AWS Certified Data Engineer Associate DEA-C01 Practice Question
An analytics team in Account A must query customer tables stored as Parquet files in several Amazon S3 buckets that belong to Account B. Analysts should see only the rows for the sales region they cover. Queries will run from Amazon Athena and Amazon Redshift Spectrum. Which Lake Formation configuration in Account B meets these security and access requirements while minimizing operational overhead?
Use S3 bucket policies that restrict access to region-specific prefixes and create IAM roles that analysts in Account A assume to access those prefixes.
Register the S3 locations with Lake Formation, create a Data Filter for each region, grant SELECT permission on the tables using the appropriate filter, and share the governed tables and filters with Account A through AWS Resource Access Manager.
Register the S3 locations, create LF-Tags for each region, grant LF-Tag permissions to Account A, and rely on LF-Tags to provide row-level security.
Copy each region's data into separate S3 buckets, create region-specific Athena workgroups, and restrict workgroup membership with IAM policies.
Registering the S3 locations with Lake Formation enables centralized governance over the data. Lake Formation Data Filters can enforce row-level security by restricting query results to rows that match a regional filter expression. When the governed tables-and the associated Data Filters-are shared with Account A through AWS Resource Access Manager, analysts can query the data in Athena or Redshift Spectrum, and Lake Formation automatically applies the correct filter. The alternative options either rely on S3 or IAM policies that cannot provide row-level security, duplicate datasets, or use views that can be bypassed, so they do not satisfy the requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Lake Formation?
Open an interactive chat with Bash
What are Data Filters in AWS Lake Formation?
Open an interactive chat with Bash
How does AWS Resource Access Manager work with Lake Formation?
Open an interactive chat with Bash
What are Lake Formation Data Filters, and how do they enforce row-level security?
Open an interactive chat with Bash
How does AWS Resource Access Manager (RAM) enable cross-account sharing in this scenario?
Open an interactive chat with Bash
Why are S3 bucket policies and IAM roles insufficient for row-level security in this use case?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Store Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .