A company maintains a data lake on AWS that ingests datasets from various business units. The storage is in Amazon S3, and the AWS Glue Data Catalog stores metadata. Analysts use Amazon Athena to run queries. The company needs to enforce fine-grained, column-level access controls for Athena based on user roles. Which approach satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Set up AWS Lake Formation. Define security policy-based rules for the users and applications by IAM role in Lake Formation..
Why this is the answer
AWS Lake Formation is specifically designed to simplify building, securing, and managing data lakes, providing fine-grained access control down to the column and row level. By defining security policies in Lake Formation based on IAM roles, the company can enforce the required column-level access for Athena users. Defining IAM policies directly on Glue tables (resource-based or identity-based) does not provide the necessary column-level granularity for Athena queries. IAM policies can grant or deny access to entire tables or databases but cannot restrict access to specific columns within a table. AWS Resource Access Manager (RAM) is used for sharing resources across AWS accounts or within an organization, not for defining fine-grained access control within a single account's data lake.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed