AWS Certified Data Engineer – AssociateData Governance and SecurityHard
A global pharmaceutical company is building a data lake on AWS S3 to store sensitive clinical trial data. The company needs to enforce strict access control, ensuring that data scientists can only query specific columns of a dataset (e.g., patient ID, drug dosage) and only rows pertaining to trials they are authorized for. The solution must integrate seamlessly with Amazon Athena, which is used for querying the data lake. Which AWS service is best suited to implement this fine-grained access control for S3 data queried by Athena?
- AAWS Lake Formation
- BIAM Policies on S3 buckets
- CAWS Organizations Service Control Policies (SCPs)
- DS3 Access Points with object-level ACLs
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Lake Formation
AWS Lake Formation allows for fine-grained access control at the table, column, and row level for data in S3 that is registered with Lake Formation. It integrates directly with query services like Amazon Athena, enabling the specified column and row-level restrictions based on user permissions.
Why the other options are wrong
- B. IAM policies on S3 buckets provide bucket-level or prefix-level access, but not fine-grained column or row-level control for data within files.
- C. AWS Organizations SCPs apply broad permissions across accounts and services but are not designed for fine-grained data access control within a data lake table interrogated by Athena.
- D. S3 Access Points simplify access to S3, and object-level ACLs provide object-level permissions, but neither offers column or row-level filtering within files.
AWS Lake Formation Fine-Grained Access
AWS Lake Formation provides centralized, fine-grained access control for data lakes, allowing permissions to be defined at the database, table, column, and row level for data stored in S3 and queried by services like Athena.
- Centralized permissions management for data lake resources.
- Supports column-level and row-level security.
- Integrates with query engines like Amazon Athena and Amazon Redshift Spectrum.
Memory trick: Lake Formation: Level-Up Data Access Control.