AWS Certified Data Engineer – AssociateData Governance and SecurityMedium

A healthcare provider is migrating patient data to an Amazon S3 data lake. The data contains Protected Health Information (PHI) and must comply with HIPAA regulations. The security team requires that all PHI be masked for non-production environments and for analytics users who do not require direct access to sensitive identifiers. Which AWS service or feature can be used to implement dynamic data masking for sensitive columns without altering the source data?

  1. AAWS Lake Formation data filters
  2. BAmazon Macie data classification
  3. CAWS Glue Data Catalog table properties
  4. DAmazon Redshift Spectrum external tables
Show answer & explanation

Correct answer: A. AWS Lake Formation data filters

AWS Lake Formation's data filters allow column-level and row-level access control, including transformations to mask or redact sensitive data dynamically when queried, without modifying the underlying S3 objects. This directly addresses the requirement for dynamic data masking for PHI.

Why the other options are wrong

  • B. Amazon Macie is a data security and privacy service that discovers and classifies sensitive data, but it does not perform dynamic data masking.
  • C. Glue Data Catalog table properties store metadata, but do not provide dynamic data masking capabilities.
  • D. Redshift Spectrum allows querying data in S3, but it does not inherently offer dynamic data masking features for external tables; masking would need to be implemented within Redshift itself or upstream.

AWS Lake Formation Data Filters

AWS Lake Formation data filters provide fine-grained access control to data lake resources, including column-level and row-level filtering and dynamic data masking.

  • Control access to specific columns or rows
  • Mask or redact sensitive data dynamically at query time
  • Applied to various AWS analytics services like Athena, Redshift Spectrum, EMR

Memory trick: Lake Formation filters mask data for PHI protection.

More Data Governance and Security questions