nerdexam
Amazon

SCS-C02 · Question #189

A company is investigating controls to protect sensitive data. The company uses Amazon Simple Notification Service (Amazon SNS) topics to publish messages from application components to custom…

The correct answer is B. Configure an inbound message data protection policy. In the policy, include the De-identify. https://aws.amazon.com/blogs/compute/introducing-message-data-protection-for-amazon-sns/

Submitted by andres_qro· Mar 6, 2026Data Protection

Question

A company is investigating controls to protect sensitive data. The company uses Amazon Simple Notification Service (Amazon SNS) topics to publish messages from application components to custom logging services. The company is concerned that an application component might publish sensitive data that will be accidentally exposed in transaction logs and debug logs. Which solution will protect the sensitive data in these messages from accidental exposure?

Options

  • AUse Amazon Made to scan the SNS topics for sensitive data elements in the SNS messages.
  • BConfigure an inbound message data protection policy. In the policy, include the De-identify
  • CConfigure the SNS topics with an AWS Key Management Service (AWS KMS) customer
  • DCreate an Amazon GuardDuty finding for sensitive data that is transmitted to the SNS topics.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    76% (39)
  • C
    14% (7)
  • D
    6% (3)

Explanation

https://aws.amazon.com/blogs/compute/introducing-message-data-protection-for-amazon-sns/

Topics

#SNS data protection policy#PII masking#sensitive data#message de-identification

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice