AWS Certified Security – SpecialtyDomain 5: Data ProtectionEasy
A company is implementing a data loss prevention (DLP) strategy for sensitive documents stored in Amazon S3. The company needs to automatically identify documents containing PII (e.g., social security numbers, credit card numbers) and prevent them from being shared publicly or with unauthorized external parties. Which AWS service is best suited for automatically discovering, classifying, and reporting on such sensitive data in S3?
- AAWS Detective
- BAmazon Macie
- CAWS Security Hub
- DAWS Config
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Macie
Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS, specifically focusing on S3. It automatically detects and alerts on PII and other sensitive data, making it ideal for DLP strategies.
Why the other options are wrong
- A. AWS Detective helps security analysts investigate security findings or suspicious activities. It's for incident response and forensics, not for proactive data classification and DLP.
- C. AWS Security Hub provides a comprehensive view of your security alerts and security posture across your AWS accounts. It aggregates findings from other services like Macie but does not perform the data discovery and classification itself.
- D. AWS Config assesses, audits, and evaluates the configurations of your AWS resources. It's used for compliance and governance, but not for deep content inspection and PII detection within S3 objects.
Amazon Macie
Amazon Macie is a data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS, especially in Amazon S3.
- Automatically detects sensitive data like PII.
- Provides visibility into S3 bucket security.
- Generates findings for security posture analysis.
Memory trick: Macie is your 'Magnifying Glass' for 'Sensitive Data' in S3.