for each country's customer data. Provide access to each analyst based on the country that the analyst serves.
- Register the S3 bucket as a data lake location in AWS Lake Formation. Use the Lake Formation row-level security features to enforce the company's access policies.
- Move the data to AWS Regions that are close to the countries where the customers are. Provide access to each analyst based on the country that the analyst serves.
- Load the data into Amazon Redshift. Create a view for each country. Create separate IAM roles for each country to provide access to data from each country. Assign the appropriate roles to the analysts.
Show answer
B — Register the S3 bucket as a data lake location in AWS Lake Formation. Use the Lake Formation row-level security features to enforce the company's access policies.AWS Lake Formation provides row-level security through row filter expressions, letting you restrict which rows each analyst sees based on attributes such as country, all centrally managed with minimal effort. Creating a separate table per country (A) multiplies tables and ETL jobs, which is high operational overhead. Moving data across Regions (C) does not enforce per-analyst access and adds complexity and cost. Loading into Redshift with per-country views and IAM roles (D) requires a data warehouse migration plus many views and roles, which is far more operational effort than Lake Formation row filters on the existing S3 data lake.
A media company wants to improve a system that recommends media content to customer based on user behavior and preferences. To improve the recommendation system, the company needs to incorporate insights from third-party datasets into the company's existing analytics platform. The company wants to minimize the effort and time required to incorporate third-party datasets. Which solution will meet these requirements with the LEAST operational overhead?
- Use API calls to access and integrate third-party datasets from AWS Data Exchange.
- Use API calls to access and integrate third-party datasets from AWS DataSync.
- Use Amazon Kinesis Data Streams to access and integrate third-party datasets from AWS CodeCommit repositories.
- Use Amazon Kinesis Data Streams to access and integrate third-party datasets from Amazon Elastic Container Registry (Amazon ECR).
Show answer
A — Use API calls to access and integrate third-party datasets from AWS Data Exchange.AWS Data Exchange is a marketplace where you can find, subscribe to, and use third-party datasets, and its APIs let you integrate subscribed data directly into your analytics platform with minimal effort. AWS DataSync (B) is a data transfer service for moving data between storage systems, not a source of third-party datasets. AWS CodeCommit (C) is a source code repository service, not a dataset provider. Amazon ECR (D) stores container images, not data products. Only Data Exchange is purpose-built for discovering and consuming third-party data, so option A has the least operational overhead.
Access plans
| Access | Price |
|---|---|
| 3 months | |
| 1 year | |
| Lifetime |
Free preview inside — try 5 questions before you pay anything.
FAQ
How many practice questions are in this DEA-C01 bank?
366 questions covering the current DEA-C01 AWS Certified Data Engineer - Associate syllabus, every one with the correct answer and an explanation.How long is the real DEA-C01 exam?
The official DEA-C01 exam gives you 130 minutes. Our timed exam mode uses the same limit so the pace feels familiar.What does DEA-C01 access cost?
Plans start at $3.99 for 3 months. One payment, no subscription — and far cheaper than retaking the real exam.