Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Exam-style. One correct answer each, no partial credit. Answers with explanations at the end.
1. A team asks you to create a Quick Sight data source directly against AWS Glue Data Catalog. What do you do?
Type: GLUE in CreateDataSourceType: GLUE2. aws quicksight create-data-source returns HTTP 200 with
"CreationStatus": "CREATION_IN_PROGRESS". What is true?
DescribeDataSourceCREATION_SUCCESSFUL3. Which credential configuration produces the failure COPY_SOURCE_NOT_FOUND?
SecretArn whose secret was deletedCredentialPair with a rotated passwordCopySourceArn from a since-deleted data source4. Which two SaaS source types cannot use Secrets Manager credentials?
5. An engineer edits an API-managed data source in the console to fix a typo in its display name. The next scheduled refresh fails with an authentication error. Most likely cause?
SslProperties to defaultsSecretArnquicksight:UpdateDataSource6. Both aws-quicksight-s3-consumers-role-v0 and aws-quicksight-service-role-v0 exist in an
account. Athena connections fail with insufficient permissions. An S3 policy was added to
aws-quicksight-service-role-v0 and nothing changed. Why?
7. Athena data encrypted with a customer KMS key fails from Quick Sight but works in the Athena console. The documented fix is:
kms:* to the user's IAM policyaws kms create-grant --grantee-principal <QuickSight role ARN> --operations Decrypt8. Which pair of sources is reached through the lesson-3 service roles and not through a VPC connection?
9. CreateVPCConnection rejects your call. You supplied one subnet ID, three security group
IDs, and a role ARN. What violated the API contract?
DnsResolvers is required10. Why must the QNI security group's inbound rule allow all TCP ports 0–65535?
11. A VPC connection reports CreationStatus: CREATION_SUCCESSFUL and
AvailabilityStatus: PARTIALLY_AVAILABLE. The matching symptom is:
ACCESS_DENIED12. A database hostname lives in a Route 53 private hosted zone and only resolves inside the VPC. Which is the documented mechanism to make a Quick Sight VPC connection work?
DnsResolvers13. Users report Quick Sight "can't connect" to Redshift; the DBA reports the cluster is suddenly slow. Visuals use direct query. The most likely mechanism is:
14. Which manifest is valid for a Quick Sight-format S3 import?
manifest.txt containing fileLocations with URIsmanifest.json containing entries with url and mandatorymanifest.json containing fileLocations, mixing one CSV and one JSON filemanifest.json containing fileLocations with URIPrefixes covering a folder of same-schema CSVs15. Your security baseline requires TLS 1.2 to an Aurora MySQL source. Engine version is 5.7.21. What actually happens, per the docs?
SSL_CERTIFICATE_VALIDATION_FAILURE16. For creating a data source with a SecretArn, whose permissions authorize
secretsmanager:GetSecretValue at creation time?
aws-quicksight-secretsmanager-role-v0aws-quicksight-service-role-v0Permissions principals1 — B. There is no Glue Type in the 38-value enum. The user guide's own list says Glue Data
Catalog is "accessed using AWS Glue data catalog compatible services, such as Athena or Redshift
Spectrum." A and C invent an enum value; D works but abandons the catalog and live queries.
2 — B. Creation is asynchronous; the 200 acknowledges the request. Connection testing resolves
later into CREATION_SUCCESSFUL/CREATION_FAILED — read it with DescribeDataSource. A and D
claim validations that haven't happened; C retries a non-idempotent create (you'd hit
ResourceExistsException).
3 — C. COPY_SOURCE_NOT_FOUND is the borrowing chain breaking. A deleted secret (A) fails as
an access/auth error; B as authentication; D as a KMS/decrypt failure.
4 — B. Verbatim from the Secrets Manager integration page: "Jira and ServiceNow are not currently supported."
5 — C. "Secrets are automatically removed from a data source when the data source is altered in the UI" — any console edit, even cosmetic. A and B aren't documented behaviors; D would have blocked the edit, not broken the refresh.
6 — B. The troubleshooting page: the s3-consumers role is the default for Athena/S3/Federation; the service role is used only "if the s3-consumers-role is not present." Policy went to the inactive role. A, C, D aren't documented mechanisms.
7 — C. The documented remedy is a KMS grant for Decrypt to the Quick Sight role. A grants to the wrong principal and over-broadly; B is surrender, not a fix; D is unrelated to KMS.
8 — B. Athena and S3 are absent from the supported-VPC-sources list — they're authorized via the service roles. All other pairs listed are on the VPC list.
9 — B. SubnetIds: "Minimum number of 2 items. Maximum number of 15." Security groups allow
1–16 (A wrong); the role is a normal IAM role you supply (C wrong); DnsResolvers is optional
(D wrong).
10 — B. Verbatim: the QNI's security group "isn't stateful", so return traffic isn't auto-admitted, and "the destination port number of any inbound return packets is set to a randomly allocated port number." C gets the 2023 date backwards — the docs scope the documented rules to pre-2023 connections and are silent about after; D misstates how NACLs and SGs compose.
11 — B. PARTIALLY_AVAILABLE means part of the connection's capacity is healthy. With ENIs
across ≥2 subnets, some paths work — the classic intermittent failure. A is an auth symptom; C and
D aren't real mechanisms.
12 — C. The requirement is that the DNS name resolve from outside the VPC; DnsResolvers
(Route 53 Resolver inbound endpoints, per the setup page) is the documented answer. A doesn't fix
resolution and worsens security posture; D violates the private-IP requirement.
13 — B. The data-source-limits page: visuals time out at 2 minutes, "not all database drivers react to the 2-minute timeout, for example Amazon Redshift" — queries keep running server-side. Each user retry adds load; the docs tell you to cancel from the Redshift side. The others don't explain both symptoms.
14 — D. URIPrefixes importing a folder of same-format, same-schema files is exactly the
documented use. A fails the .json-extension rule for Quick Sight format; B mixes Redshift-format
keys into a claim about Quick Sight format; C violates "all files… must use the same file format."
15 — B. "TLS 1.2 for MySQL connections requires MySQL version 5.7.28 or higher. For MySQL versions below 5.7.28, Quick Sight falls back to TLS 1.1." No error, no refusal — which is why the DB version is the compliance control.
16 — A. "Amazon Quick authorizes secretsmanager:GetSecretValue access to the secret based on
the API caller's IAM policy, not the IAM service role's policy." The secretsmanager role (B) is
assumed at analysis/dashboard view time.
| Score | Reading |
|---|---|
| 15–16 | Ready to be the person Support escalates to |
| 12–14 | Solid — re-read the lessons behind your misses |
| 9–11 | Re-run the lab; cause each failure you missed |
| < 9 | Re-read lessons 3–5 before touching production |