A data lake on Amazon S3 contains records with personally identifiable information (PII). Multiple user groups need access to the raw data but must be restricted to only the PII fields they require. Which approach provides the required column-level access control with the least effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Athena to query the data. Set up AWS Lake Formation and create data filters to establish levels of access for the company's IAM roles. Assign each user to the IAM role that matches the user's PII access requirements..
Why this is the answer
This option is correct because AWS Lake Formation is specifically designed to manage fine-grained access control, including column-level security, for data lakes built on Amazon S3. By integrating with Amazon Athena, Lake Formation allows you to define data filters based on IAM roles, ensuring users only see the PII fields they are authorized for with minimal administrative overhead. Amazon QuickSight can provide column-level security, but it's a visualization tool, not the primary mechanism for raw data access control in a data lake. It would still rely on an underlying service like Lake Formation for robust, centralized governance. Building a custom UI is a high-effort solution that duplicates functionality already offered by AWS services. While IAM roles and identity-based policies are fundamental for access control, directly managing column-level access within IAM policies for a data lake is complex and less efficient than using Lake Formation, which abstracts this complexity and integrates with query engines like Athena.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed