Several teams must read the same Amazon S3 lake tables for feature work, and the data engineer wants a catalog-level permission model rather than a thicket of raw bucket policies. Which Domain 1 service pair fits?
Select an answer to reveal the explanation.
Short Explanation
Think of several teams reading the same S3 lake tables, and the engineer is tired of raw bucket-policy thickets. AWS Lake Formation plus the Glue Data Catalog gives table-level grants. That is still Domain 1 ingest, not a Domain 4 VPC project.
Full Explanation
AWS Lake Formation with the Glue Data Catalog catalogs tables and grants table-level access for ML ingest consumers. Raw bucket-policy thickets and vision APIs are not that model. This item stays in Domain 1 ingest, not Domain 4 network security.