An organization has an Amazon Redshift cluster accessed by over 100 users with different IAM roles. The organization needs to control access to database objects based on users' job roles, permissions, and data sensitivity. Which feature should be used to meet this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Use the role-based access control (RBAC) feature of Amazon Redshift..
Why this is the answer
Role-based access control (RBAC) is the correct choice because it allows you to define permissions for groups of users (roles) and then assign those roles to individual users or IAM roles. This directly addresses the requirement to control access to database objects based on users' job roles and permissions. Row-level security (RLS) restricts which rows a user can see, and column-level security (CLS) restricts which columns a user can see; both are too granular for controlling access to entire database objects based on job roles. Dynamic data masking policies obscure sensitive data values, which is different from controlling access to the objects themselves.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed