Question 1 · choose 1
A table in the AWS Glue Data Catalog is governed by AWS Lake Formation and queried with Amazon Athena. Analysts must be able to query every column except ssn and salary, while the HR team sees all columns. The data is stored in the same Parquet files. What should a data engineer do?
- AGrant SELECT in Lake Formation with ssn and salary excluded
- BAdd an S3 bucket policy that denies the analysts access to the ssn and salary data
- CCreate an Athena view without the two columns and ask analysts to query the view
- DEncrypt the ssn and salary data with SSE-KMS and withhold the key from analysts
Show the answer and why
AGrant SELECT in Lake Formation with ssn and salary excluded
Correct
Lake Formation grants on a table can be limited to specific columns, so analysts see only the columns they are granted while HR keeps full access.
BAdd an S3 bucket policy that denies the analysts access to the ssn and salary data
Incorrect
Bucket policies work on objects and prefixes. The columns sit inside the same Parquet files as the allowed columns.
CCreate an Athena view without the two columns and ask analysts to query the view
Incorrect
A view is a stored query. If the analysts still have access to the table, they can query the columns directly.
DEncrypt the ssn and salary data with SSE-KMS and withhold the key from analysts
Incorrect
SSE-KMS encrypts whole objects. It cannot hide two columns inside a file that analysts must otherwise read.
Column-level security in a lake is a catalog permission, not a storage setting: Lake Formation filters the columns before Athena returns results.
AWS documentation
- Granting permissions on Data Catalog resources (opens in a new tab)
- Data filtering and cell-level security in Lake Formation (opens in a new tab)
- Controlling access from VPC endpoints with bucket policies (opens in a new tab)
- Work with views (opens in a new tab)
- Using server-side encryption with AWS KMS keys (SSE-KMS) (opens in a new tab)