Why Does QuickSight Report Insufficient Permissions for Athena S3 Data?
A data engineer needs to use an Amazon QuickSight dashboard that is based on Amazon Athena queries on data that is stored in an Amazon S3 bucket. When the data engineer connects to the QuickSight dashboard, the data engineer receives an error message that indicates insufficient permissions. Which factors could cause to the permissions-related errors? (Choose two.)
Community Votes
83% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the split between the QuickSight, Athena, and S3 permission layers and the trap of picking E: a completely missing IAM role produces an authentication/authorization failure, not the Athena insufficient-permissions message.
Amazon QuickSight dashboards backed by Athena over S3 fail with insufficient-permissions errors when the QuickSight service role cannot read the S3 bucket (C) or cannot decrypt S3 objects with KMS (D). This guide confirms the two documented causes and explains why a missing IAM role (E) is not the answer.
Many learners choose CE, assuming that if QuickSight has no IAM role it must be the permission problem; however, that yields a different class of error, while the documented causes for Athena insufficient permissions are S3 bucket access (C) and KMS decrypt rights (D).
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
C and D match AWS's documented troubleshooting guidance for Athena insufficient-permissions errors: QuickSight's service role must be able to read the source S3 bucket and the Athena query-results bucket, and if SSE-KMS is used it must have kms:Decrypt on the key. The AWS troubleshooting page cited in the comments lists S3 bucket access and KMS decryption as the two classic causes of this exact message. Community consensus aligns, with rralucard_ explaining that missing S3 read access "would result in an error indicating insufficient permissions" and Christina666 adding that QuickSight needs "explicit S3 permissions" plus decrypt rights. Both C and D therefore describe real, documented permission failures for a QuickSight dashboard over Athena data stored in S3.Why the Other Options Are Wrong
A is wrong because QuickSight has a native Athena connector; a missing connection would prevent data-source creation rather than produce an insufficient-permissions error while querying. B is wrong because uncataloged tables produce a table-or-database-not-found or metadata error in Athena, not a permissions error. E is wrong because an unassigned IAM role is a broader authentication/authorization failure; as fceb2c1 noted, "it will result in authentication/authorization error, not insufficient permission error". QuickSight also automatically provisions the aws-quicksight-service-role-v0 service role, and the scenario's specific error is the Athena insufficient-permissions condition. taka5094's comment that D depends on encryption is a fair caveat, but D remains the documented cause whenever S3 data is encrypted.Community Comment Notes
Most voters selected CD (83 votes) over CE (17 votes), and fceb2c1 cited the AWS troubleshooting page while rejecting E on error-type grounds. rralucard_ and Christina666 both highlighted S3 read access and KMS decrypt as the actual causes, while damaldon and Ousseyni also landed on CD with the same official link. bakarys argued for CE by treating a missing IAM role as the cause, but that describes a broken QuickSight service role rather than the Athena insufficient-permissions condition. taka5094 pointed out that the scenario does not state encryption, which is a reasonable caveat and does not weaken the documented CD answer.Official Reference
Exam Strategy
When a QuickSight question reports 'insufficient permissions' for Athena, scan first for S3 bucket access and KMS decrypt options such as C and D, because those are the AWS-documented causes. Distinguish error types carefully: a missing IAM role or no permissions at all is an authentication/authorization failure, and uncataloged tables yield metadata errors, not this message.
Frequently Asked Questions
Why is 'no IAM role assigned to QuickSight' not the correct answer?
A missing QuickSight service role causes an authentication or authorization failure before Athena queries run, not the specific Athena insufficient-permissions error; QuickSight normally auto-creates aws-quicksight-service-role-v0.
Why does QuickSight need kms:Decrypt for Athena data in S3?
If the S3 objects or Athena query results are encrypted with SSE-KMS, QuickSight's role must have kms:Decrypt and the key policy must allow it, otherwise queries fail with insufficient permissions.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →