AWS Training
Modules Listen Certification

← Data Sources and Connectivity

Q1 Quiz — data sources and connectivity

Exam-style. One correct answer each, no partial credit. Answers with explanations at the end.


1. A team asks you to create a Quick Sight data source directly against AWS Glue Data Catalog. What do you do?

2. aws quicksight create-data-source returns HTTP 200 with "CreationStatus": "CREATION_IN_PROGRESS". What is true?

3. Which credential configuration produces the failure COPY_SOURCE_NOT_FOUND?

4. Which two SaaS source types cannot use Secrets Manager credentials?

5. An engineer edits an API-managed data source in the console to fix a typo in its display name. The next scheduled refresh fails with an authentication error. Most likely cause?

6. Both aws-quicksight-s3-consumers-role-v0 and aws-quicksight-service-role-v0 exist in an account. Athena connections fail with insufficient permissions. An S3 policy was added to aws-quicksight-service-role-v0 and nothing changed. Why?

7. Athena data encrypted with a customer KMS key fails from Quick Sight but works in the Athena console. The documented fix is:

8. Which pair of sources is reached through the lesson-3 service roles and not through a VPC connection?

9. CreateVPCConnection rejects your call. You supplied one subnet ID, three security group IDs, and a role ARN. What violated the API contract?

10. Why must the QNI security group's inbound rule allow all TCP ports 0–65535?

11. A VPC connection reports CreationStatus: CREATION_SUCCESSFUL and AvailabilityStatus: PARTIALLY_AVAILABLE. The matching symptom is:

12. A database hostname lives in a Route 53 private hosted zone and only resolves inside the VPC. Which is the documented mechanism to make a Quick Sight VPC connection work?

13. Users report Quick Sight "can't connect" to Redshift; the DBA reports the cluster is suddenly slow. Visuals use direct query. The most likely mechanism is:

14. Which manifest is valid for a Quick Sight-format S3 import?

15. Your security baseline requires TLS 1.2 to an Aurora MySQL source. Engine version is 5.7.21. What actually happens, per the docs?

16. For creating a data source with a SecretArn, whose permissions authorize secretsmanager:GetSecretValue at creation time?


Answers and explanations

1 — B. There is no Glue Type in the 38-value enum. The user guide's own list says Glue Data Catalog is "accessed using AWS Glue data catalog compatible services, such as Athena or Redshift Spectrum." A and C invent an enum value; D works but abandons the catalog and live queries.

2 — B. Creation is asynchronous; the 200 acknowledges the request. Connection testing resolves later into CREATION_SUCCESSFUL/CREATION_FAILED — read it with DescribeDataSource. A and D claim validations that haven't happened; C retries a non-idempotent create (you'd hit ResourceExistsException).

3 — C. COPY_SOURCE_NOT_FOUND is the borrowing chain breaking. A deleted secret (A) fails as an access/auth error; B as authentication; D as a KMS/decrypt failure.

4 — B. Verbatim from the Secrets Manager integration page: "Jira and ServiceNow are not currently supported."

5 — C. "Secrets are automatically removed from a data source when the data source is altered in the UI" — any console edit, even cosmetic. A and B aren't documented behaviors; D would have blocked the edit, not broken the refresh.

6 — B. The troubleshooting page: the s3-consumers role is the default for Athena/S3/Federation; the service role is used only "if the s3-consumers-role is not present." Policy went to the inactive role. A, C, D aren't documented mechanisms.

7 — C. The documented remedy is a KMS grant for Decrypt to the Quick Sight role. A grants to the wrong principal and over-broadly; B is surrender, not a fix; D is unrelated to KMS.

8 — B. Athena and S3 are absent from the supported-VPC-sources list — they're authorized via the service roles. All other pairs listed are on the VPC list.

9 — B. SubnetIds: "Minimum number of 2 items. Maximum number of 15." Security groups allow 1–16 (A wrong); the role is a normal IAM role you supply (C wrong); DnsResolvers is optional (D wrong).

10 — B. Verbatim: the QNI's security group "isn't stateful", so return traffic isn't auto-admitted, and "the destination port number of any inbound return packets is set to a randomly allocated port number." C gets the 2023 date backwards — the docs scope the documented rules to pre-2023 connections and are silent about after; D misstates how NACLs and SGs compose.

11 — B. PARTIALLY_AVAILABLE means part of the connection's capacity is healthy. With ENIs across ≥2 subnets, some paths work — the classic intermittent failure. A is an auth symptom; C and D aren't real mechanisms.

12 — C. The requirement is that the DNS name resolve from outside the VPC; DnsResolvers (Route 53 Resolver inbound endpoints, per the setup page) is the documented answer. A doesn't fix resolution and worsens security posture; D violates the private-IP requirement.

13 — B. The data-source-limits page: visuals time out at 2 minutes, "not all database drivers react to the 2-minute timeout, for example Amazon Redshift" — queries keep running server-side. Each user retry adds load; the docs tell you to cancel from the Redshift side. The others don't explain both symptoms.

14 — D. URIPrefixes importing a folder of same-format, same-schema files is exactly the documented use. A fails the .json-extension rule for Quick Sight format; B mixes Redshift-format keys into a claim about Quick Sight format; C violates "all files… must use the same file format."

15 — B. "TLS 1.2 for MySQL connections requires MySQL version 5.7.28 or higher. For MySQL versions below 5.7.28, Quick Sight falls back to TLS 1.1." No error, no refusal — which is why the DB version is the compliance control.

16 — A. "Amazon Quick authorizes secretsmanager:GetSecretValue access to the secret based on the API caller's IAM policy, not the IAM service role's policy." The secretsmanager role (B) is assumed at analysis/dashboard view time.

Scoring

Score Reading
15–16 Ready to be the person Support escalates to
12–14 Solid — re-read the lessons behind your misses
9–11 Re-run the lab; cause each failure you missed
< 9 Re-read lessons 3–5 before touching production