A data engineering team is setting up a new data governance framework for their machine learning platform. A critical requirement is to ensure that all data access requests to sensitive datasets in Amazon S3 are subject to approval workflows, and that data usage adheres to strict compliance policies. Furthermore, they need to track who accessed what data, when, and for what purpose, across different analytics and ML services. Which AWS service combination provides the necessary capabilities for granular access control, approval workflows, and comprehensive auditing?
- AAWS Lake Formation, AWS Single Sign-On (SSO), and AWS Config.
- BAmazon Macie, AWS Resource Access Manager (RAM), and S3 Access Logs.
- CAWS IAM, S3 Bucket Policies, and AWS CloudTrail.
- DAWS Lake Formation, AWS Glue Data Catalog, and AWS CloudTrail.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Lake Formation, AWS Glue Data Catalog, and AWS CloudTrail.
AWS Lake Formation provides a centralized control plane for managing data access permissions, including granular, table-level, and column-level access to data stored in S3 and registered with the AWS Glue Data Catalog. It integrates with approval workflows. The AWS Glue Data Catalog is essential for defining the schemas and locations of the sensitive datasets. AWS CloudTrail logs all API calls, including Lake Formation actions and S3 data events, providing comprehensive auditing for compliance.
Why the other options are wrong
- A. AWS Lake Formation is excellent for granular access and governance. AWS SSO manages user identities but doesn't directly provide the governance and auditing layer for data. AWS Config tracks resource configurations, not access logs or approval workflows.
- B. Amazon Macie is for data discovery and sensitive data identification, not access control or governance workflows. AWS RAM shares resources but doesn't manage granular data access. S3 Access Logs are useful but less comprehensive for auditing all governance-related actions than CloudTrail.
- C. While IAM and S3 Bucket Policies provide access control, they lack the granular (table/column level) control and built-in approval workflows offered by Lake Formation for data lakes. CloudTrail is good for auditing but needs the underlying access control mechanisms.
AWS Data Governance with Lake Formation
Establishing and enforcing policies for data access, usage, and auditing within a data lake, primarily using AWS Lake Formation for centralized control.
- AWS Lake Formation for centralized, granular access control.
- Integrates with AWS Glue Data Catalog for metadata.
- Supports table-, column-, and row-level permissions.
- Provides approval workflows for data access.
- AWS CloudTrail for comprehensive auditing of data access and governance actions.
Memory trick: Lake Formation governs, Glue catalogs, CloudTrail audits all data logs.