A security engineer uses Amazon Macie to scan the company’s Amazon S3 buckets for sensitive data. There are many buckets and objects. The engineer must identify which buckets contain sensitive data and then run deeper scans on those buckets, with minimal administrative overhead. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Macie automated discovery to continuously sample data in the S3 environment, and run full classification jobs on the buckets where sensitive data is found..
Why this is the answer
The correct solution is to enable Macie automated discovery. Automated discovery continuously samples data across your S3 environment, identifying buckets that likely contain sensitive data with minimal overhead. Once these buckets are identified, you can then run targeted, full classification jobs on them for a deeper scan. This approach is efficient because it avoids running full, potentially costly, scans on all buckets initially. Incorrect options: S3 Cross-Region Replication (CRR) and scanning in another Region adds unnecessary complexity and cost without directly addressing the need for efficient sensitive data discovery. An AWS Lambda function triggered by S3 object uploads would initiate a scan for every new object, which is inefficient for identifying existing sensitive data across many buckets and can incur high costs. Scheduling Macie classification jobs on all buckets is not efficient for initial discovery across a large environment, as it performs a deep scan on every bucket regardless of its likelihood of containing sensitive data. Aggregating results in DynamoDB is useful for analysis but doesn't optimize the initial scanning process.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed