ETExamTower
Q9Data Security and Governance

A company uses Amazon Athena for one-time queries against data that is in Amazon S3. The company has several use cases. The company must implement permission controls to separate query processes and access to query history among users, teams, and applications that are in the same AWS account. Which solution will meet these requirements?

← → navigate · a answer
Community votes
B
100% (6)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 6
B 18
Selected Answer: B Haha, they copied this from the old DA Specialty. It's B https://docs.aws.amazon.com/athena/latest/ug/user-created-workgroups.html
16
B. Create an Athena workgroup for each use case. Add tags to the workgroup. Create an IAM policy that uses the tags to apply the right permissions to the workgroup. Explanation: Athena workgroups let you isolate and manage different workloads, users, and permissions. By creating a separate workgroup for each use case, you can control access to query history, manage permissions, and enforce resource usage limits independently for each workload. Applying tags to workgroups lets you categorize and organize them by use case, which makes policy management simpler.
B 2
Selected Answer: B The only other answer that's confusing is C, but it's not the one. Creating separate IAM roles for each use case and linking them with Athena would not give the needed isolation and access control for query processes and query history.
B 2
Selected Answer: B B is correct.
B 1
Selected Answer: B B is more granular
B 1
Selected Answer: B B is correct