QuestionQ151

Data Security and Governance

A company is configuring a new Amazon SageMaker Unified Studio domain. Each business unit requires isolated control of its own assets, projects, and metadata. Certain datasets must be shareable with other business units after approval. The company also needs centralized user authentication and identity mapping.

Which solution meets these requirements?

  • A Configure each business unit as a domain unit with delegated ownership and fine-grained permissions policies. Give users the ability to share assets across domain units with explicit access control. Assign API keys to users for authentication to access the domain portal.
  • B Configure business units as separate domain units with owner permissions. Restrict projects exclusively to owners to prevent data sharing between domains. Configure AWS IAM Identity Center for centralized authentication. Map user profiles to their respective domain units.
  • C Configure business units to be represented as separate domains. Establish isolated environments with no shared administrative policies. Configure AWS IAM Identity Center for centralized authentication. Delegate administration at the domain level.
  • D Configure each business unit as a separate domain unit to manage permissions on assets, projects, and metadata. Configure AWS IAM Identity Center for centralized authentication. Map user profiles to their respective domain units. Enable cross-business unit sharing through access requests. Instruct domain unit owners to approve or deny the requests.
Explanation

Amazon SageMaker Unified Studio domain units organize assets and domain entities by business unit while delegating authority to domain-unit owners. IAM Identity Center provides centralized authentication and user management. Users can discover assets across domain units and submit access requests; an authorized owner can approve or reject the request, enabling governed cross-business-unit sharing.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!