Give each application an S3 Object Lambda access point that redacts data as objects are retrieved

Answer Correct answer: D — give each application an S3 Object Lambda access point whose Lambda function redacts the data on retrieval.

A company is launching an application that stores raw data in an Amazon S3 bucket. Three applications need to access the data to generate reports. The data must be redacted differently for each application before the applications can access the data. Which solution will meet these requirements?

  1. Create an S3 bucket for each application. Configure S3 Same-Region Replication (SRR) from the raw data's S3 bucket to each application's S3 bucket. Configure each application to consume data from its own S3 bucket.
  2. Create an Amazon Kinesis data stream. Create an AWS Lambda function that is invoked by object creation events in the raw data’s S3 bucket. Program the Lambda function to redact data for each application. Publish the data on the Kinesis data stream. Configure each application to consume data from the Kinesis data stream.
  3. For each application, create an S3 access point that uses the raw data's S3 bucket as the destination. Create an AWS Lambda function that is invoked by object creation events in the raw data's S3 bucket. Program the Lambda function to redact data for each application. Store the data in each application's S3 access point. Configure each application to consume data from its own S3 access point.
  4. Create an S3 access point that uses the raw data’s S3 bucket as the destination. For each application, create an S3 Object Lambda access point that uses the S3 access point. Configure the AWS Lambda function for each S3 Object Lambda access point to redact data when objects are retrieved. Configure each application to consume data from its own S3 Object Lambda access point Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

S3 Object Lambda access points run an AWS Lambda function on each GET request, which is the only option that applies a per-consumer transformation at read time without duplicating data (D). Option A replicates the same raw objects into three buckets, producing no redaction at all, and option C writes redacted copies through an ordinary access point, which stores one fixed redaction rather than a per-application one and still requires an event-driven copy step. Option B funnels every application through one shared Kinesis stream, so per-consumer redaction is impossible there.

Because the raw data must be redacted differently for each of the three reporting applications, each application needs its own on-read transformation. Create an S3 access point on the raw-data bucket, then for each application create an S3 Object Lambda access point backed by that access point with its own Lambda function that performs the application-specific redaction during retrieval. Each application then reads through its own Object Lambda access point and receives data redacted exactly as it requires, with the raw bucket itself never exposed.

Using S3 Same-Region Replication to three buckets (A)—replication copies identical raw objects and performs no redaction, so every application would still see sensitive fields. Writing redacted data through a standard S3 access point with an event-triggered Lambda (C)—a plain access point serves stored bytes with no on-read transformation, and one stored redaction cannot satisfy three different redaction requirements. Sharing a Kinesis stream across all applications (B) also cannot vary the output per consumer. Object Lambda access points are the mechanism built for per-request, per-consumer transformation.

Community Discussion (9 comments)

jamesf 👍 3 Selected: D
keywords: S3 Object Lambda access point to redact data
c3518fc 👍 3 Selected: D
https://docs.aws.amazon.com/AmazonS3/latest/userguide/tutorial-s3-object-lambda-uppercase.html
dkp 👍 3 Selected: D
answer D
anj_k 👍 4 Selected: D
https://docs.aws.amazon.com/AmazonS3/latest/userguide/tutorial-s3-object-lambda-uppercase.html
dzn 👍 2 Selected: C
S3 Object Lambda access point is not suitable for generating reports. Generally, creating a report requires an aggregate process, which is expensive. Since reports are expected to be viewed multiple times, it is inefficient to pay for Lambda processing time and CPU costs each time they are viewed. To adopt D, CloudFront should be added to the front. https://aws.amazon.com/jp/blogs/aws/new-use-amazon-s3-object-lambda-with-amazon-cloudfront-to-tailor-content-for-end-users/
fdoxxx 👍 4 Selected: D
D, using S3 Object Lambda access points, is the most appropriate solution for the requirements: S3 Object Lambda allows you to add your own code to S3 GET requests to modify and process data at the time of retrieval. In this scenario, you can create an S3 access point that uses the raw data's S3 bucket as the destination. For each application, create a separate S3 Object Lambda access point that uses the S3 access point as the source. Configure the AWS Lambda function for each S3 Object Lambda access point to redact data when objects are retrieved. This solution ensures that each application can access the data with its own redaction rules, and the redaction is applied dynamically at the time of retrieval.
Ramdi1 👍 3 Selected: D
Single source of truth: This solution maintains a single copy of the raw data in the original S3 bucket, avoiding data duplication and associated costs. Fine-grained redaction: Each application has its own S3 Object Lambda access point, allowing independent Lambda functions to redact data according to specific needs. This ensures targeted redaction without creating multiple S3 buckets with potentially inefficient data copies. Efficient access: Applications access the data through their respective S3 Object Lambda access points, incurring the redaction processing only when data is retrieved, improving cost-effectiveness compared to upfront redaction approaches.
thanhnv142 👍 3 Selected: D
D is correct: S3 access point is actually S3 lambda access point, which is option D A and B: too expensive C: is not correct
Chelseajcole 👍 2
D. S3 Bucker endpoint plus Lambda

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

S3 Object Lambda access points associate an AWS Lambda function with an access point so that the function is invoked on each object retrieval and can transform the response before it reaches the client. Pointing them at an access point on the raw-data bucket gives each of the three reporting applications its own access point and its own redaction logic, so each consumer receives data redacted to its own specification while the underlying bucket remains private and unmodified.

Why the Other Options Are Wrong

A replicates the identical raw objects into three separate buckets, which performs no redaction at all and triples storage without changing what any application sees. C stores redacted objects through a standard access point, which serves stored bytes with no on-read transformation; it would also require choosing a single redaction format, which cannot satisfy three different requirements, and the dzn commenter noted that Object Lambda is generally a poor fit for generating aggregate reports, which is a valid workload caveat. B publishes every application onto one shared Kinesis data stream, so consumers cannot each receive a different transformation of the same record. D is the correct choice.

Community Comment Notes

Community voted D (92), with commenters linking the AWS tutorial on using an S3 Object Lambda access point to transform data. One commenter argued for C on the grounds that Object Lambda is costly for aggregate reporting; that is a legitimate workload-specific concern, but the requirement is a different transformation per application at read time, for which Object Lambda access points are the purpose-built mechanism.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide