SCS-C02 · Question #418
A security engineer uses Amazon Macie to scan a company's Amazon S3 buckets for sensitive data. The company has many S3 buckets and many objects stored in the S3 buckets. The security engineer must…
The correct answer is C. Configure Macie automated discovery to continuously sample data from the S3 buckets. Macie's automated discovery feature continuously samples and evaluates data in S3 buckets, allowing you to identify sensitive data without the need for full scans of every bucket initially. This reduces administrative overhead by only requiring full scans on specific buckets…
Question
A security engineer uses Amazon Macie to scan a company's Amazon S3 buckets for sensitive data. The company has many S3 buckets and many objects stored in the S3 buckets. The security engineer must identify S3 buckets that contain sensitive data and must perform additional scanning on those S3 buckets. Which solution will meet these requirements with the LEAST administrative overhead?
Options
- AConfigure S3 Cross-Region Replication (CRR) on the S3 buckets to replicate the objects to a
- BCreate an AWS Lambda function as an S3 event destination for the S3 buckets. Configure the
- CConfigure Macie automated discovery to continuously sample data from the S3 buckets.
- DConfigure Macie scans to run on the S3 buckets. Aggregate the results of the scans in an
How the community answered
(48 responses)- A10% (5)
- B4% (2)
- C71% (34)
- D15% (7)
Explanation
Macie's automated discovery feature continuously samples and evaluates data in S3 buckets, allowing you to identify sensitive data without the need for full scans of every bucket initially. This reduces administrative overhead by only requiring full scans on specific buckets where sensitive data is found, making the process more efficient and scalable for environments with many S3 buckets and objects.
Topics
Community Discussion
No community discussion yet for this question.