AWS · DEA-C01

AWS DEA-C01 Exam Practice Questions

366 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 366 questions in this pack

Question 1

A data engineer is configuring an AWS Glue job to read data from an Amazon S3 bucket. The data engineer has set up the necessary AWS Glue connection details and an associated IAM role. However, when the data engineer attempts to run the AWS Glue job, the data engineer receives an error message that indicates that there are problems with the Amazon S3 VPC gateway endpoint.

The data engineer must resolve the error and connect the AWS Glue job to the S3 bucket.

Which solution will meet this requirement?

  1. Update the AWS Glue security group to allow inbound traffic from the Amazon S3 VPC gateway endpoint.
  2. Configure an S3 bucket policy to explicitly grant the AWS Glue job permissions to access the S3 bucket.
  3. Review the AWS Glue job code to ensure that the AWS Glue connection details include a fully qualified domain name.
  4. Verify that the VPC's route table includes inbound and outbound routes for the Amazon S3 VPC gateway endpoint.
Show answer and explanation

Correct answer: D. Verify that the VPC's route table includes inbound and outbound routes for the Amazon S3 VPC gateway endpoint.

outbound routes for the Amazon S3 VPC gateway endpoint. When an AWS Glue job runs in a VPC, its traffic can reach Amazon S3 only if the route table associated with the Glue subnets contains a route for the S3 prefix list that targets the gateway endpoint. If that route is missing, or the endpoint is not associated with the correct route table, the job fails with S3 VPC gateway endpoint errors. Checking and correcting the route table entries fixes the network path. This is a VPC routing problem, not a security group, bucket policy, or application code problem.

Why the other options are wrong

  • A. Gateway endpoints are not associated with security groups, so changing inbound rules does not restore the path to S3.
  • B. A bucket policy grants permissions but cannot fix a missing endpoint route that blocks connectivity.
  • C. Glue reaches S3 through the endpoint automatically; no fully qualified domain name setting is required here.

Question 2

A retail company has a customer data hub in an Amazon S3 bucket. Employees from many countries use the data hub to support company-wide analytics. A governance

team must ensure that the company's data analysts can access data only for customers who are within the same country as the analysts.

Which solution will meet these requirements with the LEAST operational effort?

  1. Create a separate table for each country's customer data. Provide access to each analyst based on the country that the analyst serves.
  2. Register the S3 bucket as a data lake location in AWS Lake Formation. Use the Lake Formation row-level security features to enforce the company's access policies.
  3. Move the data to AWS Regions that are close to the countries where the customers are. Provide access to each analyst based on the country that the analyst serves.
  4. Load the data into Amazon Redshift. Create a view for each country. Create separate IAM roles for each country to provide access to data from each country. Assign the appropriate roles to the analysts.
Show answer and explanation

Correct answer: B. Register the S3 bucket as a data lake location in AWS Lake Formation. Use the Lake Formation row-level security features to enforce the company's access policies.

Lake Formation. Use the Lake Formation row-level security features to enforce the company's access policies. AWS Lake Formation provides built-in row-level security features that allow enforcement of access policies based on attributes like country. By registering the S3 bucket as a data lake location in Lake Formation and configuring row-level security, analysts can access the same table but only see rows relevant to their country. This requires minimal operational effort compared to creating separate tables, managing multiple regions, or building custom Redshift views and IAM roles.

Why the other options are wrong

  • A. Creating separate tables for each country is operationally intensive and does not scale well as countries are added.
  • C. Moving data to multiple regions introduces significant complexity, cost, and operational overhead for a data governance problem.
  • D. Using Amazon Redshift with separate views and IAM roles requires more manual management and operational effort than Lake Formation's built-in security features.

Question 3

A media company wants to improve a system that recommends media content to customer based on user behavior and preferences. To improve the recommendation system, the company needs to incorporate insights from third-party datasets into the company's existing analytics platform.

The company wants to minimize the effort and time required to incorporate third-party datasets.

Which solution will meet these requirements with the LEAST operational overhead?

  1. Use API calls to access and integrate third-party datasets from AWS Data Exchange.
  2. Use API calls to access and integrate third-party datasets from AWS DataSync.
  3. Use Amazon Kinesis Data Streams to access and integrate third-party datasets from AWS CodeCommit repositories.
  4. Use Amazon Kinesis Data Streams to access and integrate third-party datasets from Amazon Elastic Container Registry (Amazon ECR).
Show answer and explanation

Correct answer: A. Use API calls to access and integrate third-party datasets from AWS Data Exchange.

datasets from AWS Data Exchange. AWS Data Exchange is purpose-built for accessing and integrating third-party datasets with minimal effort. It provides pre-packaged datasets that can be accessed via API calls and easily integrated into existing analytics platforms. This is the most straightforward solution with the least operational overhead compared to alternatives.

Why the other options are wrong

  • B. AWS DataSync is designed for data transfer and synchronization between storage systems, not for accessing third-party datasets.
  • C. Amazon Kinesis Data Streams is a real-time streaming service, not a third-party dataset source; AWS CodeCommit is for version control.
  • D. Kinesis Data Streams is not designed for dataset integration; Amazon ECR is a container registry, not a third-party dataset source.

See all 10 free questions Get the full pack, US$39

366 practice questions for AWS Certified Data Engineer, Associate (DEA-C01), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 366 questions across all four DEA-C01 domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed DEA-C01 attempt costs another US$150, plus the time it takes to restudy. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 366 questions

What makes the DEA-C01 hard

DEA-C01 is not a theory exam. The scenarios are practical: a Glue job failing silently, a Kinesis stream dropping records, a Lake Formation permission not behaving the way it should. You need to know what to do, not just what the service is called, which is what separates candidates who pass from candidates who know AWS but have not studied the exam.

65 questions in 130 minutes, 720 out of 1000 to pass. This pack has 366 practice questions covering the AWS service combinations and specific scenarios that keep coming up, with no filler and no generic cloud questions.

About the exam

DEA-C01 is Amazon’s associate-level certification for data engineering on AWS. It validates the ability to design, build and manage data pipelines using core AWS data services. It is aimed at professionals with two to three years of data engineering experience and one to two years working hands-on with AWS. Valid for three years.

Exam domains

  • Data Ingestion and Transformation: 34%
  • Data Store Management: 26%
  • Data Operations and Support: 22%
  • Data Security and Governance: 18%

65 questions, 130 minutes, pass mark 720 out of 1000 (compensatory scoring), US$150 per attempt, online proctored or test centres, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the AWS DEA-C01 pack?

366 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.