Skip to content
BytePatterns

DEA-C01 · Domain 4: Data Security and Governance · 18% of the exam

Task 4.1: Apply authentication mechanisms

Proving who is calling: security groups, IAM roles for services and tools, rotated credentials in Secrets Manager, policies on access points and endpoints, managed versus unmanaged services, and domains and projects in SageMaker Unified Studio.

Study it

  • IAM roles for data services, security groups and VPC endpoints

    Partly covered by: Shared Responsibility & IAM, VPC: Subnets, NAT & Firewalls

  • Credentials: Secrets Manager rotation and Parameter Store

    Lesson coming

  • SageMaker Unified Studio domains, domain units and projects

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An AWS Glue job connects to an Amazon RDS for PostgreSQL database with a user name and password that are typed into the job's parameters. Security requires that the password be stored encrypted, rotated automatically every 30 days, and picked up by the job without redeploying it. What should a data engineer do?

  1. AStore the password as a SecureString parameter in Parameter Store and read it in the job script
  2. BKeep the credentials in a rotated AWS Secrets Manager secret used by the Glue connection
  3. CEncrypt the password with a KMS key and keep the ciphertext in the job parameters
  4. DSave the credentials in an SSE-KMS encrypted S3 object that the job reads at start-up
Show the answer and why
  • AStore the password as a SecureString parameter in Parameter Store and read it in the job script

    Incorrect

    SecureString encrypts the value, but Parameter Store does not rotate it. AWS recommends Secrets Manager for database credentials.

  • BKeep the credentials in a rotated AWS Secrets Manager secret used by the Glue connection

    Correct

    Secrets Manager stores secrets encrypted and rotates them on a schedule, and a Glue connection can read its credentials from a Secrets Manager secret, so the job always gets the current value.

  • CEncrypt the password with a KMS key and keep the ciphertext in the job parameters

    Incorrect

    The password is encrypted but never rotated, and every change would mean editing the job.

  • DSave the credentials in an SSE-KMS encrypted S3 object that the job reads at start-up

    Incorrect

    The object is encrypted at rest, but nothing rotates the password in the object and the database together.

Database credentials belong in Secrets Manager: encrypted, rotated on a schedule, and fetched at run time by services such as Glue connections.

Question 2 · choose 2

An Amazon EMR cluster in private subnets with no internet access must read and write one S3 bucket. The traffic must not leave the AWS network, the company does not want hourly endpoint charges, and the bucket must reject requests that do not arrive through that private path. Which actions should a data engineer take? (Choose TWO.)

  1. ACreate an interface VPC endpoint for S3 in each Availability Zone of the cluster
  2. BCreate a gateway VPC endpoint for S3 in the private subnets' route tables
  3. CAdd a NAT gateway in a public subnet and route the private subnets through it
  4. DAdd a bucket policy that denies requests unless aws:SourceVpce equals the endpoint ID
  5. ETurn on S3 Transfer Acceleration for the bucket and use its endpoint
Show the answer and why
  • ACreate an interface VPC endpoint for S3 in each Availability Zone of the cluster

    Incorrect

    An interface endpoint would also be private, but it is billed for each hour it is provisioned in each Availability Zone.

  • BCreate a gateway VPC endpoint for S3 in the private subnets' route tables

    Correct

    A gateway endpoint gives the subnets a route to S3 without an internet gateway or NAT device, and gateway endpoints have no additional charge.

  • CAdd a NAT gateway in a public subnet and route the private subnets through it

    Incorrect

    Through a NAT device, traffic to S3 goes out through the internet gateway of the VPC.

  • DAdd a bucket policy that denies requests unless aws:SourceVpce equals the endpoint ID

    Correct

    The aws:SourceVpce condition lets a bucket policy restrict access to a specific VPC endpoint.

  • ETurn on S3 Transfer Acceleration for the bucket and use its endpoint

    Incorrect

    Transfer Acceleration speeds up transfers over long distances through edge locations. It is a public endpoint, not a private path.

For S3 and DynamoDB, a gateway endpoint is the free private path. Pair it with an aws:SourceVpce condition so the bucket accepts traffic only from that endpoint.

Question 3 · choose 2

An AWS Glue job runs with an IAM role in account A and must read objects in a bucket in account B. Account B's security team grants access through IAM roles, not bucket policy changes, and does not allow long-term keys. Which TWO steps should a data engineer take? (Choose TWO.)

  1. AIn account A, attach a permissions boundary to the job role that names the bucket
  2. BIn account B, create a role with read access whose trust policy names the job role in account A
  3. CIn account B, create a role whose trust policy names the glue.amazonaws.com principal
  4. DIn account A, allow the job role to call sts:AssumeRole on the role in account B
  5. EIn account B, set S3 Object Ownership on the bucket to bucket owner enforced
Show the answer and why
  • AIn account A, attach a permissions boundary to the job role that names the bucket

    Incorrect

    A permissions boundary only sets the maximum permissions that identity policies can grant; it grants nothing in another account.

  • BIn account B, create a role with read access whose trust policy names the job role in account A

    Correct

    The role in the trusting account defines the originating account as a trusted entity and carries the permissions to read the data.

  • CIn account B, create a role whose trust policy names the glue.amazonaws.com principal

    Incorrect

    For cross-account delegation, the role trusts the other account, which is the trusted entity, not a service in account B.

  • DIn account A, allow the job role to call sts:AssumeRole on the role in account B

    Correct

    Principals in the trusted account also need permission to assume the role in the other account.

  • EIn account B, set S3 Object Ownership on the bucket to bucket owner enforced

    Incorrect

    Object Ownership decides who owns objects and disables ACLs. It does not give account A any access.

Cross-account roles need both sides: a trust policy in the account that owns the data, and permission to assume the role in the account that uses it.

Question 4 · choose 1

Kafka producers and consumers on Amazon ECS write to and read from an Amazon MSK cluster. The team does not want to manage usernames, passwords, or client certificates, and wants permissions per topic defined in IAM policies. Which client authentication should a data engineer configure?

  1. ASASL/SCRAM with sign-in credentials in Secrets Manager
  2. BMutual TLS with certificates from AWS Private CA
  3. CIAM access control on the MSK cluster
  4. DSecurity group rules that allow only the ECS tasks
Show the answer and why
  • ASASL/SCRAM with sign-in credentials in Secrets Manager

    Incorrect

    This uses sign-in credentials stored in Secrets Manager, which is the username and password management the team wants to avoid.

  • BMutual TLS with certificates from AWS Private CA

    Incorrect

    Mutual TLS needs client certificates from an AWS Private CA, which the team does not want to manage.

  • CIAM access control on the MSK cluster

    Correct

    IAM access control handles both authentication and authorization, so MSK checks that a client is an authenticated identity and that it is allowed to produce or consume.

  • DSecurity group rules that allow only the ECS tasks

    Incorrect

    Security groups control network traffic. They do not authenticate clients or grant per-topic permissions.

MSK supports IAM, SASL/SCRAM, and mutual TLS; IAM is the option that needs no separate credentials and keeps topic permissions in IAM policies.

Question 5 · choose 1

A Lambda function loads data into an Amazon RDS for PostgreSQL database. Security policy forbids storing a database password anywhere, including in a secrets store. How should the function authenticate to the database?

  1. AIAM database authentication with a generated token
  2. BA rotated password in AWS Secrets Manager
  3. CA password in a KMS-encrypted environment variable
  4. DA database security group rule that names the function
Show the answer and why
  • AIAM database authentication with a generated token

    Correct

    With IAM database authentication, the function connects with an authentication token that RDS generates on request instead of a password.

  • BA rotated password in AWS Secrets Manager

    Incorrect

    Rotation changes the password, but the password is still stored in a secrets store, which the policy forbids.

  • CA password in a KMS-encrypted environment variable

    Incorrect

    Encrypting the variable protects the password, but the function still stores a password, which the policy forbids.

  • DA database security group rule that names the function

    Incorrect

    Security groups control which network traffic can reach the database. They do not authenticate a database user.

IAM database authentication replaces stored passwords with short-lived tokens that are signed with the caller's IAM credentials.

Question 6 · choose 1

Servers in an on-premises data center run scripts that upload files to Amazon S3 with IAM user access keys. The company already issues X.509 certificates to these servers and wants to stop managing long-term AWS credentials for them. What should a data engineer use?

  1. AThe same access keys, rotated every 30 days by a script
  2. BAn EC2 instance profile attached to each on-premises server
  3. CA bucket policy that allows uploads from the data center's IP range
  4. DIAM Roles Anywhere with the company's certificate authority
Show the answer and why
  • AThe same access keys, rotated every 30 days by a script

    Incorrect

    Rotated access keys are still long-term credentials that must be managed, which is what the company wants to stop.

  • BAn EC2 instance profile attached to each on-premises server

    Incorrect

    Instance profiles deliver role credentials to applications on Amazon EC2 instances, not to servers outside AWS.

  • CA bucket policy that allows uploads from the data center's IP range

    Incorrect

    A bucket policy can restrict access, but the scripts would still need credentials to sign their requests.

  • DIAM Roles Anywhere with the company's certificate authority

    Correct

    Roles Anywhere gives workloads outside AWS temporary credentials for IAM roles, using X.509 certificates, so there are no long-term keys to manage.

Inside AWS, roles reach code through instance profiles and execution roles; outside AWS, Roles Anywhere exchanges certificates for the same temporary role credentials.

Question 7 · choose 1

Jobs in private subnets reach Amazon S3 through a gateway VPC endpoint. The security team wants to make sure that, through this endpoint, the jobs can reach only the company's approved buckets, so that data cannot be copied to other buckets. What should a data engineer configure?

  1. ABucket policies on the approved buckets that require this endpoint
  2. BA security group outbound rule that allows only the S3 prefix list
  3. CA route table entry for the endpoint in each private subnet only
  4. DAn endpoint policy that allows access only to the approved buckets
Show the answer and why
  • ABucket policies on the approved buckets that require this endpoint

    Incorrect

    Such bucket policies control who can reach the approved buckets. They do not stop the jobs from writing to other buckets.

  • BA security group outbound rule that allows only the S3 prefix list

    Incorrect

    Security groups control traffic to and from resources. The prefix list covers Amazon S3 as a whole, not individual buckets.

  • CA route table entry for the endpoint in each private subnet only

    Incorrect

    The route sends S3 traffic through the gateway endpoint. Without an endpoint policy, the default policy allows access through it.

  • DAn endpoint policy that allows access only to the approved buckets

    Correct

    An endpoint policy is a resource-based policy on the endpoint that controls access to Amazon S3 through it, and it can limit that access to specific buckets.

Endpoint policies govern what can be reached through the endpoint; bucket policies govern who can reach a bucket. Exfiltration controls need the endpoint side.

Practise domain 4 →Practise all domains →