AWS Certified Data Engineer – AssociateData Governance and SecurityHard
An analytics team uses Amazon Athena to query data stored in an S3 data lake. The data contains personally identifiable information (PII) that must be protected. The security team requires that access to specific sensitive columns be restricted based on the user's department, meaning users from the 'Marketing' department should not see 'Salary' data, but 'HR' users should. How can a data engineer implement this fine-grained column-level access control for Athena users querying S3 data?
- AImplement S3 Object ACLs to restrict access to objects containing sensitive columns.
- BCreate separate S3 buckets with different IAM policies for each department.
- CUse AWS Lake Formation with column-level permissions on Glue Data Catalog tables.
- DEncrypt sensitive columns in S3 using KMS and manage key access via IAM.
Show answer & explanationAnswer & explanation
Correct answer: C. Use AWS Lake Formation with column-level permissions on Glue Data Catalog tables.
AWS Lake Formation is specifically designed for fine-grained access control in data lakes. By integrating with the Glue Data Catalog, it allows defining column-level permissions on tables. When Athena queries these tables, Lake Formation enforces these permissions, ensuring that users only see the columns they are authorized for, based on their department.
Why the other options are wrong
- A. S3 Object ACLs provide object-level permissions, not granular column-level control within an object, and are difficult to manage at scale for data lake scenarios.
- B. Creating separate S3 buckets and IAM policies for every permutation of department and data sensitivity is complex, prone to error, and leads to data duplication or fragmentation.
- D. Encrypting columns with KMS and managing key access via IAM is a valid encryption strategy, but it does not inherently provide data masking or column-level filtering for queries without complex custom application logic.
Lake Formation Column-Level Security
AWS Lake Formation enables column-level security for data lake tables in the Glue Data Catalog, allowing administrators to specify which columns individual users or roles can query, effectively masking sensitive data from unauthorized departments.
- Fine-grained access control for data lakes.
- Integrates with Glue Data Catalog and Athena.
- Restricts access to specific columns.
- Simplifies compliance and data privacy.
Memory trick: Lake Forms Column Limits