A municipal data lake on S3 serves many departments. Coarse IAM on whole buckets is too blunt for table- and column-level access. Which service should the architect use for fine-grained lake permissions?
Select an answer to reveal the explanation.
Short Explanation
Whole-bucket IAM is a sledgehammer when departments need table-level keys. Lake Formation adds that fine-grained governance on the lake. CloudFront cookies and security groups are not how you authorize Glue/Athena tables.
Full Explanation
AWS Lake Formation provides fine-grained data access governance for lakes, including table- and column-level permissions that complement or refine coarse S3 IAM. CloudFront signed cookies, public website hosting, and security groups (which do not attach to S3 objects) do not deliver lake table governance.