AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global e-commerce company uses Amazon S3 to store customer order data, which is classified into various sensitivity levels (e.g., PII, financial, public). They need to automate the classification of new objects as they are uploaded to S3 and trigger different workflows based on the sensitivity level. For instance, highly sensitive data might require immediate alerting and a stricter access policy. Which solution effectively automates this data classification and subsequent action?

  1. AImplement a custom data processing pipeline using AWS Glue to analyze incoming S3 objects for sensitive data and apply S3 Object Tags based on predefined rules.
  2. BConfigure Amazon Macie to automatically discover and classify sensitive data in S3, and then use Macie findings to trigger an AWS EventBridge rule that invokes an AWS Lambda function to apply S3 Object Tags.
  3. CManually tag each S3 object upon upload with its sensitivity level, and then use S3 event notifications to trigger workflows based on these tags.
  4. DUse S3 event notifications to trigger an AWS Lambda function that calls Amazon Macie to analyze the object, then applies S3 Object Tags based on Macie's findings.
Show answer & explanation

Correct answer: B. Configure Amazon Macie to automatically discover and classify sensitive data in S3, and then use Macie findings to trigger an AWS EventBridge rule that invokes an AWS Lambda function to apply S3 Object Tags.

Amazon Macie is specifically designed for automated sensitive data discovery and classification in S3. Its findings can directly integrate with EventBridge, allowing for rule-based actions, such as triggering a Lambda function to apply S3 Object Tags or invoke other workflows, providing an efficient and scalable automation for data classification.

Why the other options are wrong

  • A. AWS Glue is primarily for ETL and data cataloging. While it can be used for custom data analysis, it's a more complex and resource-intensive solution for real-time sensitive data discovery and classification compared to Macie.
  • C. Manual tagging does not meet the requirement for *automated* classification and is prone to human error, especially for large volumes of data.
  • D. While possible, calling Macie directly from Lambda for every S3 upload might be less efficient and potentially more costly than letting Macie continuously monitor the bucket. Macie's findings are designed to be consumed by EventBridge.

Automated S3 Data Classification with Macie

Using Amazon Macie for automated discovery and classification of sensitive data in Amazon S3, integrating its findings with AWS EventBridge to trigger subsequent actions like applying S3 Object Tags or invoking workflows.

  • Macie continuously monitors S3 buckets for sensitive data.
  • Macie findings can be published to EventBridge.
  • EventBridge rules can trigger various AWS services (e.g., Lambda) based on Macie findings.
  • S3 Object Tags are effective for metadata-driven workflow automation.

Memory trick: Macie Finds, EventBridge Tags.

More Domain 5: Data Protection questions