A company has five offices in different AWS Regions. Each office's HR team uses a distinct IAM role. Employee records are stored in an Amazon S3–based data lake. The data engineering team must restrict each HR department so it can access only records for employees in that department's Region. Which combination of actions provides this with the least operational overhead? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Register the S3 path as an AWS Lake Formation location., Enable fine-grained access control in AWS Lake Formation. Add a data filter for each Region..
Why this is the answer
The correct options leverage AWS Lake Formation for fine-grained access control, which is designed for this exact scenario with minimal operational overhead. Registering the S3 path as a Lake Formation location (correct option 2) integrates the data lake with Lake Formation's security model. Enabling fine-grained access control and adding data filters for each Region (correct option 4) allows you to define specific access rules based on data characteristics, such as the Region embedded in the S3 path, without modifying IAM roles directly for each filter. Incorrect options: Using data filters to register S3 paths is not a standard Lake Formation action; registration is a prerequisite. Modifying IAM roles for each department and Region would be operationally intensive and less scalable than Lake Formation's centralized data filtering. Creating separate S3 buckets for each Region is inefficient, increases storage management overhead, and doesn't scale well for fine-grained access within a data lake.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed