AWS Certified Machine Learning – SpecialtyData EngineeringHard

A research institution collects genomic sequence data, which is extremely large (petabytes) and highly sensitive. This data is stored in Amazon S3. Due to regulatory compliance, the data must be encrypted at rest and in transit, and access must be strictly controlled with granular permissions, ensuring only authorized researchers can access specific subsets of the data. Furthermore, all access attempts, successful or not, must be logged for auditing purposes. Which combination of AWS security features provides the most comprehensive solution for this scenario?

  1. AIAM policies, S3 Versioning, S3 Replication, and VPC Endpoints.
  2. BS3 Bucket Policies, IAM roles, KMS-managed S3 encryption (SSE-KMS), and AWS CloudTrail.
  3. CS3 Default Encryption (SSE-S3), S3 Block Public Access, and AWS Config.
  4. DS3 object ACLs, IAM users, and S3 Server Access Logging.
Show answer & explanation

Correct answer: B. S3 Bucket Policies, IAM roles, KMS-managed S3 encryption (SSE-KMS), and AWS CloudTrail.

This option provides the most comprehensive security. S3 Bucket Policies and IAM Roles enforce granular access control. KMS-managed S3 encryption (SSE-KMS) ensures data is encrypted at rest with customer-managed keys. AWS CloudTrail logs all API calls and S3 data events, providing a complete audit trail for compliance. This combination addresses encryption, granular access, and auditing requirements effectively.

Why the other options are wrong

  • A. IAM policies are good for access control. S3 Versioning and S3 Replication are for data durability and disaster recovery, not primary security for encryption, granular access, and auditing. VPC Endpoints enhance network security but don't address data-at-rest encryption or comprehensive auditing.
  • C. S3 Default Encryption (SSE-S3) is good but SSE-KMS offers more control over keys. S3 Block Public Access is essential but doesn't cover granular internal access. AWS Config monitors resource configurations, not access logs.
  • D. S3 object ACLs are legacy and less scalable than bucket policies. IAM users are fine, but IAM roles are preferred for temporary, granular access. S3 Server Access Logging provides access logs but CloudTrail offers a more comprehensive audit of API calls and data events.

S3 Data Lake Security

Implementing a multi-layered security strategy for Amazon S3 data lakes, encompassing encryption, access control, and auditing, to protect sensitive data.

  • Encryption at rest (SSE-KMS, SSE-S3) and in transit (TLS).
  • Granular access control (IAM Policies, S3 Bucket Policies).
  • Comprehensive logging and auditing (AWS CloudTrail, S3 Access Logs).
  • Network isolation (VPC Endpoints).
  • Block Public Access for preventing accidental exposure.

Memory trick: KMS encrypts, IAM controls, CloudTrail logs every genome scroll.

More Data Engineering questions