AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data analytics platform uses Amazon Athena to query data stored in S3. The company needs to implement fine-grained access control such that different teams can only query specific rows of data based on their department ID, which is a column in the dataset. This must be enforced at query time without duplicating data or modifying the underlying S3 objects. Which AWS service or feature should be used?

  1. AAmazon Athena workgroups with data catalog filters
  2. BS3 bucket policies with conditional access
  3. CAWS Lake Formation row-level security
  4. DAWS Glue Data Catalog with resource-based policies
Show answer & explanation

Correct answer: C. AWS Lake Formation row-level security

AWS Lake Formation's row-level security feature allows filtering data at query time based on conditions (e.g., department ID) without modifying the source data. When Athena queries data registered in Lake Formation, these row-level filters are applied, ensuring users only see authorized rows.

Why the other options are wrong

  • A. Athena workgroups provide query isolation and cost control, but they do not inherently offer row-level security or data catalog filters for dynamic row filtering.
  • B. S3 bucket policies operate at the object level, not the row level, and cannot dynamically filter rows based on column values within an object.
  • D. AWS Glue Data Catalog stores metadata, and while it supports resource-based policies, these are for access to metadata, not for dynamic row-level filtering of data within objects during a query.

Lake Formation Row-Level Security

AWS Lake Formation row-level security allows data engineers to define policies that restrict access to specific rows in a table based on conditions, applied dynamically at query time.

  • Filters data based on column values (predicates)
  • Enforced at query time by integrated services like Athena
  • Does not modify the underlying data in S3

Memory trick: Lake Formation's rows filter data for team access.

More Data Governance and Security questions