nerdexam
Amazon

SAA-C03 · Question #154

A company is enhancing the security of its AWS environment, where the company stores a significant amount of sensitive customer data. The company needs a solution that automatically identifies and…

The correct answer is C. Macie with EventBridge + SNS: Automatically identifies sensitive data, triggers alerts, and. A & B. GuardDuty: Designed for threat detection, not for identifying or classifying sensitive data in uses SNS for immediate notification via email. unnecessary complexity.

Submitted by skyler.x· Mar 4, 2026Design Secure Architectures

Question

A company is enhancing the security of its AWS environment, where the company stores a significant amount of sensitive customer data. The company needs a solution that automatically identifies and classifies sensitive data that is stored in multiple Amazon S3 buckets. The solution must automatically respond to data breaches and alert the company's security team through email immediately when noncompliant data is found. Which solution will meet these requirements?

Options

  • AUse Amazon GuardDuty. Configure an AWS Lambda function to route alerts to an Amazon
  • BUse Amazon GuardDuty. Configure an AWS Lambda function to route alerts to an Amazon
  • CMacie with EventBridge + SNS: Automatically identifies sensitive data, triggers alerts, and
  • DMacie with EventBridge + SQS: Introduces latency due to periodic polling and adds

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    9% (2)
  • C
    74% (17)
  • D
    13% (3)

Explanation

A & B. GuardDuty: Designed for threat detection, not for identifying or classifying sensitive data in uses SNS for immediate notification via email. unnecessary complexity.

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice