List of questions
Related questions
Question 54 - DEA-C01 discussion
A company has five offices in different AWS Regions. Each office has its own human resources (HR) department that uses a unique IAM role. The company stores employee records in a data lake that is based on Amazon S3 storage.
A data engineering team needs to limit access to the records. Each HR department should be able to access records for only employees who are within the HR department's Region.
Which combination of steps should the data engineering team take to meet this requirement with the LEAST operational overhead? (Choose two.)
Use data filters for each Region to register the S3 paths as data locations.
Register the S3 path as an AWS Lake Formation location.
Modify the IAM roles of the HR departments to add a data filter for each department's Region.
Enable fine-grained access control in AWS Lake Formation. Add a data filter for each Region.
Create a separate S3 bucket for each Region. Configure an IAM policy to allow S3 access. Restrict access based on Region.
0 comments
Leave a comment first