AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A healthcare organization is building a data lake on AWS S3 to store patient records. Due to strict HIPAA compliance requirements, all access to the data lake must be authenticated and authorized, with access policies centrally managed and auditable. Which AWS service is best suited for managing fine-grained data access permissions to the S3 data lake?
- AAmazon S3 Bucket Policies
- BAWS Lake Formation
- CAWS Organizations
- DAWS Identity and Access Management (IAM)
Show answer & explanationAnswer & explanation
Correct answer: B. AWS Lake Formation
AWS Lake Formation is specifically designed to centralize and simplify the management of fine-grained access control to data lakes built on S3, integrating with services like Athena and Redshift Spectrum. It allows for table, column, row, and cell-level security.
Why the other options are wrong
- A. S3 bucket policies provide object-level permissions but become complex and difficult to manage for fine-grained access across a large data lake with varying data sensitivities.
- C. AWS Organizations helps manage multiple AWS accounts but does not provide data access control within a single data lake.
- D. IAM manages user and role permissions but doesn't provide fine-grained data-level access control within a data lake without extensive manual policy creation.
AWS Lake Formation
AWS Lake Formation is a service that makes it easy to build, secure, and manage data lakes by simplifying the process of collecting, cleaning, and cataloging data and providing centralized access control.
- Centralized data lake access management.
- Fine-grained permissions (table, column, row, cell).
- Integrates with S3, Athena, Redshift Spectrum.
Memory trick: Lake Formation for Fine-Grained Protection