← AWS Certified Data Engineer - Associate
AWS · objective · 18% of the exam
Data Security and Governance — AWS Certified Data Engineer - Associate
The official AWS documentation our Data Security and Governance practice questions are cited to. Review the primary sources, then practise.
Official references for this objective
-
Amazon Web Services — Encryption - AWS Prescriptive Guidance
there is no longer a one-to-one match between Amazon S3 object access attempts and API calls to AWS KMS
-
Amazon Web Services — What is AWS Lake Formation? - AWS Lake Formation
data administrators can onboard Lake Formation permissions selectively and incrementally, focusing on one data lake use case at a time
-
Amazon Web Services — Data security and governance - Best Practices for Building a Data Lake on AWS for Games
A common approach is to replace real user identifiers with surrogate ones, store these mappings in a separate table outside of the data lake
-
Amazon Web Services — Define permissions based on attributes with ABAC authorization - AWS Identity and Access Management
The disadvantage to using the traditional RBAC model is that when you or your users add new resources to your environment, you have to update
-
Amazon Web Services — Discovering sensitive data with Macie - Amazon Macie
they can detect credit card numbers, AWS secret access keys, and passport numbers for particular countries and regions
-
Amazon Web Services — Dynamic data masking - Amazon Redshift
You can manipulate how Amazon Redshift shows sensitive data to the user at query time, without transforming it in the database.
-
Amazon Web Services — Sharing a data lake using Lake Formation fine-grained access control - AWS Lake Formation
Grantable permissions are required so admin users in Account B can grant permissions to other users in Account B.