AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data engineer is designing an access control strategy for a new data lake built on Amazon S3 and AWS Lake Formation. The requirement is to grant different data analysts access to specific columns within a table, while redacting sensitive Personally Identifiable Information (PII) columns for a subset of analysts. The underlying data in S3 must remain unchanged. Which Lake Formation feature should be used to achieve this fine-grained, dynamic control?

  1. ARow-level security with encryption at rest
  2. BTable-level permissions and S3 bucket policies
  3. CColumn-level permissions with data filters
  4. DResource-linked access control and AWS Glue Data Catalog
Show answer & explanation

Correct answer: C. Column-level permissions with data filters

AWS Lake Formation's column-level permissions, combined with data filters, allow granting access to specific columns while dynamically redacting or masking other sensitive columns (like PII) at query time. This meets the requirement for fine-grained, dynamic control without altering the source data in S3.

Why the other options are wrong

  • A. Row-level security filters rows, not columns. Encryption at rest secures data but doesn't dynamically redact specific columns for different users at query time.
  • B. Table-level permissions grant access to the entire table, not specific columns, and S3 bucket policies are for object-level access, not column or redaction.
  • D. Resource-linked access control is part of Lake Formation for cross-account access, but it doesn't directly provide dynamic column redaction. AWS Glue Data Catalog is for metadata, not access enforcement.

Lake Formation Column-Level Security & Data Filters

AWS Lake Formation provides column-level security to restrict access to specific columns, and data filters can dynamically mask or redact sensitive columns at query time for different users.

  • Grant access to a subset of columns in a table
  • Data filters allow dynamic redaction/masking on sensitive columns
  • Enforced at query time without modifying source data

Memory trick: Columns and filters redact PII dynamically.

More Data Governance and Security questions