A company uses a data mesh with a central governance account and AWS Lake Formation for cataloging and sharing. A new data product contains Amazon Redshift Serverless tables. The marketing team must receive access to only a subset of columns, and the compliance team must receive a different subset. Which combination of steps should a data engineer take to achieve this? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create an Amazon Redshift data share that includes the tables to be shared., Share the Amazon Redshift data share to the Lake Formation catalog in the governance account..
Why this is the answer
To share Amazon Redshift Serverless tables with column-level granularity in a data mesh architecture using Lake Formation, the data engineer should first create an Amazon Redshift data share. This share will encapsulate the tables intended for sharing. Next, this Redshift data share needs to be shared with the Lake Formation catalog in the central governance account. This step integrates the Redshift data share into the Lake Formation permission model, allowing Lake Formation to manage access. Once integrated, Lake Formation can then be used to grant column-level permissions to different teams (marketing and compliance) on the shared Redshift tables. Creating views for column-level access is a valid strategy within Redshift but doesn't directly leverage Lake Formation's centralized governance for cross-account sharing in a data mesh. Creating a Redshift managed VPC endpoint is for network connectivity, not for defining data access permissions. Sharing the data share directly to a Redshift Serverless workgroup in another account bypasses Lake Formation's centralized permission management, which is crucial for a data mesh.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed