AWS Certified Solutions Architect Professional AWS Certified Solutions Architect Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A multinational financial services firm is migrating its customer data lake to AWS. The data lake resides in Amazon S3 and contains sensitive Personally Identifiable Information (PII) and financial transaction records. Several internal teams require access: a development team for schema evolution and testing, an analytics team for business intelligence reporting, and a security operations team for auditing and incident response. Adherence to stringent financial regulations (e.g., PCI DSS, SOX) mandates robust access control, the principle of least privilege, and comprehensive audit trails for all data access. The firm needs a solution that allows for distinct, fine-grained permissions at the table and column level, while ensuring all data access events are logged for compliance. Which architectural approach best satisfies these requirements?

Implement AWS Lake Formation to manage data catalog and permissions, granting specific IAM roles to each team with granular table and column-level access controls defined within Lake Formation, and configure AWS CloudTrail for comprehensive auditing of all AWS API calls and data access events.
Create separate Amazon S3 buckets for each team, utilizing complex S3 bucket policies to restrict access to specific prefixes and object types, and rely solely on S3 access logs for auditing purposes.
Grant a single, broad IAM role with read and write permissions to the entire S3 data lake bucket to all three teams, and enable S3 server access logging for auditing.
Utilize AWS Glue Data Catalog to define schemas and grant read-only access to all tables via IAM policies directly attached to the respective team IAM roles, without implementing column-level security.

About the AWS Certified Solutions Architect Professional AWS Certified Solutions Architect Professional Certification

These free practice questions are designed to help you assess your readiness for the AWS Certified Solutions Architect Professional AWS Certified Solutions Architect Professional exam by Amazon. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.