A financial services company builds an analytics solution on Amazon EMR for survey data. Three personas need controlled, least-privilege access: Administrator (provisions EMR clusters), Data engineer (runs ETL), and Data analyst (runs SQL/Hive queries). The personas should only be able to launch approved/authorized applications and all resources they create must be tagged. Which solution enforces these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Service Catalog to control which Amazon EMR versions and cluster configurations can be deployed and to enforce permissions and resource choices for each persona..
Why this is the answer
AWS Service Catalog is the correct solution because it allows the company to create and manage a catalog of approved IT services, including specific Amazon EMR versions and cluster configurations. This directly addresses the requirement for personas to only launch approved/authorized applications. Service Catalog also enables the enforcement of permissions and resource choices for each persona, ensuring least-privilege access. Furthermore, it supports tagging constraints on launched products, fulfilling the requirement for all created resources to be tagged. Creating IAM roles with identity-based policies is essential for access control but doesn't inherently restrict which EMR configurations can be launched or enforce tagging on all resources. Kerberos authentication enhances security but is unrelated to controlling EMR versions, configurations, or tagging. Launching with CloudFormation and using resource-based policies is a good practice for infrastructure as code, but CloudFormation alone doesn't provide the cataloging and enforcement capabilities for approved EMR products that Service Catalog offers.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed