Chapter 4 · Data Security and Governance·v2.1.0·Updated 6/14/2026·~8 min
What's changed: In-scope coverage: added network boundary/defense (VPC/PrivateLink/WAF/Shield)
4.2Governance and Compliance (Lake Formation)
Key points
Understand data governance: fine-grained (column/row-level) access management with AWS Lake Formation, auditing with CloudTrail, and classification/data lineage with tags.
A data lake needs fine-grained control over who can access which columns/rows. AWS Lake Formation centralizes this.
4.2.1Lake Formation and auditing
- Lake Formation: centrally grant column/row/cell-level permissions on Glue Data Catalog tables.
- CloudTrail: records who accessed/changed which data and when, for auditing.
- Tags/lineage: classify data (e.g., sensitivity) and track origin/flow (data lineage).
Exam point
Common on DEA: column/row-level fine-grained access = Lake Formation, audit who accessed data = CloudTrail, classification = tags. Lake Formation centralizes permissions over the Glue catalog.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

