AWS Certified Data Engineer – AssociateData Governance and SecurityMedium
A data engineering team is building a solution to manage sensitive customer data across various S3 buckets. The company's compliance policy requires that all PII (Personally Identifiable Information) and PCI (Payment Card Industry) data stored in S3 must be automatically discovered, classified, and reported. This process needs to be continuous and provide alerts for non-compliant data. Which AWS service is specifically designed to meet these discovery, classification, and reporting requirements for sensitive data in S3?
- AAWS Config
- BAWS Security Hub
- CAmazon GuardDuty
- DAmazon Macie
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon Macie
Amazon Macie is a data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in AWS S3. It can automatically identify PII and PCI, providing continuous monitoring and alerts for non-compliance.
Why the other options are wrong
- A. AWS Config tracks resource configuration changes and compliance, but it doesn't discover or classify sensitive data within S3 objects.
- B. AWS Security Hub provides a comprehensive view of security alerts and compliance status across AWS accounts but relies on other services (like Macie) to generate the sensitive data findings, rather than performing the discovery itself.
- C. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for sensitive data discovery and classification within S3.
Amazon Macie
Amazon Macie is a data security and data privacy service that uses machine learning to discover, classify, and protect sensitive data (e.g., PII, PCI) stored in Amazon S3.
- Automates discovery of sensitive data in S3.
- Provides visibility into data access patterns and risks.
- Generates findings and alerts for sensitive data exposures.
Memory trick: Macie Makes Monitoring Sensitive Stuff Simple.