GregLab | Exam Prep

Security, Identity, and Compliance

Core

IAM

AWS principals, roles, policies, and least-privilege authorization.

Key points

  • IAM defines principals, roles, policies, groups, and authorization for AWS API actions.
  • Role trust and identity or resource policy permissions must align, while network and data-engine permissions remain separate.

Best-known use cases

  • Grant data jobs least-privilege access through service roles.
  • Delegate cross-account dataset access without sharing long-term credentials.

What candidates often confuse it with

  • IAM authorizes AWS actions; Lake Formation and database grants can impose additional data-level controls.

Key takeaway

Use IAM to give each data workload temporary, least-privilege access at the narrowest durable scope.

Relevant exam tasks

  • D4.1 — Task 4.1: Apply authentication mechanisms
  • 4.1.2 — Create and update IAM groups, roles, endpoints, and services.
  • 4.1.4 — Set up IAM roles for access (for example, AWS Lambda, Amazon API Gateway, AWS CLI, AWS CloudFormation).
  • 4.1.5 — Apply IAM policies to roles, endpoints, and services (for example, S3 Access Points, AWS PrivateLink).
  • D4.2 — Task 4.2: Apply authorization mechanisms
  • 4.2.1 — Create custom IAM policies when a managed policy does not meet the needs.
  • 4.2.5 — Apply authorization methods that address business needs (role-based, tag-based, and attribute-based).
  • 4.2.6 — Construct custom policies that meet the principle of least privilege.

Learn more

Free AWS Certified Data Engineer - Associate prep

Build focused DEA-C01 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

DEA-C01 at a glance

Category
Associate
Duration
130 minutes
Questions
65 total; 50 scored and 15 unidentified unscored
Formats
Multiple choice and multiple response
Scoring
100–1,000 scaled score; 720 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS documents 65 questions in 130 minutes: 50 scored and 15 unidentified unscored, using multiple-choice and multiple-response formats. This site's practice accuracy and readiness do not reproduce AWS's 100–1,000 scaled scoring or identify unscored items. Difficulty labels describe this site's Associate-level scenario complexity, not an AWS-published question rating.

Reference

DEA-C01 topics and reference map

Study links

DEA-C01 resources