exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 193 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 193
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A large company wants its Compliance team to audit its Amazon S3 buckets to identify if personally identifiable information (PII) is stored in them. The company has hundreds of S3 buckets and has asked the Security Engineers to scan every bucket.
How can this task be accomplished?

  • A. Configure Amazon CloudWatch Events to trigger Amazon Inspector to scan the S3 buckets daily for PII. Configure Amazon Inspector to publish Amazon SNS notifications to the Compliance team if PII is detected.
  • B. Configure Amazon Macie to classify data in the S3 buckets and check the dashboard for PII findings. Configure Amazon CloudWatch Events to capture Macie alerts and target an Amazon SNS topic to be notified if PII is detected.
  • C. Check the AWS Trusted Advisor data loss prevention page in the AWS Management Console. Download the Amazon S3 data confidentiality report and send it to the Compliance team. Configure Amazon CloudWatch Events to capture Trusted Advisor alerts and target an Amazon SNS topic to be notified if PII is detected.
  • D. Enable Amazon GuardDuty in multiple Regions to scan the S3 buckets. Configure Amazon CloudWatch Events to capture GuardDuty alerts and target an Amazon SNS topic to be notified if PII is detected.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cldy
Highly Voted 3 years, 9 months ago
B. Right.
upvoted 16 times
...
sanjaym
Highly Voted 3 years, 8 months ago
B 100%
upvoted 6 times
...
Raphaello
Most Recent 1 year, 4 months ago
Selected Answer: B
Amazon Macie. Option B is the right answer here.
upvoted 1 times
...
anhtu133
1 year, 7 months ago
Selected Answer: B
B 100%. Macie = sensitive information
upvoted 1 times
...
sapien45
2 years, 10 months ago
Selected Answer: B
I see PII and think Macie
upvoted 3 times
...
dcasabona
2 years, 11 months ago
Selected Answer: B
B for sure.
upvoted 1 times
...
kiev
3 years, 8 months ago
B as well.
upvoted 2 times
...
nainakaexam
3 years, 8 months ago
B Straight forward answer
upvoted 4 times
...
viestner
3 years, 9 months ago
b. Macie is for discovering sensitive data in S3 buckets
upvoted 6 times
...
Ayusef
3 years, 9 months ago
B is correct..
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...