AWS Certified Data Engineer – AssociateData Governance and SecurityHard

A data engineer is tasked with securing an Amazon Redshift cluster. The company policy requires that all data access from applications must use temporary credentials, and these credentials should be automatically rotated. Additionally, access to specific tables within Redshift must be restricted based on the application's role. Which set of AWS services and features should the data engineer use?

  1. AAWS Secrets Manager for credentials, IAM Identity Center for users, and Redshift row-level security.
  2. BIAM roles for Redshift, IAM policies, and Redshift user groups.
  3. CAWS Secrets Manager for credentials, IAM roles for Redshift, and Redshift table permissions.
  4. DIAM roles with federated access, AWS Lambda for rotation, and Redshift column-level security.
Show answer & explanation

Correct answer: C. AWS Secrets Manager for credentials, IAM roles for Redshift, and Redshift table permissions.

AWS Secrets Manager can be used to store and automatically rotate database credentials, providing temporary credentials. IAM roles for Redshift allow applications to assume a role to connect to Redshift without long-lived credentials. Redshift table permissions (GRANT/REVOKE) allow fine-grained access control to specific tables, meeting all requirements.

Why the other options are wrong

  • A. IAM Identity Center is for workforce identity, not direct application credential management or rotation for database users. Redshift row-level security is for rows, not tables, and is more complex than needed if only table-level restriction is required.
  • B. IAM roles for Redshift and IAM policies are good for authentication but don't inherently provide automatic credential rotation for database users. Redshift user groups manage permissions but not temporary credentials.
  • D. While Lambda can be used for custom rotation, Secrets Manager provides this natively. Column-level security is for columns, not tables, and is more specific than the 'specific tables' requirement.

Redshift Security Best Practices

Securing Redshift involves using temporary credentials, IAM roles for authentication, and fine-grained permissions within Redshift to control data access.

  • Use AWS Secrets Manager for database credential rotation
  • Utilize IAM roles for Redshift authentication for applications
  • Apply Redshift's internal permissions (GRANT/REVOKE) for table-level access control

Memory trick: Secrets for rotation, IAM for roles, Redshift for tables.

More Data Governance and Security questions