dc dotCreds
AWS Certified Data Engineer - Associate Practice Test

AWS Data Engineer Associate Practice Test

Start today’s free 10-question AWS Data Engineer Associate set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 22, 2026, 10:19 PM CDT

Go Pro - One Time Unlock

Unlock the full DEA-C01 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS Data Engineer Associate questions

Use this AWS Data Engineer Associate practice test to review AWS Certified Data Engineer - Associate. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Task 2.3: Manage the lifecycle of data Data Store Management (26%)

Regulatory exports must be retained for seven years and are almost never retrieved. Retrieval can take many hours, and minimizing long-term storage cost is the primary objective. Which lifecycle destination is the BEST fit?

Concept tested:
Question 2 of 10
Objective Task 3.1: Automate data processing by using AWS services Data Operations and Support (22%)

A pipeline should start when an AWS service emits a matching operational event and should route only selected event patterns to the processing target. Which service is the best fit?

Concept tested:
Question 3 of 10
Objective Task 4.3: Ensure data encryption and masking Data Security and Governance (18%)

A high-volume S3 data lake uses SSE-KMS with a customer managed key and generates a very large number of KMS requests. The security model should remain SSE-KMS, but the team wants to reduce KMS request cost. Which S3 feature should be evaluated?

Concept tested:
Question 4 of 10
Objective Task 1.1: Perform data ingestion Data Ingestion and Transformation (34%)

A Lambda function processes batches from Kinesis. One malformed record near the end of a 500-record batch causes the entire batch to be retried, repeatedly reprocessing hundreds of successful records. The application can identify the failed sequence number. What should be configured?

Concept tested:
Question 5 of 10
Objective Task 3.4: Ensure data quality Data Operations and Support (22%)

A source feed often contains invalid negative quantities and timestamps outside the permitted processing window. The team wants a managed rule evaluation that produces quality scores and identifies failed rules. Which service capability fits?

Concept tested:
Question 6 of 10
Objective Task 4.1: Apply authentication mechanisms Data Security and Governance (18%)

An Amazon Aurora application password is stored in Secrets Manager. Security requires regular automatic credential rotation with the service managing the supported database integration whenever possible. Which approach should be preferred?

Concept tested:
Question 7 of 10
Objective Task 2.2: Understand data cataloging systems Data Store Management (26%)

A catalog table is partitioned by `year`, `month`, `day`, and `region`, with millions of partitions. Most jobs filter by date and region. Which design is MOST aligned with Glue partition-index optimization?

Concept tested:
Question 8 of 10
Objective Task 1.4: Apply programming concepts Data Ingestion and Transformation (34%)

A company must deploy identical data-platform resources to dev, test, and production with code review, drift visibility, and repeatable change history. Which approach is BEST?

Concept tested:
Question 9 of 10
Objective Task 3.3: Maintain and monitor data pipelines Data Operations and Support (22%)

A pipeline produces logs from Lambda, Glue, and custom applications. Operators need centralized retention, search, alarms, and cross-service troubleshooting. Which service is the primary log destination?

Concept tested:
Question 10 of 10
Objective Task 4.2: Apply authorization mechanisms Data Security and Governance (18%)

A VPC-based analytics application should access only `curated/team-a/` in a shared bucket using a dedicated policy endpoint, while another application has a different prefix. Which design provides the clearest policy boundary?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
DEA-C01 Pro $4.99 one-time

Unlock all 200 AWS Data Engineer Associate questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question DEA-C01 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Access Bundle $6.99/month

AWS practitioner, architect, and machine learning practice in one monthly unlock.

What’s includedAWS AI Practitioner, AWS Cloud Practitioner, AWS Developer Associate, AWS Advanced Networking Specialty, AWS Security Specialty, AWS ML Engineer Associate, AWS SAA-C03, AWS Data Engineer Associate, AWS DevOps Engineer Professional

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full DEA-C01 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily DEA-C01 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS Data Engineer Associate set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 Regulatory exports must be retained for seven years and are almost never retrieved. Retrieval can take many hours, and minimizing long-term storage cost is the primary objective. Which lifecycle destination is the BEST fit?

Answer choices

  1. A. Keep every object in S3 Standard for seven years.
  2. B. Transition the objects to S3 Express One Zone.
  3. C. Transition the objects to S3 Glacier Deep Archive after the active-retention period.
  4. D. Expire the objects after the active-retention period.

Correct answer

Transition the objects to S3 Glacier Deep Archive after the active-retention period.

Glacier Deep Archive is designed for very infrequently accessed long-term archival data with slower retrieval.

Wrong-answer review

  • A. Keep every object in S3 Standard for seven years.: S3 Standard preserves frequent-access performance but costs more for an archival access pattern.
  • B. Transition the objects to S3 Express One Zone.: Express One Zone is designed for high-performance access in one Availability Zone, not lowest-cost deep archive.
  • D. Expire the objects after the active-retention period.: Expiration deletes the records and violates the seven-year retention requirement.

Extra learning features

Why candidates miss this

The provided distractors – S3 Standard, Express One Zone, and Expiring Objects – all represent different S3 storage classes or actions that would not meet the stated requirements of seven-year retention and minimal cost. The key distinction lies in Glacier Deep Archive's design for infrequent access and long-term archival, which is the core of the question's intent. Likely wrong answer: Keep every object in S3 Standard for seven years. Review focus: Transitioning objects using Amazon S3 Lifecycle

Why this matters

Mismanaging S3 lifecycle rules for regulatory data can lead to unexpectedly high storage costs, potentially exceeding budget limits and impacting operational expenses. Implementing the correct Glacier Deep Archive policy mitigates this risk by optimizing storage costs for long-term retention, ensuring financial stability and compliance.

Objective/domain: Data Store Management (26%)

Source: Transitioning objects using Amazon S3 Lifecycle

Question 2 A pipeline should start when an AWS service emits a matching operational event and should route only selected event patterns to the processing target. Which service is the best fit?

Answer choices

  1. A. Use EventBridge Scheduler when the trigger is time based rather than event based.
  2. B. Use Amazon SNS when a producer already publishes notifications and no content-based event-bus routing is needed.
  3. C. Use Amazon EventBridge with a rule that matches the required event pattern and target.
  4. D. Use Amazon SQS when durable queueing/consumer decoupling is the primary requirement rather than event-pattern routing.

Correct answer

Use Amazon EventBridge with a rule that matches the required event pattern and target.

Objective/domain: Data Operations and Support (22%)

Source: AWS Certified Data Engineer - Associate Exam Guide (DEA-C01)

Question 3 A high-volume S3 data lake uses SSE-KMS with a customer managed key and generates a very large number of KMS requests. The security model should remain SSE-KMS, but the team wants to reduce KMS request cost. Which S3 feature should be evaluated?

Answer choices

  1. A. Enable S3 Bucket Keys for the SSE-KMS encrypted bucket.
  2. B. Increase the KMS key rotation frequency, which does not reduce the number of S3-to-KMS requests for object encryption.
  3. C. Use SSE-S3 instead, abandoning the stated requirement to remain on SSE-KMS with the customer managed key.
  4. D. Increase S3 multipart-upload part size and assume fewer object parts eliminate KMS request cost for the workload.

Correct answer

Enable S3 Bucket Keys for the SSE-KMS encrypted bucket.

Objective/domain: Data Security and Governance (18%)

Source: Protecting data with server-side encryption

Question 4 A Lambda function processes batches from Kinesis. One malformed record near the end of a 500-record batch causes the entire batch to be retried, repeatedly reprocessing hundreds of successful records. The application can identify the failed sequence number. What should be configured?

Answer choices

  1. A. Enable `BisectBatchOnFunctionError`, which narrows failing batches but can still retry already-successful records and is not the same record-level failure response.
  2. B. Enable partial batch response and return the failed record identifiers with ReportBatchItemFailures.
  3. C. Reduce batch size to 1 so failures are isolated by brute force, increasing invocation overhead.
  4. D. Send the whole failed batch to an on-failure destination after the first error and skip retry of recoverable records.

Correct answer

Enable partial batch response and return the failed record identifiers with ReportBatchItemFailures.

Objective/domain: Data Ingestion and Transformation (34%)

Source: Using Lambda to process records from Amazon Kinesis Data Streams

Question 5 A source feed often contains invalid negative quantities and timestamps outside the permitted processing window. The team wants a managed rule evaluation that produces quality scores and identifies failed rules. Which service capability fits?

Answer choices

  1. A. Use Glue crawler schema inference and treat a column's inferred type as proof that all records satisfy uniqueness/completeness rules.
  2. B. Use AWS Glue Data Quality with rules for allowed ranges and timestamp conditions.
  3. C. Implement the checks as ad-hoc Spark assertions in each job with no reusable ruleset or published quality results.
  4. D. Use DataBrew interactive profiling only, even though the checks must run automatically in the production ETL pipeline.

Correct answer

Use AWS Glue Data Quality with rules for allowed ranges and timestamp conditions.

Objective/domain: Data Operations and Support (22%)

Source: AWS Glue Data Quality

Question 6 An Amazon Aurora application password is stored in Secrets Manager. Security requires regular automatic credential rotation with the service managing the supported database integration whenever possible. Which approach should be preferred?

Answer choices

  1. A. Store the credential in Parameter Store SecureString and implement a custom rotation Lambda/schedule.
  2. B. Enable Secrets Manager automatic managed rotation for the supported database secret.
  3. C. Rotate only the KMS key that protects the secret while leaving the database credential value unchanged.
  4. D. Use a long-lived IAM access key as the database credential and rotate it through IAM.

Correct answer

Enable Secrets Manager automatic managed rotation for the supported database secret.

Objective/domain: Data Security and Governance (18%)

Source: Rotate AWS Secrets Manager secrets

Question 7 A catalog table is partitioned by `year`, `month`, `day`, and `region`, with millions of partitions. Most jobs filter by date and region. Which design is MOST aligned with Glue partition-index optimization?

Answer choices

  1. A. Enable partition projection in Athena even though multiple Glue-integrated engines need faster server-side partition filtering from the catalog.
  2. B. Create a partition index that reflects the commonly used partition-key filter order.
  3. C. Add more crawler runs so partition metadata is refreshed more often, without indexing the large partition catalog.
  4. D. Collapse the table to fewer coarse partitions, accepting much larger data scans to reduce catalog partition count.

Correct answer

Create a partition index that reflects the commonly used partition-key filter order.

Objective/domain: Data Store Management (26%)

Source: Creating partition indexes

Question 8 A company must deploy identical data-platform resources to dev, test, and production with code review, drift visibility, and repeatable change history. Which approach is BEST?

Answer choices

  1. A. Use console screenshots as the authoritative deployment specification.
  2. B. Use an S3 Inventory manifest as the infrastructure definition.
  3. C. Define the infrastructure with AWS CloudFormation or AWS CDK and deploy it through version-controlled CI/CD.
  4. D. Use a Kinesis consumer application to create resources ad hoc at startup.

Correct answer

Define the infrastructure with AWS CloudFormation or AWS CDK and deploy it through version-controlled CI/CD.

Objective/domain: Data Ingestion and Transformation (34%)

Source: AWS Certified Data Engineer - Associate Exam Guide (DEA-C01)

Question 9 A pipeline produces logs from Lambda, Glue, and custom applications. Operators need centralized retention, search, alarms, and cross-service troubleshooting. Which service is the primary log destination?

Answer choices

  1. A. Send application logs only to S3 and query them with Athena, accepting delayed/custom log analytics rather than the requested CloudWatch-native operational path.
  2. B. Use CloudTrail Lake as the primary destination for application stdout/stderr, even though CloudTrail is oriented to activity/audit events.
  3. C. Create CloudWatch metrics only and omit the underlying application log events needed for ad-hoc text/query diagnostics.
  4. D. Send the logs to Amazon CloudWatch Logs and use features such as Logs Insights/metric filters as needed.

Correct answer

Send the logs to Amazon CloudWatch Logs and use features such as Logs Insights/metric filters as needed.

Objective/domain: Data Operations and Support (22%)

Source: AWS Certified Data Engineer - Associate Exam Guide (DEA-C01)

Question 10 A VPC-based analytics application should access only `curated/team-a/` in a shared bucket using a dedicated policy endpoint, while another application has a different prefix. Which design provides the clearest policy boundary?

Answer choices

  1. A. Use one bucket policy with application-specific conditions for all ten applications and no access points.
  2. B. Create separate S3 buckets for every application and replicate shared data among them.
  3. C. Use S3 Object Lambda access points even though no per-request object transformation is required.
  4. D. Use separate S3 Access Points with policies for the respective application prefixes.

Correct answer

Use separate S3 Access Points with policies for the respective application prefixes.

Objective/domain: Data Security and Governance (18%)

Source: Managing data access with Amazon S3 access points

Where to go after the daily web set

How are AWS Data Engineer Associate questions generated?

dotCreds builds AWS Data Engineer Associate practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS Data Engineer Associate practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.