ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 728 - SAA-C03 discussion

Report
Export

A company stores several petabytes of data across multiple AWS accounts The company uses AWS Lake Formation to manage its data lake The company's data science team wants to securely share selective data from its accounts with the company's engineering team for analytical purposes.

Which solution will meet these requirements with the LEAST operational overhead?

A.
Copy the required data to a common account. Create an 1AM access role in that account Grant access by specifying a permission policy that includes users from the engineering team accounts as trusted entities.
Answers
A.
Copy the required data to a common account. Create an 1AM access role in that account Grant access by specifying a permission policy that includes users from the engineering team accounts as trusted entities.
B.
Use the Lake Formation permissions Grant command in each account where the data is stored to allow the required engineering team users to access the data.
Answers
B.
Use the Lake Formation permissions Grant command in each account where the data is stored to allow the required engineering team users to access the data.
C.
Use AWS Data Exchange to privately publish the required data to the required engineering team accounts
Answers
C.
Use AWS Data Exchange to privately publish the required data to the required engineering team accounts
D.
Use Lake Formation tag-based access control to authorize and grant cross-account permissions for the required data to the engineering team accounts
Answers
D.
Use Lake Formation tag-based access control to authorize and grant cross-account permissions for the required data to the engineering team accounts
Suggested answer: D

Explanation:

Understanding the Requirement: The data science team needs to securely share selective data with the engineering team across multiple AWS accounts with minimal operational overhead.

Analysis of Options:

Copy data to a common account: Involves data duplication and increased storage costs, and requires managing additional permissions.

Lake Formation permissions Grant command: This method can be effective but may involve significant operational overhead if managing permissions across multiple accounts and datasets manually.

AWS Data Exchange: Designed for sharing data externally or between organizations, which adds unnecessary complexity for internal sharing within the same organization.

Lake Formation tag-based access control: Provides a scalable and efficient way to manage access permissions based on tags, allowing fine-grained control and simplified management across accounts.

Best Solution:

Lake Formation tag-based access control: This solution meets the requirements with the least operational overhead, allowing efficient management of cross-account permissions and secure data sharing.

AWS Lake Formation

Tag-based access control

asked 16/09/2024
ANDREA SIMONELLI
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first