A security engineer must detect and report sensitive data stored in an Amazon S3 bucket. Notifications must be sent to an existing Amazon Simple Notification Service (Amazon SNS) topic. Which solution delivers this with the least implementation effort?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Amazon Macie with managed data identifiers to discover and classify sensitive data, and create an Amazon EventBridge rule to forward findings to the SNS topic..
Why this is the answer
The correct answer is to use Amazon Macie with managed data identifiers and an Amazon EventBridge rule. Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to discover, classify, and protect sensitive data in Amazon S3. It natively integrates with EventBridge to send findings, which can then be routed to an SNS topic with minimal configuration, representing the least implementation effort. Incorrect options: AWS Config primarily assesses compliance and configuration changes, not sensitive data content within S3 objects. Creating an AWS Lambda function for scanning requires custom code development, maintenance, and managing the scanning logic, which is more effort than using a managed service like Macie. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for discovering sensitive data content within S3 objects. While it can use S3 data events from CloudTrail, its focus is on security threats, not data classification.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed