AWS Certified Data Engineer – AssociateData Governance and SecurityHard
A data analytics platform uses Amazon Athena to query data stored in S3. The company needs to implement fine-grained access control such that different teams can only query specific rows of data based on their department ID, which is a column in the dataset. This must be enforced at query time without duplicating data or modifying the underlying S3 objects. Which AWS service or feature should be used?
- AAmazon Athena workgroups with data catalog filters
- BS3 bucket policies with conditional access
- CAWS Lake Formation row-level security
- DAWS Glue Data Catalog with resource-based policies
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Lake Formation row-level security
AWS Lake Formation's row-level security feature allows filtering data at query time based on conditions (e.g., department ID) without modifying the source data. When Athena queries data registered in Lake Formation, these row-level filters are applied, ensuring users only see authorized rows.
Why the other options are wrong
- A. Athena workgroups provide query isolation and cost control, but they do not inherently offer row-level security or data catalog filters for dynamic row filtering.
- B. S3 bucket policies operate at the object level, not the row level, and cannot dynamically filter rows based on column values within an object.
- D. AWS Glue Data Catalog stores metadata, and while it supports resource-based policies, these are for access to metadata, not for dynamic row-level filtering of data within objects during a query.
Lake Formation Row-Level Security
AWS Lake Formation row-level security allows data engineers to define policies that restrict access to specific rows in a table based on conditions, applied dynamically at query time.
- Filters data based on column values (predicates)
- Enforced at query time by integrated services like Athena
- Does not modify the underlying data in S3
Memory trick: Lake Formation's rows filter data for team access.